diff --git a/content/.metadata.json b/content/.metadata.json
index 0d3dbb0cd0..1b9fc5de0c 100644
--- a/content/.metadata.json
+++ b/content/.metadata.json
@@ -1,7 +1,7 @@
{
"metadata": {
"version": "2.0",
- "fetch_date": "2026-09-18T10:10:17.858225Z",
+ "fetch_date": "2026-09-19T05:14:10.661864Z",
"section": "all"
},
"items": [
@@ -65,8 +65,8 @@
"url": "https://platform.claude.com/docs/en/build-with-claude/refusals-and-fallback",
"status": "success",
"path": "en/build-with-claude/refusals-and-fallback.md",
- "sha256": "a6e39544b8a8ab6c5eb705d79d83b4b99b39a9dab1bd0960ee9ded1a4e5bf648",
- "size": 57609
+ "sha256": "8709039766227a6ba216a959552bf0fd8aee8835a96603cc680dd9aa73c523ed",
+ "size": 57501
},
{
"url": "https://platform.claude.com/docs/en/build-with-claude/fallback-credit",
@@ -156,8 +156,8 @@
"url": "https://platform.claude.com/docs/en/build-with-claude/thinking",
"status": "success",
"path": "en/build-with-claude/thinking.md",
- "sha256": "20e28393b937d8436091423bf2afbeabeccd2c97b5d9db72aef2da7858752f00",
- "size": 72899
+ "sha256": "4eb6ec1207cbdc12be344a6c7f2c58a945cb74f5cb68d6f8eec7438e0c4ee30b",
+ "size": 72887
},
{
"url": "https://platform.claude.com/docs/en/build-with-claude/thinking-steering-and-cost",
@@ -177,8 +177,8 @@
"url": "https://platform.claude.com/docs/en/build-with-claude/preserved-thinking",
"status": "success",
"path": "en/build-with-claude/preserved-thinking.md",
- "sha256": "b9938c83c6f5f9ff043412edbfe60b3591a1ceff5f0b12949635fcec9ca58731",
- "size": 90002
+ "sha256": "fdb4924557d628d3a207ec29adb07747306fdf33b5801aa083e75269a45673f8",
+ "size": 89928
},
{
"url": "https://platform.claude.com/docs/en/build-with-claude/thinking-troubleshooting",
@@ -191,8 +191,8 @@
"url": "https://platform.claude.com/docs/en/build-with-claude/extended-thinking",
"status": "success",
"path": "en/build-with-claude/extended-thinking.md",
- "sha256": "cb6d05be6b84ca90b2f36c1993ef56655d4a47959e190d3ed26437e9bd7aadc6",
- "size": 22182
+ "sha256": "ea43633786686f4881dc1bbb04c0069e6d75088d21eadd4a7a888e98d228f7e7",
+ "size": 22162
},
{
"url": "https://platform.claude.com/docs/en/agents-and-tools/tool-use/overview",
@@ -471,8 +471,8 @@
"url": "https://platform.claude.com/docs/en/agents-and-tools/agent-skills/quickstart",
"status": "success",
"path": "en/agents-and-tools/agent-skills/quickstart.md",
- "sha256": "f878c9a34fc19b3104b88ed2393ee1459b2476016b87f7c8d7e61e7244c7d956",
- "size": 37102
+ "sha256": "cd2529828e1a658d83bfe9555b1ca1fa360d60fcfa09c7a6a0c90ee4815d3edc",
+ "size": 37080
},
{
"url": "https://platform.claude.com/docs/en/agents-and-tools/agent-skills/best-practices",
@@ -492,8 +492,8 @@
"url": "https://platform.claude.com/docs/en/build-with-claude/skills-guide",
"status": "success",
"path": "en/build-with-claude/skills-guide.md",
- "sha256": "41d76d7668e2553ab90c5d8c7dfad18653a453213c1587fcc8e7dc6dee53544a",
- "size": 147757
+ "sha256": "d5083a64f44d75fe9fe2955d4bec5f5252aea48746492d15a468f912987361e9",
+ "size": 147647
},
{
"url": "https://platform.claude.com/docs/en/agents-and-tools/remote-mcp-servers",
@@ -590,21 +590,21 @@
"url": "https://platform.claude.com/docs/en/build-with-claude/claude-platform-on-aws",
"status": "success",
"path": "en/build-with-claude/claude-platform-on-aws.md",
- "sha256": "95d6892924e5e6dde77da6b2f7fcb1fd38f67985fbe437c7e0efb47f67c2a4ba",
- "size": 87248
+ "sha256": "bdb738c6445b4be9267271767f647b00b7a25f85f5d2bfe2a02c509cd1bb6ccb",
+ "size": 87274
},
{
"url": "https://platform.claude.com/docs/en/build-with-claude/claude-on-vertex-ai",
"status": "success",
"path": "en/build-with-claude/claude-on-vertex-ai.md",
- "sha256": "4025f2c904a8be00a4525269430287ddf3edb151993df0d71e6f9794e5c7c420",
- "size": 32635
+ "sha256": "72843c25ca19fa5c5fb76473a225d06da645ec3fd626a2dadd1b2752cdd374e1",
+ "size": 33813
},
{
"url": "https://platform.claude.com/docs/en/build-with-claude/claude-in-microsoft-foundry",
"status": "success",
"path": "en/build-with-claude/claude-in-microsoft-foundry.md",
- "sha256": "6988971f491ba5e1ea14f954454b532d0e9b156f4818f69045e368b222744b5d",
+ "sha256": "db01a9effad13b64fd6f99e617390ef24a54fc189465d3d5869a55be07f0dd16",
"size": 37482
},
{
@@ -625,8 +625,8 @@
"url": "https://platform.claude.com/docs/en/managed-agents/onboarding",
"status": "success",
"path": "en/managed-agents/onboarding.md",
- "sha256": "b714e2783e3940e7d95b8194fa36de44e329297c6e314321711a1b19a8af1159",
- "size": 4152
+ "sha256": "f11626f1e51ed477e278c12deb1a356f6c7871a23ed3bba97023a50d546cadaf",
+ "size": 4119
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/migration",
@@ -639,15 +639,15 @@
"url": "https://platform.claude.com/docs/en/managed-agents/agent-setup",
"status": "success",
"path": "en/managed-agents/agent-setup.md",
- "sha256": "299babcc297f1d5cdd4208a3a76c25e6e965313df5862c248f28684f1d3960bf",
- "size": 31184
+ "sha256": "870eee664ffb02bd891e1a4c0d9808d343222f3367d1c9bb7035916dfc022a13",
+ "size": 31117
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/tools",
"status": "success",
"path": "en/managed-agents/tools.md",
- "sha256": "b632a7ea1dcba5e12358bbd6e0490b7957045897767846bfb46e75ee10d296b5",
- "size": 40461
+ "sha256": "e4f61473e4f82712e033b5e1410930be9ff2286def074fb39e09f904d3649bd4",
+ "size": 40417
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/mcp-connector",
@@ -660,22 +660,22 @@
"url": "https://platform.claude.com/docs/en/managed-agents/permission-policies",
"status": "success",
"path": "en/managed-agents/permission-policies.md",
- "sha256": "51d3e5da655d3f5c9d4409c3c4f1d5bc73ad80f4a51b1806654b7eed5a57c954",
- "size": 49801
+ "sha256": "ac827a4a89f953f2fb920679ea89eddae0469e9a2ac5b32a811a1b20f5a2f934",
+ "size": 49757
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/skills",
"status": "success",
"path": "en/managed-agents/skills.md",
- "sha256": "9103ef787e4627af1795423fb40622414e5ecc81bfbb79eb135803e5f9689976",
- "size": 23273
+ "sha256": "6df6edb76335f1cc8e0a13981a01c6c82af4c6925838911eee12e73c61e9af51",
+ "size": 23251
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/environments",
"status": "success",
"path": "en/managed-agents/environments.md",
- "sha256": "e4ae8b510f08e57f81520ac095355c30fe76545e4d2434f5110d15d5895a4442",
- "size": 23124
+ "sha256": "6c8fc4c80a101873bb294e11432739753f42d332dff9ecfffefcf5132f933ef0",
+ "size": 22914
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/cloud-sandboxes-reference",
@@ -688,8 +688,8 @@
"url": "https://platform.claude.com/docs/en/managed-agents/self-hosted-sandboxes",
"status": "success",
"path": "en/managed-agents/self-hosted-sandboxes.md",
- "sha256": "753522af27a8ea593fb4b89fb87c7e31d40921286836377f6b4637d733f69dfd",
- "size": 112540
+ "sha256": "9b20a8970d4d9dc9e4e34aed95bf7d8622173ca4448ac84886ebb681c47c1d22",
+ "size": 112562
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/self-hosted-sandboxes-security",
@@ -702,29 +702,29 @@
"url": "https://platform.claude.com/docs/en/managed-agents/sessions",
"status": "success",
"path": "en/managed-agents/sessions.md",
- "sha256": "87ee03ac96ccd2cdbf2580206148abc4a7806f5720faf2f9840d0c6b84e83486",
- "size": 40856
+ "sha256": "2228943f86f656591e5e1812aad89ac0d414a0fb58de1f9a4ae83c3707f76fe3",
+ "size": 40267
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/session-operations",
"status": "success",
"path": "en/managed-agents/session-operations.md",
- "sha256": "a5247ca4820d38083ef629b8d4255b060ef862574aa2936bfd1e8d0b3483366f",
- "size": 25448
+ "sha256": "7978987d9c8bf934c699559e6d031601b5fb807a673b20ac2666f7ce5eb15ad2",
+ "size": 25272
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/events-and-streaming",
"status": "success",
"path": "en/managed-agents/events-and-streaming.md",
- "sha256": "57357dafc3134675f7d29492382d17a50757b7d94106f931b4c495733f6e5600",
- "size": 120194
+ "sha256": "ecad674aab19325f9b658ad21fa9a5f5ffea8466adb5391704d4f5dd17e7de0d",
+ "size": 119929
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/budgets",
"status": "success",
"path": "en/managed-agents/budgets.md",
- "sha256": "f1488f686ae59d698628f51cc2b41ede9b34648a8fbca0a049c465b579430e7f",
- "size": 22329
+ "sha256": "8145fe4d2905055165e38e36cfcaf36fcd24d372dcde8de93b88adfc47e65d62",
+ "size": 22158
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/webhooks",
@@ -737,15 +737,15 @@
"url": "https://platform.claude.com/docs/en/managed-agents/define-outcomes",
"status": "success",
"path": "en/managed-agents/define-outcomes.md",
- "sha256": "08fd67d4b05d19cf69265a85acc3b9ffe0ebfe44a9e78fe16e00e96ea3e0021e",
- "size": 32359
+ "sha256": "b565a2d7a0685d2eae3c102c5ddf52a90cbe5c60feb5de27b5561c606ab8e6c7",
+ "size": 32170
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/vaults",
"status": "success",
"path": "en/managed-agents/vaults.md",
- "sha256": "50cdf58be928566dd357a92e960eade32c61bf813966b050500a0d59c9e9ee79",
- "size": 46540
+ "sha256": "da1ae2d4d62f60340640067bce593ddfd377ec7d21e5411bee8e3e5cdf5fafb4",
+ "size": 45884
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/github",
@@ -758,36 +758,36 @@
"url": "https://platform.claude.com/docs/en/managed-agents/files",
"status": "success",
"path": "en/managed-agents/files.md",
- "sha256": "6e8298ee92853581cdbbbad3c25c122c6a145f842c3930162d6ee9ffbe547da7",
- "size": 21939
+ "sha256": "1dc8b70d772e1c242e85e1ea1454f230913f4cc3d255679dc071865908d60846",
+ "size": 21540
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/memory",
"status": "success",
"path": "en/managed-agents/memory.md",
- "sha256": "06ec699223196cd763eaa862c76b883318186b7d8d1fccb9477768003d51ef56",
- "size": 46383
+ "sha256": "2cdbef9c20407d8773a5c96cae4ba0e8b2fe158b46ced36ede50126eb67b0773",
+ "size": 45349
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/dreams",
"status": "success",
"path": "en/managed-agents/dreams.md",
- "sha256": "97b3d54a8ba3fe98727138ad6e404a36aff3f136feed4deb39030d2e707110d7",
- "size": 24985
+ "sha256": "a5a79dda83b0cb2894b9f230fb84e97d2c3642b42f2e1fb6965fbb99b6875fc3",
+ "size": 24859
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/multiagent-orchestration",
"status": "success",
"path": "en/managed-agents/multiagent-orchestration.md",
- "sha256": "9a4afa7cd93b30333d3b858e1d17b0bea21362530a0d8e77739be422f488b21f",
- "size": 61582
+ "sha256": "d32778b2e59d9f20f307051a5b3f8fe418d84642196cd9a464001f93a85bf018",
+ "size": 61981
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/scheduled-deployments",
"status": "success",
"path": "en/managed-agents/scheduled-deployments.md",
- "sha256": "8f24632d566aa3ea531b66e112e1cd060d9fe97a869a00f4af57ffaf6a0de679",
- "size": 24938
+ "sha256": "0f45535e1062117a373a47ecbf0e1a5147720e7e474be717b7e306264a452c1b",
+ "size": 24699
},
{
"url": "https://platform.claude.com/docs/en/managed-agents/reference",
@@ -961,29 +961,29 @@
"url": "https://platform.claude.com/docs/en/manage-claude/cmek",
"status": "success",
"path": "en/manage-claude/cmek.md",
- "sha256": "f52b8fd90fdc3124495892bbfb42fe4a908dbdea45c9d0fddffa5d4d0917fc16",
- "size": 17430
+ "sha256": "5a9e0e82a0e1744e0d38c472cad8129f90c63a2eb0706aaf435e70ffe940c48b",
+ "size": 17455
},
{
"url": "https://platform.claude.com/docs/en/manage-claude/cmek-aws-kms",
"status": "success",
"path": "en/manage-claude/cmek-aws-kms.md",
- "sha256": "d711cf1c8c7c9dc1187204a515dedb48090191d4ad7b5d9aa5489070fb3d68f8",
- "size": 35081
+ "sha256": "b6e91535d32cc87960c1d4dccb56229b86fc4bc215bf9e25fbd7c59b030df0af",
+ "size": 37472
},
{
"url": "https://platform.claude.com/docs/en/manage-claude/cmek-google-cloud-kms",
"status": "success",
"path": "en/manage-claude/cmek-google-cloud-kms.md",
- "sha256": "6b39fe756aef5b8c7d8b09c27da1e1ecf68397dac0784a0a084a8ab513f80907",
- "size": 21217
+ "sha256": "0c15ec98df9a72b3ea8df49aa94d4053ab453ec66605fce7403e0691590deee2",
+ "size": 23638
},
{
"url": "https://platform.claude.com/docs/en/manage-claude/cmek-azure-key-vault",
"status": "success",
"path": "en/manage-claude/cmek-azure-key-vault.md",
- "sha256": "b4ea1ccd17fa1f3caab264bc9b8ba6a7d2a46357cec870e109f3dd7f4ecfdf9d",
- "size": 23695
+ "sha256": "117fa45def8e20c51446b240989998850f9c8de9e92a4d0cc5a1393fb5975b07",
+ "size": 26182
},
{
"url": "https://platform.claude.com/docs/en/manage-claude/inference-hooks",
@@ -1283,8 +1283,8 @@
"url": "https://platform.claude.com/docs/en/models/sonnet-5/migration-guide",
"status": "success",
"path": "en/models/sonnet-5/migration-guide.md",
- "sha256": "756681842fe2d97a4873e4abbab03a2e6e8c9668682f1d2573206261bf089b68",
- "size": 38667
+ "sha256": "b8c29a3eb6bbe5483e794e706d8019383f45ef2db7e089519283e54ec9451437",
+ "size": 38647
},
{
"url": "https://platform.claude.com/docs/en/models/haiku-4-5/overview",
@@ -1395,8 +1395,8 @@
"url": "https://platform.claude.com/docs/en/about-claude/model-deprecations",
"status": "success",
"path": "en/about-claude/model-deprecations.md",
- "sha256": "0230d571767d0ef6a3f76db87a2e4c9edff9faad8baab36abf69ee0581bd9922",
- "size": 13514
+ "sha256": "3a2df47b1dd8818789c13f72c5e81c2cd58b539087ee855d52e9e47527075a07",
+ "size": 13826
},
{
"url": "https://platform.claude.com/docs/en/resources/overview",
@@ -1899,14 +1899,14 @@
"url": "https://platform.claude.com/docs/en/api/skills",
"status": "success",
"path": "en/api/skills.md",
- "sha256": "9a5eac4fb34e925a81dc7a49e29f282a4e5c9220fd3bf351cef25cfaccfe1c0d",
+ "sha256": "58e691ceceb88cce81ee55af2df2fb89360cd964b8a6354c52b45911a32830a7",
"size": 18997
},
{
"url": "https://platform.claude.com/docs/en/api/skills/create",
"status": "success",
"path": "en/api/skills/create.md",
- "sha256": "92f8f0f2acba9d3bebc180216f273a14199422f68ae7f8c989640037e3ea881b",
+ "sha256": "a671bf1ddcfb144e200c95fc93c4c0bc613067b63df17b51d30484f17b254f8a",
"size": 2821
},
{
@@ -1934,14 +1934,14 @@
"url": "https://platform.claude.com/docs/en/api/skills/versions",
"status": "success",
"path": "en/api/skills/versions.md",
- "sha256": "c616b15e118a9c656cca98ecbd7fe979435fd0fe16c0fdfca5a4f3a20735a395",
+ "sha256": "29e394fea0d5e53ce6bf3ac3e578745b7ea6899ab0c28ab45ee5aeff7cd1865c",
"size": 8753
},
{
"url": "https://platform.claude.com/docs/en/api/skills/versions/create",
"status": "success",
"path": "en/api/skills/versions/create.md",
- "sha256": "5b80ec07e84f4a954a59dac1af1592d029d7ebb8c1e2979982ed6e7cdcbf68a5",
+ "sha256": "de480e5105f48ccfb816ffe5180afa5dbb868af9a0c9fa99f5e8ecce3915e9b1",
"size": 2051
},
{
@@ -1969,8 +1969,8 @@
"url": "https://platform.claude.com/docs/en/api/beta",
"status": "success",
"path": "en/api/beta.md",
- "sha256": "6828640164ed4c850085e242bba3931190506bcbb14b903b5df111736243fbe0",
- "size": 2553199
+ "sha256": "03c80004e1db6f4896b146bdd2fcdbf83068b302c61a94dd764914a3bf56d34a",
+ "size": 2563359
},
{
"url": "https://platform.claude.com/docs/en/api/beta/models",
@@ -1997,36 +1997,36 @@
"url": "https://platform.claude.com/docs/en/api/beta/messages",
"status": "success",
"path": "en/api/beta/messages.md",
- "sha256": "2680e5d117874f9691fff21cda1e35b3ab267a9d6819e0dec782e5d7fafddcf0",
- "size": 1400541
+ "sha256": "ed69f7228cc253e62396f8c52568bf832107ba8e2fad28541a932620981bb3d6",
+ "size": 1400502
},
{
"url": "https://platform.claude.com/docs/en/api/beta/messages/create",
"status": "success",
"path": "en/api/beta/messages/create.md",
- "sha256": "33e1a3e0688f393dce4402859130e4f7f1dfb3842ccabdb4b37d6f854452b6d5",
- "size": 200839
+ "sha256": "358ed3d5a70127677ce710506641537ca675289dd412cca5b37e5acc62e02a03",
+ "size": 200833
},
{
"url": "https://platform.claude.com/docs/en/api/beta/messages/count_tokens",
"status": "success",
"path": "en/api/beta/messages/count_tokens.md",
- "sha256": "c70854e0d463bbd8726d53650d4a3ef6159bce28df460d47c96f9ac421975c95",
- "size": 125471
+ "sha256": "a409e8fed684f9b4ab7c1ca1ed02a1f0720f46c8336b232e03088232349ca27b",
+ "size": 125465
},
{
"url": "https://platform.claude.com/docs/en/api/beta/messages/batches",
"status": "success",
"path": "en/api/beta/messages/batches.md",
- "sha256": "687f3707e6330427350298c95489c4b579960ddd9960d22552995cc6c6c8171a",
- "size": 417836
+ "sha256": "341ea7d3a36f3da19c9514ba6f964427bebfcbb32971cac75fcef209b9813ce4",
+ "size": 417830
},
{
"url": "https://platform.claude.com/docs/en/api/beta/messages/batches/create",
"status": "success",
"path": "en/api/beta/messages/batches/create.md",
- "sha256": "cd90d550939f994bacae8dcbe4dc74abbfc56294126317bf19b2130acb74ffcf",
- "size": 146648
+ "sha256": "d043430520e16f1fd3ec8e2f4210d576a226f2504f5aaa9f6eee25f9bba905c0",
+ "size": 146642
},
{
"url": "https://platform.claude.com/docs/en/api/beta/messages/batches/retrieve",
@@ -2753,14 +2753,14 @@
"url": "https://platform.claude.com/docs/en/api/beta/skills",
"status": "success",
"path": "en/api/beta/skills.md",
- "sha256": "f6674c9d5dc20a7c5ac5131037dccdfe383cb3de8e19bdad7a7f79018bd0e39b",
+ "sha256": "862967bc914d483aaf768eb7f1bdaac7480a7e2de4df995f4ba709fcd6099a34",
"size": 37820
},
{
"url": "https://platform.claude.com/docs/en/api/beta/skills/create",
"status": "success",
"path": "en/api/beta/skills/create.md",
- "sha256": "cfcf4d880cf70549c395dc06555ad843a5e5d821d8888dfc1aff1e67fb2a99f8",
+ "sha256": "cc6db1798568aa5930ea4e5ccbc06ab72a314faba6c12a53fa151826f8f19691",
"size": 4834
},
{
@@ -2788,14 +2788,14 @@
"url": "https://platform.claude.com/docs/en/api/beta/skills/versions",
"status": "success",
"path": "en/api/beta/skills/versions.md",
- "sha256": "cccc651d146850da9418ed802a3578cd12a1dd6ff8ca1966e405b8b3559e4440",
+ "sha256": "8c848db51328e4d4c2dc23df39f5ef57ca1c9ff66a7c17aee8bf80784b14bd99",
"size": 19531
},
{
"url": "https://platform.claude.com/docs/en/api/beta/skills/versions/create",
"status": "success",
"path": "en/api/beta/skills/versions/create.md",
- "sha256": "db6da4cc2e0835b21239b086ad8656aa2de57239fca9ea4ace988abc4180b700",
+ "sha256": "7eb368860c735bd33977548dc44ed4db4151b8b3c09bcc12f23fdad4ff961ffb",
"size": 4060
},
{
@@ -2998,8 +2998,8 @@
"url": "https://platform.claude.com/docs/en/api/beta/organization",
"status": "success",
"path": "en/api/beta/organization.md",
- "sha256": "b9bf409f62222a23c972eaa22dbf6ccd1d29f4cf43f18e2b883b3104982de39e",
- "size": 537788
+ "sha256": "211149428ec989d2192268da63569128579963bacee86691b02aac92f6f1c68b",
+ "size": 547966
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/retrieve",
@@ -3558,78 +3558,78 @@
"url": "https://platform.claude.com/docs/en/api/beta/organization/mcp_tunnels",
"status": "success",
"path": "en/api/beta/organization/mcp_tunnels.md",
- "sha256": "f2141fb387feb99388e11f9fe7c7d7430581643db6c939c25d77195d4a49b597",
- "size": 41090
+ "sha256": "cacf0c71f086fd64b29c0c7d3a89f9e38167b25cf8c5b3a304f9fd285f9c2c7e",
+ "size": 41738
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/mcp_tunnels/list",
"status": "success",
"path": "en/api/beta/organization/mcp_tunnels/list.md",
- "sha256": "e6b566620052f781139d979d5c000ae8f4f83b2204666e0ab9c5ce96a9837aa1",
- "size": 5141
+ "sha256": "ebd481c352e654f95ea4a659f5c06fd3d8dd0eee45e7001d65d72d2971cce0f0",
+ "size": 5213
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/mcp_tunnels/retrieve",
"status": "success",
"path": "en/api/beta/organization/mcp_tunnels/retrieve.md",
- "sha256": "fbe21971807dbed1728fb11358e40a230096162ad39c893a31ab3964d83dc540",
- "size": 4248
+ "sha256": "554eeba945856b9cce66dec2dd514183c4ee73c21639acf77f2546b19a61ec7a",
+ "size": 4320
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/mcp_tunnels/archive",
"status": "success",
"path": "en/api/beta/organization/mcp_tunnels/archive.md",
- "sha256": "9a0c6ca03175ffca45ed5eddf95ea69fc833742f894c54bd552ea5f3cad35d7e",
- "size": 4518
+ "sha256": "d4f9a07a3bc9e9017207044df37da29182433d099da36937d91f1c83f5a1cf63",
+ "size": 4590
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/mcp_tunnels/reveal_token",
"status": "success",
"path": "en/api/beta/organization/mcp_tunnels/reveal_token.md",
- "sha256": "0b5143e070756db1d63de04209200bf602fba7dc703362b29ac268850f20c2a5",
- "size": 3782
+ "sha256": "895168719c81f175fb639e8a3903ad5b54c15a7611587a39a4774d91515b6547",
+ "size": 3854
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/mcp_tunnels/rotate_token",
"status": "success",
"path": "en/api/beta/organization/mcp_tunnels/rotate_token.md",
- "sha256": "a69694a04d99fb1978bb513402dd45309fde72d98af0bd3b378a4599930b6642",
- "size": 3925
+ "sha256": "42e90d7f6515a4db428c8d6338cbffcdde3cf903f012f30a8a2e46318a800a4c",
+ "size": 3997
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/mcp_tunnels/tunnel_certificates",
"status": "success",
"path": "en/api/beta/organization/mcp_tunnels/tunnel_certificates.md",
- "sha256": "cb5ecc0d7fabacfdff5a22b8bcb987120ac568904dfa2cb21125b99ea450fbba",
- "size": 19570
+ "sha256": "507ff559093746c7ce61c936d10d100b42aae5f7bacd55914dc14c732c3b17e3",
+ "size": 19858
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/mcp_tunnels/tunnel_certificates/create",
"status": "success",
"path": "en/api/beta/organization/mcp_tunnels/tunnel_certificates/create.md",
- "sha256": "a46b3349fbbeb85a8c9a4336879bbdea1da460cc40c4cd73481db250998728ec",
- "size": 5005
+ "sha256": "f5c957b068ad1008a9d31ecbc9a1c7643bf03bb0ac51367613bf14cb77dafbe8",
+ "size": 5077
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/mcp_tunnels/tunnel_certificates/list",
"status": "success",
"path": "en/api/beta/organization/mcp_tunnels/tunnel_certificates/list.md",
- "sha256": "afcde0f93f67aadbd2db8f9a751440c309dd01f5315bab8fd6a44d6d45bd89e7",
- "size": 4988
+ "sha256": "bab80d4b8eaea453c1b3d839cdc9dcb1d6c83645e6408689e158bb8448ae7eff",
+ "size": 5060
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/mcp_tunnels/tunnel_certificates/retrieve",
"status": "success",
"path": "en/api/beta/organization/mcp_tunnels/tunnel_certificates/retrieve.md",
- "sha256": "d1f009d304afe403b2767a69046d79c357342fee35d77257f9af05e7de24d882",
- "size": 4402
+ "sha256": "03ccfe2ed7e13d5eb3154023bb333125fc839150f928ffc3ffabe5fba88cae48",
+ "size": 4474
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/mcp_tunnels/tunnel_certificates/archive",
"status": "success",
"path": "en/api/beta/organization/mcp_tunnels/tunnel_certificates/archive.md",
- "sha256": "516c2fe815c595b13ddfbb61b47f22b3db4aaab4b695adaa1b376d22ee00d634",
- "size": 4622
+ "sha256": "a65a961e4cbc061ababcad0de2a4a8c4d8edbdcfbd62f81cdc9f60167eee6708",
+ "size": 4694
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/analytics",
@@ -3775,71 +3775,71 @@
"url": "https://platform.claude.com/docs/en/api/beta/organization/spend_limits",
"status": "success",
"path": "en/api/beta/organization/spend_limits.md",
- "sha256": "2ae75671257279dd5fc66fd65a84de8ebce6bd287a1375d457fb0e07174402b3",
- "size": 48504
+ "sha256": "a967b0bb9c26eb869324198cf2acfd506064a9cc99691d122502238e4324e125",
+ "size": 59779
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/spend_limits/create",
"status": "success",
"path": "en/api/beta/organization/spend_limits/create.md",
- "sha256": "d8ad5273e0e20066d11e8d6d9d80de7c8317e10142c7ad5103ca46a4028b0453",
- "size": 3815
+ "sha256": "8accc33887a02ba19902426fe0ebf261aa783e9d407e757f622ff2e7dd95d75e",
+ "size": 5122
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/spend_limits/retrieve",
"status": "success",
"path": "en/api/beta/organization/spend_limits/retrieve.md",
- "sha256": "9ea5a2cb4b08a6f0045a5fdc83d09c26b2f43671995ea82d7972447fe8f819f2",
- "size": 2766
+ "sha256": "68fc43e70e039ead2141d08d0dd2ed3db5219cb3cedddf5d2842e5e3a3940a45",
+ "size": 3072
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/spend_limits/delete",
"status": "success",
"path": "en/api/beta/organization/spend_limits/delete.md",
- "sha256": "cfc282484a3e654b64d55f8a48c683a6acc9d7a621ab36b5c548d3853717a8e4",
- "size": 843
+ "sha256": "a8d41c000044f5708301f8f2ebc22bd39075711d1c389592475d5c9b40bfe79f",
+ "size": 1043
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/spend_limits/list_effective",
"status": "success",
"path": "en/api/beta/organization/spend_limits/list_effective.md",
- "sha256": "ec8d08b3313b8953a685a17ebfdc36b44fcf05df9bdcf0f881a812cfa0a59342",
- "size": 4902
+ "sha256": "67b04c70235fd57e51da610c12f34b7626dd9117d4117e2a9edf6ce82b5bd4ce",
+ "size": 6341
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/spend_limits/increase_requests",
"status": "success",
"path": "en/api/beta/organization/spend_limits/increase_requests.md",
- "sha256": "4210f38b8569d982d1074bfcfd80740a1481cff3b08d979730bfe84b9a0353b9",
- "size": 44272
+ "sha256": "7fb104400e0010f2f76d08c183bb64c1c67ebb8b3b24ddd832a885eb890de799",
+ "size": 53892
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/spend_limits/increase_requests/list",
"status": "success",
"path": "en/api/beta/organization/spend_limits/increase_requests/list.md",
- "sha256": "1184059c6cc8dc0ec16aad550dbb3343ffd0df4b0499104851043221b3fc2ece",
- "size": 7720
+ "sha256": "4b1cb42cd65cbdf6022afa5607b0322d6bef2afd845c0e312dfba5c45cd19c16",
+ "size": 9231
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/spend_limits/increase_requests/retrieve",
"status": "success",
"path": "en/api/beta/organization/spend_limits/increase_requests/retrieve.md",
- "sha256": "01296d1f9d689a2e5aa1be6376eb9ba16af8e42a870b65f5fad72a08fe058572",
- "size": 7170
+ "sha256": "dcac80434fdddb510eb80527b8234a665668f2a9efe40886f823b86cd16f838e",
+ "size": 8681
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/spend_limits/increase_requests/approve",
"status": "success",
"path": "en/api/beta/organization/spend_limits/increase_requests/approve.md",
- "sha256": "989438c6cf8d1b5e0e511b9bca060ec6aaf9d0c8197c4005528e8afcc0d486ef",
- "size": 9750
+ "sha256": "65ebfd25cf122fb29cf52eed714b87f2f80b27c7366c54939a04bb7f60012088",
+ "size": 11495
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/spend_limits/increase_requests/deny",
"status": "success",
"path": "en/api/beta/organization/spend_limits/increase_requests/deny.md",
- "sha256": "3f33f4115836363e70a366370ca9295facb104ab7cca00866d7e4482ca0d4fbd",
- "size": 7344
+ "sha256": "b2a55b2a15052442150f0f4dc5439089f52e402a0bf316a5ed6a1ad6982a3448",
+ "size": 8855
},
{
"url": "https://platform.claude.com/docs/en/api/beta/organization/rbac_groups",
@@ -3957,22 +3957,22 @@
"url": "https://platform.claude.com/docs/en/api/compliance",
"status": "success",
"path": "en/api/compliance.md",
- "sha256": "1cc5e548a6a5d7e3e8ecc34205df917ad2a6c8ad04f29ad0ee7eb4ca91238d96",
- "size": 3339310
+ "sha256": "053d08d9c5eeb2b048c56a82f8d93a24132e79404325888f680d36861636870f",
+ "size": 3352984
},
{
"url": "https://platform.claude.com/docs/en/api/compliance/activities",
"status": "success",
"path": "en/api/compliance/activities.md",
- "sha256": "4a9db70ea3ae44d6eac1e3ba01a9c0343e3c5f937afe3f374e67db0a2729e997",
- "size": 6309584
+ "sha256": "e3c5c7d3f1053ec24ff9e79d39456c8b455e6443a88613a67639228b2445b5de",
+ "size": 6335910
},
{
"url": "https://platform.claude.com/docs/en/api/compliance/activities/list",
"status": "success",
"path": "en/api/compliance/activities/list.md",
- "sha256": "c56a060996b9cf329a186203be5977e2ea95fc767ae0c183af21ac60e2290b0a",
- "size": 3215999
+ "sha256": "f2bbe60466239f5658a52413f17074320cdf9b6f639545b34a2154dfb172da76",
+ "size": 3229673
},
{
"url": "https://platform.claude.com/docs/en/api/compliance/organizations",
@@ -4412,8 +4412,8 @@
"url": "https://code.claude.com/docs/en/overview",
"status": "success",
"path": "en/docs/claude-code/overview.md",
- "sha256": "3e40a3b91b0d01dbde0c5c7d32dec14a90d2ab237c100c50e44b80af6e5ce55a",
- "size": 16763
+ "sha256": "1e235e1f7d470485720b87f48d03d914796fe6e2ce0c39915f2f7bcb6af744a1",
+ "size": 16926
},
{
"url": "https://code.claude.com/docs/en/quickstart",
@@ -4426,15 +4426,15 @@
"url": "https://code.claude.com/docs/en/changelog",
"status": "success",
"path": "en/docs/claude-code/changelog.md",
- "sha256": "91154c90ef0f2959a50159a5f76238255d87034bd33fbf4b9423df03d3ebf53c",
- "size": 767853
+ "sha256": "837a9299c3415beb26ac7a75847154cbb89e996dc7e4f9ab2a8e6609031c85bb",
+ "size": 781912
},
{
"url": "https://code.claude.com/docs/en/how-claude-code-works",
"status": "success",
"path": "en/docs/claude-code/how-claude-code-works.md",
- "sha256": "fd2cf401b1c2b0921cd46dee3c892d3c0d353d72b8c849288ddb5c23e6cc8246",
- "size": 19615
+ "sha256": "b07472946283485c42cb15990019aa39d636fceb2471abaf7d8282dfb9726c1d",
+ "size": 19761
},
{
"url": "https://code.claude.com/docs/en/features-overview",
@@ -4447,15 +4447,15 @@
"url": "https://code.claude.com/docs/en/claude-directory",
"status": "success",
"path": "en/docs/claude-code/claude-directory.md",
- "sha256": "808b6a06b86abe4a20cc21002785210b89a08280b47e98f21cf76ffcf3fef626",
- "size": 102185
+ "sha256": "2665b57430526bbdf0f9b8c9a6e298d7dfe6c195487195c2f7c676d4e589f24a",
+ "size": 103403
},
{
"url": "https://code.claude.com/docs/en/context-window",
"status": "success",
"path": "en/docs/claude-code/context-window.md",
- "sha256": "1ce0cea3bc4090ff1d5d49723a93027fed687cab4a21d0e659976e93ae0a65f2",
- "size": 62163
+ "sha256": "f334fe44527612b0847e28c0b56a630c9b3f3f33f2c709ee4d1e9a16daa3c2e1",
+ "size": 62259
},
{
"url": "https://code.claude.com/docs/en/prompt-caching",
@@ -4468,8 +4468,8 @@
"url": "https://code.claude.com/docs/en/memory",
"status": "success",
"path": "en/docs/claude-code/memory.md",
- "sha256": "98c6d06ea754d557011393608849dfbe23eed8634edb3db318f77178b6ce0f1b",
- "size": 38430
+ "sha256": "1cf44b112e7daa1bc85820c368b8bed40359abc687d962925d4f93b2f54ffb82",
+ "size": 52465
},
{
"url": "https://code.claude.com/docs/en/sessions",
@@ -4559,8 +4559,8 @@
"url": "https://code.claude.com/docs/en/slack",
"status": "success",
"path": "en/docs/claude-code/slack.md",
- "sha256": "b62a6d0f2f8f174c41ea88ac2475b2c12c584b609fbe4932d5f855b9aee29132",
- "size": 15641
+ "sha256": "7a58fa817787846249f962a5a17f00a5104b1848172a8ce0df1627bd885bd0f2",
+ "size": 15744
},
{
"url": "https://code.claude.com/docs/en/claude-tag",
@@ -4573,22 +4573,22 @@
"url": "https://code.claude.com/docs/en/web-quickstart",
"status": "success",
"path": "en/docs/claude-code/web-quickstart.md",
- "sha256": "3e1276fde82eb25e52e8813c6efa212378d3db6b0ee669ecc44a0fa072a41ae7",
- "size": 26065
+ "sha256": "56b31df35fcb954fd588a4c61e1e936bc79a0b6614b442cc4ae49436a1c5c510",
+ "size": 26226
},
{
"url": "https://code.claude.com/docs/en/claude-code-on-the-web",
"status": "success",
"path": "en/docs/claude-code/claude-code-on-the-web.md",
- "sha256": "167c5456e0649ced062e5fe06757ebf69ae6499e50fd5970db137b90427eec27",
- "size": 41992
+ "sha256": "bff22aa7961d6269538c6b0522696bbb6955b71feb02b6311b60a5b68566a6e2",
+ "size": 42170
},
{
"url": "https://code.claude.com/docs/en/routines",
"status": "success",
"path": "en/docs/claude-code/routines.md",
- "sha256": "d76aa5af0d53c71ec2496c591db62a2774baf98e4455e5876adc328eaf1e5d2d",
- "size": 33670
+ "sha256": "a893163ca0f7d804962a6b304a30944fa95c84f781c7d61b59b38de2d3b51fc0",
+ "size": 35382
},
{
"url": "https://code.claude.com/docs/en/ultrareview",
@@ -4608,8 +4608,8 @@
"url": "https://code.claude.com/docs/en/desktop",
"status": "success",
"path": "en/docs/claude-code/desktop.md",
- "sha256": "bfc2f76c8b2b58d3ad2f02610373670d670439b059e9e2409d0d2532c6d5d8bd",
- "size": 103453
+ "sha256": "622a094b23496a6dafc308b0ce9e466e96423bd3f5707faff25183313a75ef40",
+ "size": 103817
},
{
"url": "https://code.claude.com/docs/en/desktop-linux",
@@ -4699,8 +4699,8 @@
"url": "https://code.claude.com/docs/en/sub-agents",
"status": "success",
"path": "en/docs/claude-code/sub-agents.md",
- "sha256": "b6fa1f2099a3df0b5b92a49fe4e42351f4c3aa31227c8d2d8256b9187e650f07",
- "size": 115439
+ "sha256": "bc5cde1e31c0049ae254f0a65314d4d34072f94c15a173fe98cf52bcf0f553d0",
+ "size": 115522
},
{
"url": "https://code.claude.com/docs/en/agent-view",
@@ -4783,8 +4783,8 @@
"url": "https://code.claude.com/docs/en/artifacts",
"status": "success",
"path": "en/docs/claude-code/artifacts.md",
- "sha256": "775c2561af3120ddd2552f96bc99e5f99f4a1cc2c354bc44c4c83eee93de1e46",
- "size": 40823
+ "sha256": "5452dc9afd6f3d30827bdb0186b3d6d966df2381dc8896a9d3efb894345f30e6",
+ "size": 40783
},
{
"url": "https://code.claude.com/docs/en/hooks-guide",
@@ -4818,8 +4818,8 @@
"url": "https://code.claude.com/docs/en/headless",
"status": "success",
"path": "en/docs/claude-code/headless.md",
- "sha256": "a17fc295554efd8ec6860edf3ea0b45ba60edfe431bb888ff5bc1d86530c759c",
- "size": 36448
+ "sha256": "5c0a2bc88989093c1c6803f3efaaf27851c8f0bbc41cbfecfc4ac938cfe6292b",
+ "size": 36408
},
{
"url": "https://code.claude.com/docs/en/deep-links",
@@ -4860,8 +4860,8 @@
"url": "https://code.claude.com/docs/en/errors",
"status": "success",
"path": "en/docs/claude-code/errors.md",
- "sha256": "6a0195a164b013439616064a80b4fcc3296c8475f10fc208742b9571c27cb319",
- "size": 463543
+ "sha256": "6e9fc3562d08087f694491df1e6c04f293222df3f8a1ae3f1066db1b573bdf8b",
+ "size": 464790
},
{
"url": "https://code.claude.com/docs/en/admin-setup",
@@ -4923,8 +4923,8 @@
"url": "https://code.claude.com/docs/en/feature-availability",
"status": "success",
"path": "en/docs/claude-code/feature-availability.md",
- "sha256": "a6f2df6a93158947d90142f6c43d0dad448dfec4eeb016552b7caadf80c8b6e0",
- "size": 23140
+ "sha256": "83284c85d33a8f28c46c0cb27ebe5cd5df4dbd2205170a2cc99efc1c84a04528",
+ "size": 23692
},
{
"url": "https://code.claude.com/docs/en/amazon-bedrock",
@@ -4965,8 +4965,8 @@
"url": "https://code.claude.com/docs/en/corporate-launcher",
"status": "success",
"path": "en/docs/claude-code/corporate-launcher.md",
- "sha256": "74ea19aa77f523c0db149d4b73314c430c858426f3e59ba8edc62df0f664393e",
- "size": 13308
+ "sha256": "3e10814e1ec535d3343f1158b378bf11edafe20e49f682c227c7c21c4a957ecb",
+ "size": 13383
},
{
"url": "https://code.claude.com/docs/en/devcontainer",
@@ -4993,8 +4993,8 @@
"url": "https://code.claude.com/docs/en/claude-apps-gateway-config",
"status": "success",
"path": "en/docs/claude-code/claude-apps-gateway-config.md",
- "sha256": "20bafaa9e2173b5e44bced0c31594b8bf96d6f3c045cc6fa3ff3f54b27bea227",
- "size": 129051
+ "sha256": "007c141fe2f1b4d7ef7c0f122173398991ade3c5d980200378b1e1a0d25de282",
+ "size": 139116
},
{
"url": "https://code.claude.com/docs/en/claude-apps-gateway-spend-limits",
@@ -5007,29 +5007,29 @@
"url": "https://code.claude.com/docs/en/claude-apps-gateway-deploy",
"status": "success",
"path": "en/docs/claude-code/claude-apps-gateway-deploy.md",
- "sha256": "3474b661a72413e9040f79e25a8e5906b2c2e78e1b33393840de95409862cba1",
- "size": 77164
+ "sha256": "4ab7b2a4a5978c2ee53e8834fe69015fc62d15ffeef94f00e6d8bd64ea7d1f71",
+ "size": 89479
},
{
"url": "https://code.claude.com/docs/en/claude-apps-gateway-on-aws",
"status": "success",
"path": "en/docs/claude-code/claude-apps-gateway-on-aws.md",
- "sha256": "f2bfe2859aefd42acffcc4d8e61d3c3fb1572a24bcb3a05ea391a29b877422df",
+ "sha256": "c2116399cda0623f46451fa6c817b11d2b016029b8b5a4858b45aceaf4401252",
"size": 51083
},
{
"url": "https://code.claude.com/docs/en/claude-apps-gateway-on-gcp",
"status": "success",
"path": "en/docs/claude-code/claude-apps-gateway-on-gcp.md",
- "sha256": "caa7e445cfbc099cddef18f5b448cb245d93c04df03ff514772a395cc1b4ba19",
+ "sha256": "3044537575ca9a8afce6ef1488fe6d586327c6ac1bbe935bd972e1a2200a2044",
"size": 25008
},
{
"url": "https://code.claude.com/docs/en/llm-gateway",
"status": "success",
"path": "en/docs/claude-code/llm-gateway.md",
- "sha256": "236a7b796b0255310652fa290588809971d92ef4f8b43f2a3da5c1b16544f85f",
- "size": 6182
+ "sha256": "e863684e59a07b3817483d81dc7ff96d91c96a12edba8fbe41649c6387daa4b5",
+ "size": 6330
},
{
"url": "https://code.claude.com/docs/en/llm-gateway-connect",
@@ -5042,15 +5042,15 @@
"url": "https://code.claude.com/docs/en/llm-gateway-rollout",
"status": "success",
"path": "en/docs/claude-code/llm-gateway-rollout.md",
- "sha256": "f578fee1c4c8f2d49d89caa66e326179309a4b1e8f06a45f9b532721354f070b",
- "size": 32752
+ "sha256": "504cc1dbc2264b89c1a9c153e22e848b228464f67d138158d9ecdbd501ad3ad7",
+ "size": 37692
},
{
"url": "https://code.claude.com/docs/en/llm-gateway-protocol",
"status": "success",
"path": "en/docs/claude-code/llm-gateway-protocol.md",
- "sha256": "19c52d46285264754c3e271d8234e98767b5d6fd25201f92ed883ab5a00c2e0e",
- "size": 35740
+ "sha256": "e82c90fa5f99716521ced55cf2cdb7486cf9adfa2ce4fba7dfb30786c29bca31",
+ "size": 46212
},
{
"url": "https://code.claude.com/docs/en/monitoring-usage",
@@ -5147,8 +5147,8 @@
"url": "https://code.claude.com/docs/en/settings-reference",
"status": "success",
"path": "en/docs/claude-code/settings-reference.md",
- "sha256": "912a26a5f027e0495aa9ddf1ffc41723c6275efaf083eb6e3c20dfaabdee5219",
- "size": 443586
+ "sha256": "ac4329e74a5b56185b5b1a0cc65f7b7916463ff7e87a5b3ac62c82a181ce2b17",
+ "size": 443819
},
{
"url": "https://code.claude.com/docs/en/settings-example",
@@ -5168,8 +5168,8 @@
"url": "https://code.claude.com/docs/en/permission-modes",
"status": "success",
"path": "en/docs/claude-code/permission-modes.md",
- "sha256": "6f3718d5a765fe18e3b8f916dd149ea6fb0a892d3ccbc723c23cc5f898f2fd58",
- "size": 82151
+ "sha256": "581e2ab28eff24b699a8201d90468437aac16aa6108225646d5d8d41422f913d",
+ "size": 82879
},
{
"url": "https://code.claude.com/docs/en/sandboxing",
@@ -5189,8 +5189,8 @@
"url": "https://code.claude.com/docs/en/cloud-environments",
"status": "success",
"path": "en/docs/claude-code/cloud-environments.md",
- "sha256": "4ce623ebfa9a19052925c248803d90533076f71ea78eb04346cc64d6ea35f4a4",
- "size": 65760
+ "sha256": "396efc0ddb0ff3f3f9284900a03645401d039b5cd4759fcc68b5156bf5161dee",
+ "size": 66544
},
{
"url": "https://code.claude.com/docs/en/self-hosted-environments",
@@ -5210,8 +5210,8 @@
"url": "https://code.claude.com/docs/en/self-hosted-environments-deploy",
"status": "success",
"path": "en/docs/claude-code/self-hosted-environments-deploy.md",
- "sha256": "242c91919cda11088c9746bd21c9ecaaadee7ebe9fd8fa1b71f6c3d39ed9ec4c",
- "size": 62448
+ "sha256": "559c0fec720c2ed971c18ca44670e70197c250494da93f0ddff4bbb02176db38",
+ "size": 64886
},
{
"url": "https://code.claude.com/docs/en/self-hosted-environments-configuration",
@@ -5231,8 +5231,8 @@
"url": "https://code.claude.com/docs/en/self-hosted-environments-reference",
"status": "success",
"path": "en/docs/claude-code/self-hosted-environments-reference.md",
- "sha256": "f24d267f6621b9fb2b380e35bc9bca73fd772e93eab7dea6fafde6f1031f8f46",
- "size": 89954
+ "sha256": "642bceb936e97d57536c3502bda57ba87980c26598dd14c4d959dd3fe0a8c478",
+ "size": 90550
},
{
"url": "https://code.claude.com/docs/en/self-hosted-environments-identity",
@@ -5322,22 +5322,22 @@
"url": "https://code.claude.com/docs/en/commands",
"status": "success",
"path": "en/docs/claude-code/commands.md",
- "sha256": "1ba21dd2fbe7151da4dbc0a7d78ad82673eda45eea33857763d911e094e1c952",
+ "sha256": "ba8c67752aac27c6a43317bb5f6abc1a26750c84c50e5e5e40fe8a8929e5601a",
"size": 176593
},
{
"url": "https://code.claude.com/docs/en/env-vars",
"status": "success",
"path": "en/docs/claude-code/env-vars.md",
- "sha256": "4c12354ed5b3015794d2c8868c40f7ccd9dd67a04371e838f93d733a25098509",
- "size": 496121
+ "sha256": "17c833c69ac7d9c16c48993110880e13cefbf0fb61509fa2f656a87e09d1a834",
+ "size": 496249
},
{
"url": "https://code.claude.com/docs/en/tools-reference",
"status": "success",
"path": "en/docs/claude-code/tools-reference.md",
- "sha256": "db05442248b85c9bd4302e70b86a0ad14ea9d82ee567956694922e323bd85d82",
- "size": 109948
+ "sha256": "72201e1682f1bdc04bcf7b892e072da1427094c84b2b26c20829e11cc23f2406",
+ "size": 110008
},
{
"url": "https://code.claude.com/docs/en/interactive-mode",
@@ -5357,15 +5357,15 @@
"url": "https://code.claude.com/docs/en/hooks",
"status": "success",
"path": "en/docs/claude-code/hooks.md",
- "sha256": "84dee417bb2ee0b6a858f5f874ebd9a1690c0ddcfef479abdb49f625cf19a4c1",
- "size": 328716
+ "sha256": "e0a14dcffd8299c22401f2ba18e577470f4ae25cb3dd6609a68160f1f2fbb390",
+ "size": 329656
},
{
"url": "https://code.claude.com/docs/en/plugins-reference",
"status": "success",
"path": "en/docs/claude-code/plugins-reference.md",
- "sha256": "5c1824cd1851c35e079c72db49e383bac26cd376fddb6b96ca6df2ecf980e544",
- "size": 141869
+ "sha256": "f0e0bed28ed0adca7d818232a0788607f62965f97f5d3234b884ca1b2b4b18fe",
+ "size": 141682
},
{
"url": "https://code.claude.com/docs/en/channels-reference",
@@ -5378,8 +5378,8 @@
"url": "https://code.claude.com/docs/en/glossary",
"status": "success",
"path": "en/docs/claude-code/glossary.md",
- "sha256": "00b68b486a912831e613733ffa85344eb9ddd33f324eeea5cd77ea0b77c211aa",
- "size": 24939
+ "sha256": "1ab3fe3d0f14e34504d4f44ee789b5277c117583601be0550b497aa6a8b8ecf2",
+ "size": 25596
},
{
"url": "https://code.claude.com/docs/en/agent-sdk/overview",
@@ -5875,8 +5875,8 @@
"url": "https://modelcontextprotocol.io/community/interest-groups/primitive-grouping",
"status": "success",
"path": "mcp/community/interest-groups/primitive-grouping.md",
- "sha256": "51e12068489862a0cfbee50168279cc0931a4a8ef2400d3f89dbe1e7bee96258",
- "size": 8600
+ "sha256": "bc3545f9085df13d499a1122fbbedbb8aeffef7ed35e57db80bf3cbd1aa46318",
+ "size": 8676
},
{
"url": "https://modelcontextprotocol.io/community/interest-groups/security",
@@ -5931,8 +5931,8 @@
"url": "https://modelcontextprotocol.io/community/working-groups/filesystems",
"status": "success",
"path": "mcp/community/working-groups/filesystems.md",
- "sha256": "7e6b3cd2e9837b1c38aa66b9b567039dd1e8e23d9aed4fc70702b0ab97a3ff98",
- "size": 6927
+ "sha256": "2e0c23f29b73facfe1f92fa8202f44931e4f881289ff2b091355260d44d63bf2",
+ "size": 7081
},
{
"url": "https://modelcontextprotocol.io/community/working-groups/inspector-v2",
@@ -5973,8 +5973,8 @@
"url": "https://modelcontextprotocol.io/community/working-groups/skills-over-mcp",
"status": "success",
"path": "mcp/community/working-groups/skills-over-mcp.md",
- "sha256": "abc94b91aca39660bf8b4c07e23fbe1b552430bc8825e7059d6596efef41d2a1",
- "size": 12404
+ "sha256": "e32d05f595c143d52eea8995fda64a5976bc716718036fa494bffaf3cbba374a",
+ "size": 12032
},
{
"url": "https://modelcontextprotocol.io/community/working-groups/transports",
@@ -6834,8 +6834,8 @@
"url": "https://modelcontextprotocol.io/extensions/skills/overview",
"status": "success",
"path": "mcp/extensions/skills/overview.md",
- "sha256": "36ca8a5641cc6e77f0a628d5820c180029c82d4f1ad34fb694b5ca03b50105df",
- "size": 15672
+ "sha256": "c616c7ab1e93b2d562d41697f25bc92ff65e082cbaeabbe2e2ed3a919a296000",
+ "size": 16129
},
{
"url": "https://modelcontextprotocol.io/extensions/tasks/overview",
@@ -8297,8 +8297,8 @@
"url": "https://support.claude.com/en/articles/8114491-get-started-with-claude",
"status": "success",
"path": "support/8114491-get-started-with-claude.md",
- "sha256": "d5875112a0d4839c8f78690ffc6910fc3050dd57e759a7d0c0f0480d72ddd519",
- "size": 5207
+ "sha256": "44271d7b20288c3312a975f093e6f4d7e146abda92f6ff1612f370a5e265209b",
+ "size": 5203
},
{
"url": "https://support.claude.com/en/articles/8114494-how-up-to-date-is-claude-s-training-data",
@@ -8374,8 +8374,8 @@
"url": "https://support.claude.com/en/articles/8230524-delete-or-rename-a-conversation",
"status": "success",
"path": "support/8230524-delete-or-rename-a-conversation.md",
- "sha256": "238ebc9ffdc58fc2e70c2f27d10a54e421a96b36b98023b0407189d0b4e6d31b",
- "size": 5873
+ "sha256": "660358cda620d9aba61c6bb127d9c4b40c41812b0f07695947577d4a9297b105",
+ "size": 5885
},
{
"url": "https://support.claude.com/en/articles/8241126-upload-files-to-claude",
@@ -8444,8 +8444,8 @@
"url": "https://support.claude.com/en/articles/8325618-paid-plan-billing-faqs",
"status": "success",
"path": "support/8325618-paid-plan-billing-faqs.md",
- "sha256": "c57a64a35879c599dbb2866e6ea6cbc56f1363a36bc7198a7269901a0a3f7d04",
- "size": 4551
+ "sha256": "af74b886782ce5df44d43e54ce67de25de5b32eb8f7ab776ec7f0466afa8d117",
+ "size": 4553
},
{
"url": "https://support.claude.com/en/articles/8325621-i-would-like-to-input-sensitive-data-into-my-chats-with-claude-who-can-view-my-conversations",
@@ -8507,8 +8507,8 @@
"url": "https://support.claude.com/en/articles/8887527-customizing-your-appearance-settings",
"status": "success",
"path": "support/8887527-customizing-your-appearance-settings.md",
- "sha256": "bb30c020a05527a9795f040660b5b8559ceea68c338a962320f1e50797a5c55e",
- "size": 1872
+ "sha256": "f363c8a8194f009118982f70f71b4223b39114c6e7096de1ffe989c1bba08bf8",
+ "size": 1874
},
{
"url": "https://support.claude.com/en/articles/8896518-does-anthropic-crawl-data-from-the-web-and-how-can-site-owners-block-the-crawler",
@@ -8682,8 +8682,8 @@
"url": "https://support.claude.com/en/articles/9267400-move-your-personal-claude-account-to-a-team-or-enterprise-organization",
"status": "success",
"path": "support/9267400-move-your-personal-claude-account-to-a-team-or-enterprise-organization.md",
- "sha256": "150d2c639bb6ea351c0e0b9df7a8d389cf284364732b007490202a3803c2a54d",
- "size": 9725
+ "sha256": "6e871aca44a8346c9bd4e7c4d27b1ffbc66925e25f3b31e1357762f004fd33a6",
+ "size": 9723
},
{
"url": "https://support.claude.com/en/articles/9301722-updates-to-our-acceptable-use-policy-now-usage-policy-consumer-terms-of-service-and-privacy-policy",
@@ -8717,8 +8717,8 @@
"url": "https://support.claude.com/en/articles/9487310-what-are-artifacts-and-how-do-i-use-them",
"status": "success",
"path": "support/9487310-what-are-artifacts-and-how-do-i-use-them.md",
- "sha256": "87608738138c78b18fe05dcebe4c618f967e1daa12bffe35183f625944b9fef0",
- "size": 11900
+ "sha256": "f55195e3cefc3a4206d4eade21e24f01f9c40d3d306ef26d82f3333320287e97",
+ "size": 11945
},
{
"url": "https://support.claude.com/en/articles/9517075-what-are-projects",
@@ -8731,15 +8731,15 @@
"url": "https://support.claude.com/en/articles/9519177-how-can-i-create-and-manage-projects",
"status": "success",
"path": "support/9519177-how-can-i-create-and-manage-projects.md",
- "sha256": "067be8b20c32df8b3d6f0b1bca9a708d45fd78d72eef933f42a5f1ddbf9b599b",
- "size": 8855
+ "sha256": "a7101f9ae1e81ee7d0c22b9d470c0fb235faa95bcb22efcc929eac196a29e9d8",
+ "size": 8853
},
{
"url": "https://support.claude.com/en/articles/9519189-manage-project-visibility-and-sharing",
"status": "success",
"path": "support/9519189-manage-project-visibility-and-sharing.md",
- "sha256": "87ab9febd95afc82e1c991286a4614450aab3198e7307bafaf91d61194c0ae21",
- "size": 8567
+ "sha256": "661086f0b0731f0bd1597dad93f64b0483f20c91cf84d420b38f0c7aa75f6c3e",
+ "size": 8557
},
{
"url": "https://support.claude.com/en/articles/9519291-what-is-anthropic-s-policy-for-handling-governmental-requests-for-user-information",
@@ -8759,7 +8759,7 @@
"url": "https://support.claude.com/en/articles/9534590-cost-and-usage-reporting-in-the-claude-console",
"status": "success",
"path": "support/9534590-cost-and-usage-reporting-in-the-claude-console.md",
- "sha256": "70316668a7b99acf94678059c394d07b818d54bdbe013e984132c817874d87f0",
+ "sha256": "af5b87111c5e6a2b45a4b2b869e91c837e3e88b9facf2e9289ea7904dbe4ae87",
"size": 5102
},
{
@@ -8843,7 +8843,7 @@
"url": "https://support.claude.com/en/articles/9927533-disable-public-projects-for-your-organization",
"status": "success",
"path": "support/9927533-disable-public-projects-for-your-organization.md",
- "sha256": "95386d0e0dcec417caaee35477289e151f50a0c2662089e6102760fe6ced4b8a",
+ "sha256": "570eb1f9bbea3ba779c47d1b11df28210d6c29552ab0bf72ebf50ca040fca65e",
"size": 2580
},
{
@@ -8983,15 +8983,15 @@
"url": "https://support.claude.com/en/articles/10310342-how-do-i-log-out-of-all-active-sessions",
"status": "success",
"path": "support/10310342-how-do-i-log-out-of-all-active-sessions.md",
- "sha256": "61b13cffd50986fddf31cd60cc60de3916b434a8a529e775d093666f1acebcd1",
- "size": 2496
+ "sha256": "5176e345bf98d21627b1639eaaa80fe9245aaf1770b19fda065f204658fc2429",
+ "size": 2494
},
{
"url": "https://support.claude.com/en/articles/10366376-how-can-i-delete-my-claude-console-account",
"status": "success",
"path": "support/10366376-how-can-i-delete-my-claude-console-account.md",
- "sha256": "6acf9cd9a2b0436a62e8ffbf57968feee11db5f8c5c474f722588669e67a734e",
- "size": 3163
+ "sha256": "579fe3cf829cb4d5438ef2ee4431a34eb6e7686c3bdb9d4f045fd8e1895ac0f6",
+ "size": 3171
},
{
"url": "https://support.claude.com/en/articles/10366389-how-can-i-get-higher-rate-limits-on-the-claude-api",
@@ -9032,15 +9032,15 @@
"url": "https://support.claude.com/en/articles/10504844-manage-user-feedback-settings-on-team-and-enterprise-plans",
"status": "success",
"path": "support/10504844-manage-user-feedback-settings-on-team-and-enterprise-plans.md",
- "sha256": "6de03f928c056ddc37ffd9e092f3d281ad713627b76db4ee3870462b9b43c9de",
- "size": 1036
+ "sha256": "66ffe3dc10ea0e9425752b972c551dba8ceab5ddf734980ff4ed0285f1e4330a",
+ "size": 1038
},
{
"url": "https://support.claude.com/en/articles/10504853-manage-user-feedback-settings-on-claude-console",
"status": "success",
"path": "support/10504853-manage-user-feedback-settings-on-claude-console.md",
- "sha256": "ac035377873cc2cd1e838b2a24efa26a31be2460fb2e23fd437420dce6d155e7",
- "size": 997
+ "sha256": "6d3fc6701d6f9ef6f1a91ba0893ffd1a95ab961297e14124b84a3f66aa125ca6",
+ "size": 999
},
{
"url": "https://support.claude.com/en/articles/10534883-use-the-claude-widget-on-android",
@@ -9053,8 +9053,8 @@
"url": "https://support.claude.com/en/articles/10593882-share-and-unshare-chats",
"status": "success",
"path": "support/10593882-share-and-unshare-chats.md",
- "sha256": "2e578536d956ee8139b7a3c9e6d0647bfdc25b96e97d19a192c0ac337de494ba",
- "size": 4016
+ "sha256": "5bb195e6251deb7f4a511abc8376071dceba702b2a29edc74395e88fcbcd72a6",
+ "size": 4012
},
{
"url": "https://support.claude.com/en/articles/10684626-enable-and-use-web-search",
@@ -9081,7 +9081,7 @@
"url": "https://support.claude.com/en/articles/10949351-getting-started-with-local-mcp-servers-on-claude-desktop",
"status": "success",
"path": "support/10949351-getting-started-with-local-mcp-servers-on-claude-desktop.md",
- "sha256": "f089a68d699216137e97a376cc7f08a20af2e9a11c7c570e29b2545f6d501ad6",
+ "sha256": "2814b4c316dd5d3ce91bba8c8d5639766bcd267002394ad59bfe10127caf6e26",
"size": 8267
},
{
@@ -9116,7 +9116,7 @@
"url": "https://support.claude.com/en/articles/11101966-use-voice-mode",
"status": "success",
"path": "support/11101966-use-voice-mode.md",
- "sha256": "5f413b6cf2fdf4be139838f10c0b4d090c94c21dd22014c68e7acec91e924668",
+ "sha256": "f6d49ba31c009be4f6a8fb52f2f8e455da2695ed9689cbd642f2a03ff37fe66e",
"size": 10555
},
{
@@ -9249,8 +9249,8 @@
"url": "https://support.claude.com/en/articles/11725453-set-up-the-claude-lti-in-canvas-by-instructure",
"status": "success",
"path": "support/11725453-set-up-the-claude-lti-in-canvas-by-instructure.md",
- "sha256": "7b5671656ac4b5dd1e2d04143900a4a1249baf2bbd64ad3882b016eeb470f5e8",
- "size": 2746
+ "sha256": "b9bc41d21c6d7e3a254098d7370e001866a1eb0010e1a40e26501043d08bcc2a",
+ "size": 2748
},
{
"url": "https://support.claude.com/en/articles/11732894-who-owns-and-manages-the-data-of-my-claude-for-education-account",
@@ -9263,15 +9263,15 @@
"url": "https://support.claude.com/en/articles/11817273-use-claude-s-chat-search-and-memory-to-build-on-previous-context",
"status": "success",
"path": "support/11817273-use-claude-s-chat-search-and-memory-to-build-on-previous-context.md",
- "sha256": "9bb2bb6dc03581ebcf4e7fb08aab074b759f2052e480c53d3e5665a2cbae7dea",
+ "sha256": "406c662d690ee5b5afdb45b99fb79950afbf6c15d86fe400b538632c3e5a7aac",
"size": 25858
},
{
"url": "https://support.claude.com/en/articles/11818288-why-am-i-being-asked-to-verify-my-payment-method",
"status": "success",
"path": "support/11818288-why-am-i-being-asked-to-verify-my-payment-method.md",
- "sha256": "7ce52be3cb0f1a1a58502481738dc83dd8b14a2dbe178d14eedbec176e9f9120",
- "size": 816
+ "sha256": "cd6e399b23d2cbc7feda1158320e7150065e6aff4ca29c4efff2982479457aa4",
+ "size": 818
},
{
"url": "https://support.claude.com/en/articles/11825384-how-to-update-claude-for-ios",
@@ -9305,8 +9305,8 @@
"url": "https://support.claude.com/en/articles/11869629-use-claude-with-android-apps",
"status": "success",
"path": "support/11869629-use-claude-with-android-apps.md",
- "sha256": "21d93b75864175d00975ad241a2af2f26b0bdf11cc7e8830bd6bd3beb319d90a",
- "size": 13999
+ "sha256": "a5294fa10c57b4373e0c916e609ffcfd2a19de55ae56b89e9946297101b48d64",
+ "size": 13993
},
{
"url": "https://support.claude.com/en/articles/11932705-automated-security-reviews-in-claude-code",
@@ -9340,15 +9340,15 @@
"url": "https://support.claude.com/en/articles/12005970-manage-usage-credits-for-team-and-seat-based-enterprise-plans",
"status": "success",
"path": "support/12005970-manage-usage-credits-for-team-and-seat-based-enterprise-plans.md",
- "sha256": "fb0adff83c893a5aa787ba260f918eadf4845ec9e0d9bd51585b9646d4fdaa26",
- "size": 9709
+ "sha256": "9b50396129c11637e691670c126dd28c4efd681ff2dcaa9bc1e7670bba58dd11",
+ "size": 9699
},
{
"url": "https://support.claude.com/en/articles/12012173-get-started-with-claude-in-chrome",
"status": "success",
"path": "support/12012173-get-started-with-claude-in-chrome.md",
- "sha256": "f0e4588c5fa999075355127722bbf88d8f13fd5397b858712d45a2afd10da5a4",
- "size": 14853
+ "sha256": "4d88b3a00ad93eae3080f2a6ef684e091538cc5b91bb8aaec7fd7a93a10a7ad7",
+ "size": 14857
},
{
"url": "https://support.claude.com/en/articles/12053672-what-happens-to-a-user-s-data-when-they-are-removed-from-a-team-or-enterprise-organization",
@@ -9361,8 +9361,8 @@
"url": "https://support.claude.com/en/articles/12083917-change-your-team-plan-from-monthly-to-annual-billing",
"status": "success",
"path": "support/12083917-change-your-team-plan-from-monthly-to-annual-billing.md",
- "sha256": "f574c0bcc9474311ed216ca5662452faedae04d6189ab20edf0ba50660a05f73",
- "size": 1398
+ "sha256": "26bf095fc58270c6a59f1b4572afb543118a5f58d91388a0ced6495cdff17d2a",
+ "size": 1396
},
{
"url": "https://support.claude.com/en/articles/12109679-creating-a-new-account-after-deletion",
@@ -9375,7 +9375,7 @@
"url": "https://support.claude.com/en/articles/12111783-create-and-edit-files-with-claude",
"status": "success",
"path": "support/12111783-create-and-edit-files-with-claude.md",
- "sha256": "e0df3aef8ab9212a04586609dd5a076ab116be2b31c0a848801b5543393db980",
+ "sha256": "d2727c6211d572f9ad33103a1b4929979f18da5c4110a1327e380b666fe2457e",
"size": 17960
},
{
@@ -9403,22 +9403,22 @@
"url": "https://support.claude.com/en/articles/12157520-claude-code-usage-analytics",
"status": "success",
"path": "support/12157520-claude-code-usage-analytics.md",
- "sha256": "72ab6b74f9bafd8dc162119a97e8be30fcb354768d923c4b5b2de572ca65a3a2",
- "size": 6427
+ "sha256": "60b30d9ca57dc76680cd8cf8a06b18b4ecfe91e33cc97368a1b7798c1944ef18",
+ "size": 6431
},
{
"url": "https://support.claude.com/en/articles/12260368-use-incognito-chats",
"status": "success",
"path": "support/12260368-use-incognito-chats.md",
- "sha256": "e7b30e162cdac55cfd70b29c4721f9ccc72e4ea0a307c5ea368b7611760c3770",
- "size": 3757
+ "sha256": "25a5da52d7d24e92056c235ae84d8ea55e722f1dfb12bf736e106a569cf353d7",
+ "size": 3753
},
{
"url": "https://support.claude.com/en/articles/12293051-use-claude-in-xcode",
"status": "success",
"path": "support/12293051-use-claude-in-xcode.md",
- "sha256": "5fbb02ff1c13a276ca5c33ba227d2c7f7831ec2b754edeee2058ff5047a2bf42",
- "size": 1911
+ "sha256": "4c1641d447bf7c1b13eff74bc5352c8b6665557e522f1348b2b74a6b27eb476c",
+ "size": 1905
},
{
"url": "https://support.claude.com/en/articles/12304248-manage-api-key-environment-variables-in-claude-code",
@@ -9459,14 +9459,14 @@
"url": "https://support.claude.com/en/articles/12429409-manage-usage-credits-for-paid-claude-plans",
"status": "success",
"path": "support/12429409-manage-usage-credits-for-paid-claude-plans.md",
- "sha256": "6899556b59292bc050032f0389b115fd82105858dd0721cb21eaf9b6dafc82b2",
- "size": 6418
+ "sha256": "d4a42a3014844480a33c4e55b56007875e28645a61b8fa32f57c34dda657603f",
+ "size": 6412
},
{
"url": "https://support.claude.com/en/articles/12466728-troubleshoot-claude-error-messages",
"status": "success",
"path": "support/12466728-troubleshoot-claude-error-messages.md",
- "sha256": "243f330dd2fa3a37fd2aa4ca66e6f1d3d6bfc3d74d6f9e4fc885a2be292ff3f4",
+ "sha256": "485007172536212661b61f07aa0d83eb8622b743da455cda56c07fef94041c0c",
"size": 4234
},
{
@@ -9487,8 +9487,8 @@
"url": "https://support.claude.com/en/articles/12512180-use-skills-in-claude",
"status": "success",
"path": "support/12512180-use-skills-in-claude.md",
- "sha256": "3186a2b0b903a604392dc483b0c020ece5ef50a6601d5bf7f9cc22fd550f9976",
- "size": 15920
+ "sha256": "46ee691b40e2d0d0e8271e6ef774b4e498e64069e21017aaa2a300f21935b749",
+ "size": 15918
},
{
"url": "https://support.claude.com/en/articles/12512198-how-to-create-custom-skills",
@@ -9501,15 +9501,15 @@
"url": "https://support.claude.com/en/articles/12542951-set-up-the-microsoft-365-connector",
"status": "success",
"path": "support/12542951-set-up-the-microsoft-365-connector.md",
- "sha256": "65abb44427b7c54c90c579eeb46caccbaea6accec3cf52bb06af1178ac80bf24",
- "size": 21753
+ "sha256": "23d6ad280de12ca3866afbd517e4d5c2313c59d0120e4ed32f05b46f2beb64fe",
+ "size": 21824
},
{
"url": "https://support.claude.com/en/articles/12592343-enabling-and-using-the-desktop-extension-allowlist",
"status": "success",
"path": "support/12592343-enabling-and-using-the-desktop-extension-allowlist.md",
- "sha256": "8d959ff55f67f91ba88f6cca3e509b91b56427b9b8d39e12645441e1516dfdf7",
- "size": 5720
+ "sha256": "2e73fd7d35f8a24a48d7e316f0e11d6ce0aa3d0188ca63b07e756a0964bf581b",
+ "size": 5706
},
{
"url": "https://support.claude.com/en/articles/12611117-deploy-claude-desktop-for-macos",
@@ -9522,8 +9522,8 @@
"url": "https://support.claude.com/en/articles/12618689-claude-code-on-the-web",
"status": "success",
"path": "support/12618689-claude-code-on-the-web.md",
- "sha256": "ce6d426fbb4d02fe0dc5cd56e4893b69ecd1b99dbca4ce07c7aec237991f7d97",
- "size": 10966
+ "sha256": "bcd5aa87e95557c2264486925c5e74901ec67b1a9126257a74ffc17fef76e969",
+ "size": 10962
},
{
"url": "https://support.claude.com/en/articles/12622667-enterprise-configuration-for-claude-desktop",
@@ -9543,15 +9543,15 @@
"url": "https://support.claude.com/en/articles/12626668-use-quick-entry-with-claude-desktop-on-mac",
"status": "success",
"path": "support/12626668-use-quick-entry-with-claude-desktop-on-mac.md",
- "sha256": "fd4b773649314f8e318aa80a0b2a795f56787918ae6cd211c8232f6450dce6e9",
- "size": 5972
+ "sha256": "230d210cfd7d033185362bf5d1b9dade159d38c8ee40ecec40ccb330c1666468",
+ "size": 5974
},
{
"url": "https://support.claude.com/en/articles/12684923-microsoft-365-connector-security-guide",
"status": "success",
"path": "support/12684923-microsoft-365-connector-security-guide.md",
- "sha256": "f815a93b320cf6aaf872d489f3001c04b260618c5651892cd105badc12b91a27",
- "size": 26174
+ "sha256": "b8629bdfd92bf6f22e39f749df7e628d9038b97f2dbd9eedc6ef5f96dd7add3f",
+ "size": 26323
},
{
"url": "https://support.claude.com/en/articles/12702546-deploying-enterprise-grade-mcp-servers-with-desktop-extensions",
@@ -9578,8 +9578,8 @@
"url": "https://support.claude.com/en/articles/12883420-view-usage-analytics-for-team-and-enterprise-plans",
"status": "success",
"path": "support/12883420-view-usage-analytics-for-team-and-enterprise-plans.md",
- "sha256": "9666a09c4e5baa4db86a3f236dd7767ebde9316ab0bedb88b49db542858ff28c",
- "size": 14517
+ "sha256": "42ac1398bba7ad2560efa2ba09f4e04df4873e97bfba482eec6ce0d9d287376a",
+ "size": 14519
},
{
"url": "https://support.claude.com/en/articles/12902405-claude-in-chrome-troubleshooting",
@@ -9599,7 +9599,7 @@
"url": "https://support.claude.com/en/articles/12902446-claude-in-chrome-permissions-guide",
"status": "success",
"path": "support/12902446-claude-in-chrome-permissions-guide.md",
- "sha256": "f04832b8317fcf8ab8797643024c9c292fef5b2b1feac5be30165e431461ebd5",
+ "sha256": "474eadd8464b094ca3a02d2f8005b72c82cff55c8760251f8cd284746df3cbec",
"size": 9563
},
{
@@ -9627,7 +9627,7 @@
"url": "https://support.claude.com/en/articles/12997503-team-plan-billing-faqs",
"status": "success",
"path": "support/12997503-team-plan-billing-faqs.md",
- "sha256": "9ee3f860236269b583d2003cb79cb2616afda5891cf71df6d9454b947bdab7e8",
+ "sha256": "5f68f1206c26971f8c0537d94b848624495f2f3eb96072d8febf81585cb97018",
"size": 4853
},
{
@@ -9676,15 +9676,15 @@
"url": "https://support.claude.com/en/articles/13132885-set-up-single-sign-on-sso",
"status": "success",
"path": "support/13132885-set-up-single-sign-on-sso.md",
- "sha256": "a12802dc8c8c441da006fe2ac6d9826be8d92f681a67265d9d5e937774615e45",
+ "sha256": "7eb4f999b4dd71167802bedcd5517be4afc0e45a71649151c2831189e6189f91",
"size": 13337
},
{
"url": "https://support.claude.com/en/articles/13133195-set-up-jit-or-scim-provisioning",
"status": "success",
"path": "support/13133195-set-up-jit-or-scim-provisioning.md",
- "sha256": "40c84cf2183ec56cfb96747020dbf99fd7de7675564f26005a2665f11e21024e",
- "size": 20340
+ "sha256": "faf34cd27150ec3b881b988014bcfbf977b4b7b9808b4f4ad052e8741f9eab13",
+ "size": 20338
},
{
"url": "https://support.claude.com/en/articles/13133750-manage-members-on-team-and-enterprise-plans",
@@ -9711,8 +9711,8 @@
"url": "https://support.claude.com/en/articles/13163631-configuring-session-security-settings",
"status": "success",
"path": "support/13163631-configuring-session-security-settings.md",
- "sha256": "62d6256605e7ec64c9833a7e8cbd5d61e56ab7a7466067b298af6e0721d62ff6",
- "size": 3696
+ "sha256": "eb1768e037a7ddead2fd6eb36b7a4dc1d971b0bb17bf4c718b188b60c0c68bfc",
+ "size": 3698
},
{
"url": "https://support.claude.com/en/articles/13171706-crisis-helpline-support-in-claude",
@@ -9725,7 +9725,7 @@
"url": "https://support.claude.com/en/articles/13189465-log-in-to-your-claude-account",
"status": "success",
"path": "support/13189465-log-in-to-your-claude-account.md",
- "sha256": "7ae017e6264cc64cb8576926b65947cc882fb8b8901669bea48cf9b47ebcf9b4",
+ "sha256": "9b337ccb8824338f8f16b33caf5d3fbe3fd9bbbf80cfb1cdf7f9afed9a269232",
"size": 7038
},
{
@@ -9753,22 +9753,22 @@
"url": "https://support.claude.com/en/articles/13325567-account-management-faqs",
"status": "success",
"path": "support/13325567-account-management-faqs.md",
- "sha256": "f8b25c2db44a16840c7d89f0b39c26791f4d4e0770e8a8510a0b3282998c1c4a",
+ "sha256": "218978b70695cbadf423481379cf4d10bbadd49b47e9222971af2872c2982165",
"size": 2634
},
{
"url": "https://support.claude.com/en/articles/13345190-get-started-with-claude-cowork",
"status": "success",
"path": "support/13345190-get-started-with-claude-cowork.md",
- "sha256": "bb6cfd2c42a33be2e01a74b5e21ae6faa5f92c960eeb86f4f45daadc986a0073",
- "size": 23097
+ "sha256": "638f0ac8ba38de30ee13e7cbeb2888f4ac3f27f119756db7f851c3dbfb40b0ec",
+ "size": 22657
},
{
"url": "https://support.claude.com/en/articles/13346458-customizing-your-console-appearance-settings",
"status": "success",
"path": "support/13346458-customizing-your-console-appearance-settings.md",
- "sha256": "01b08421432027393ceceac28499dd422f3403bc05ba2b541f6c67f9abd80b35",
- "size": 605
+ "sha256": "3736968274639268e2278cdb6241669271af81a52946fc3578c9f2c35da66422",
+ "size": 609
},
{
"url": "https://support.claude.com/en/articles/13346720-export-your-organization-s-data",
@@ -9788,8 +9788,8 @@
"url": "https://support.claude.com/en/articles/13371040-log-in-to-your-console-account",
"status": "success",
"path": "support/13371040-log-in-to-your-console-account.md",
- "sha256": "949f08ddf2721bb1272f682be9d352770c5a83b54594f06c38cb866d5ef855ff",
- "size": 4609
+ "sha256": "f48c07d20a64083c80ec03be21daa50c957fea2c9fcf4eb63db41535fd8ca0bd",
+ "size": 4611
},
{
"url": "https://support.claude.com/en/articles/13393991-purchase-and-manage-seats-on-enterprise-plans",
@@ -9830,8 +9830,8 @@
"url": "https://support.claude.com/en/articles/13455879-use-claude-cowork-on-team-and-enterprise-plans",
"status": "success",
"path": "support/13455879-use-claude-cowork-on-team-and-enterprise-plans.md",
- "sha256": "7468c0297ab3eef4c441356b879a1b582d4f2468f6da2f1f9e3e07a348a435f7",
- "size": 13367
+ "sha256": "fc1d9748e33b7e389fea90ca2bbe05af8fc103d8bb39941c24897a7b2c233d75",
+ "size": 12465
},
{
"url": "https://support.claude.com/en/articles/13566435-find-and-join-a-team-or-enterprise-organization",
@@ -9844,8 +9844,8 @@
"url": "https://support.claude.com/en/articles/13641943-visual-and-interactive-content",
"status": "success",
"path": "support/13641943-visual-and-interactive-content.md",
- "sha256": "ed9fdda2e7a0ac3600861546e8eb2e02abc32e055eda5382f2472bd5463b3137",
- "size": 6511
+ "sha256": "1eb3b47ad02599ada09b13c4abc5f7ff43714e06aa2b64b28aa050bbbc216e2b",
+ "size": 6507
},
{
"url": "https://support.claude.com/en/articles/13663666-use-visual-and-interactive-content-on-team-and-enterprise-plans",
@@ -9872,8 +9872,8 @@
"url": "https://support.claude.com/en/articles/13756069-public-sector-faqs",
"status": "success",
"path": "support/13756069-public-sector-faqs.md",
- "sha256": "cedc876d925ae1c2ed2aee9c5992507fbc6f01dc8a168ecbf1c7c15140d347a5",
- "size": 8378
+ "sha256": "8a96e8b5c9b1699ba161375205a504004a2167a7225d477bdedea71e51cd05c5",
+ "size": 8382
},
{
"url": "https://support.claude.com/en/articles/13776697-join-an-organization-via-invite-link",
@@ -9893,22 +9893,22 @@
"url": "https://support.claude.com/en/articles/13799932-manage-groups-and-group-spend-limits-on-enterprise-plans",
"status": "success",
"path": "support/13799932-manage-groups-and-group-spend-limits-on-enterprise-plans.md",
- "sha256": "d4aa6ac51f43a26d2faf8a38d8428e09700ac91bd882e2689dc03ed42e028007",
- "size": 12953
+ "sha256": "3c60811c36c13e78e1633034b81e5e75cf7a710138fd83fc745565d2ec2f07ed",
+ "size": 12956
},
{
"url": "https://support.claude.com/en/articles/13837433-manage-plugins-for-your-organization",
"status": "success",
"path": "support/13837433-manage-plugins-for-your-organization.md",
- "sha256": "2a9f38296f2b8a9a2f39e202089df7a4a98f3bf2eeb785d266645ea40462f53c",
- "size": 21285
+ "sha256": "1efc23f8412667a61bed1869b40f58357bf5bc9733ef401d9749dd4f9f20e88b",
+ "size": 21287
},
{
"url": "https://support.claude.com/en/articles/13837440-use-plugins-in-claude",
"status": "success",
"path": "support/13837440-use-plugins-in-claude.md",
- "sha256": "9d4aaede4a5f706ecf4c605132c5824a8c765b9c8e77b431fb3d0c8c9f2a62b1",
- "size": 10881
+ "sha256": "35c85ef6c63db109fab84af468af8b28be72ac1249ea8b8f4da31646d20ad2ed",
+ "size": 10875
},
{
"url": "https://support.claude.com/en/articles/13854387-schedule-recurring-tasks-in-claude-cowork",
@@ -10005,8 +10005,8 @@
"url": "https://support.claude.com/en/articles/13947068-assign-tasks-from-anywhere-in-claude-cowork",
"status": "success",
"path": "support/13947068-assign-tasks-from-anywhere-in-claude-cowork.md",
- "sha256": "8f57932e553c78f376a8be22e409e56483d84900a79162a03c9574be4d91be5e",
- "size": 9229
+ "sha256": "8e48debacd0b40ea9da4cb9c7045a91332948d21dd2508c048654db506763db6",
+ "size": 9231
},
{
"url": "https://support.claude.com/en/articles/13979539-custom-visuals-in-chat-and-cowork",
@@ -10026,8 +10026,8 @@
"url": "https://support.claude.com/en/articles/14116274-organize-your-tasks-with-projects-in-claude-cowork",
"status": "success",
"path": "support/14116274-organize-your-tasks-with-projects-in-claude-cowork.md",
- "sha256": "acff92eb2e6eef78ac0e4d5f5d0ce2a0751172bae04977c73b3b09adbde0a5d5",
- "size": 6826
+ "sha256": "893d213e30d7a59ef87b9ffe9a459a475df8c5b7c08628bdb5cb4793785d563d",
+ "size": 6820
},
{
"url": "https://support.claude.com/en/articles/14128542-let-claude-use-your-computer-in-cowork",
@@ -10096,8 +10096,8 @@
"url": "https://support.claude.com/en/articles/14499648-how-scim-sync-works-for-enterprise-organizations",
"status": "success",
"path": "support/14499648-how-scim-sync-works-for-enterprise-organizations.md",
- "sha256": "14d546a4878e063f68f589ae4edd1e030866e38c6daaa9a5cfb572d906a998ac",
- "size": 7672
+ "sha256": "31241c5a648ed392ac8d48dc1b3c2c7dca2c437b461b9323e59f1cfa35b4c971",
+ "size": 7674
},
{
"url": "https://support.claude.com/en/articles/14503520-available-beta-and-research-preview-features",
@@ -10110,22 +10110,22 @@
"url": "https://support.claude.com/en/articles/14503590-get-started-with-claude-for-government",
"status": "success",
"path": "support/14503590-get-started-with-claude-for-government.md",
- "sha256": "5504c2565169112a91e575fc6385acf9ec211ff326eb1878b0a81ae840bc52f1",
- "size": 4570
+ "sha256": "9cb5edf60213654614cc2e416a8eab4e568f6b91b1ef333d320952423d8bf48b",
+ "size": 1418
},
{
"url": "https://support.claude.com/en/articles/14503613-sso-login",
"status": "success",
"path": "support/14503613-sso-login.md",
- "sha256": "1802d5ee7daf38230842a592bbf930be717224ca857d33039916de1438fc818a",
- "size": 6684
+ "sha256": "56fd38aa47b634d40abd248b3c97a13094666a4cc616caacc268ecb7dea7ae7e",
+ "size": 6682
},
{
"url": "https://support.claude.com/en/articles/14503643-set-up-scim-in-claude-for-government",
"status": "success",
"path": "support/14503643-set-up-scim-in-claude-for-government.md",
- "sha256": "5ffa90de3b88dddafdd28a4285d85a58dfb6625f555d34aefad610ceb912a737",
- "size": 6425
+ "sha256": "289d505bffafd45f3c48f1dd8b4efd4e44227ecd7ba23c81b401f5da928b4063",
+ "size": 6417
},
{
"url": "https://support.claude.com/en/articles/14503675-organization-instructions-in-claude-for-government",
@@ -10152,8 +10152,8 @@
"url": "https://support.claude.com/en/articles/14503775-mcp-web-search",
"status": "success",
"path": "support/14503775-mcp-web-search.md",
- "sha256": "779de7ba14b43792f0298a2ddac97bfeaf9c7aaaaad052270f3f9e48f513efb3",
- "size": 4677
+ "sha256": "9cc67925182da2e3b27d9dd43d58599a2a1b7e7267605d15d91ea3a65f538282",
+ "size": 4679
},
{
"url": "https://support.claude.com/en/articles/14503794-model-availability-in-claude-for-government",
@@ -10250,8 +10250,8 @@
"url": "https://support.claude.com/en/articles/14604397-set-up-your-design-system-in-claude-design",
"status": "success",
"path": "support/14604397-set-up-your-design-system-in-claude-design.md",
- "sha256": "9a81d24d80cff34e7c84910fa7262501f1598afabce23f861695adef2b86c4dd",
- "size": 5764
+ "sha256": "992e7427e76663e9ae3b0695dc291a741df326fc717c2f2b842d20761705b518",
+ "size": 5762
},
{
"url": "https://support.claude.com/en/articles/14604406-claude-design-admin-guide-for-team-and-enterprise-plans",
@@ -10264,8 +10264,8 @@
"url": "https://support.claude.com/en/articles/14604416-get-started-with-claude-design",
"status": "success",
"path": "support/14604416-get-started-with-claude-design.md",
- "sha256": "8c4093a2e624cc9c25b59c65556cf3fc4490dca72fb51e2cd06745e2c9971b99",
- "size": 13651
+ "sha256": "e613c97f50e33bbf6b2dea313496a21fe942ff5ca55495c9fe7fc39ab9068781",
+ "size": 13676
},
{
"url": "https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude-opus-and-sonnet",
@@ -10390,8 +10390,8 @@
"url": "https://support.claude.com/en/articles/15330088-set-a-default-model-for-your-organization",
"status": "success",
"path": "support/15330088-set-a-default-model-for-your-organization.md",
- "sha256": "637c45e08a61a06ff73de906437016fe60f819b815527aa47eee77d9fc0e2eb6",
- "size": 8910
+ "sha256": "3da5e26aef1e78ff443bb14bbab2e328a567759151d0c7a7a11c1388d9c894ac",
+ "size": 8914
},
{
"url": "https://support.claude.com/en/articles/15330651-claude-enterprise-admin-api-reference-guide",
@@ -10502,8 +10502,8 @@
"url": "https://support.claude.com/en/articles/15694740-manage-model-access-for-your-organization",
"status": "success",
"path": "support/15694740-manage-model-access-for-your-organization.md",
- "sha256": "976739febefd8888733c2237928d666198e6871b601e2639f99ab1971b9851b2",
- "size": 10143
+ "sha256": "7778900968c27c80a3997ff71c6d63253051ea316c964e3736aa42db8751e359",
+ "size": 10145
},
{
"url": "https://support.claude.com/en/articles/15707726-using-claude-for-legal-work-privilege-confidentiality-and-how-to-think-about-configuration",
@@ -10537,8 +10537,8 @@
"url": "https://support.claude.com/en/articles/15936181-get-started-with-1password-for-claude",
"status": "success",
"path": "support/15936181-get-started-with-1password-for-claude.md",
- "sha256": "b466af8d5810ec03feed5d4e31122a2fa7a7965fcf958ebac49c910c1a1b36cd",
- "size": 5056
+ "sha256": "397f0247ebd7107f5a57214bc4e083857000d14d923e50115e849c70a7f21126",
+ "size": 5058
},
{
"url": "https://support.claude.com/en/articles/16049681-why-claude-switched-models-in-your-conversation-with-opus-5",
@@ -10586,8 +10586,8 @@
"url": "https://support.claude.com/en/articles/16607638-understanding-your-pro-or-max-plan-invoices",
"status": "success",
"path": "support/16607638-understanding-your-pro-or-max-plan-invoices.md",
- "sha256": "f2ba45d095489b902e9c85c8dc75388c03e1d678346680e202065ca8676972be",
- "size": 5437
+ "sha256": "ac531a1cbe78e235f2c2d782dce55885adb321bba101405ed695166942275bb2",
+ "size": 5435
},
{
"url": "https://support.claude.com/en/articles/16607668-understanding-your-team-plan-invoices",
@@ -10656,8 +10656,8 @@
"url": "https://support.claude.com/en/articles/16764810-assign-a-program-to-workspaces-in-claude-console",
"status": "success",
"path": "support/16764810-assign-a-program-to-workspaces-in-claude-console.md",
- "sha256": "6bca88eb9bbea044fc42b45566ecd54847034f08f09ea8c5ec46a0bae8092d91",
- "size": 5099
+ "sha256": "1794b5fc65ebb95fc1e6ba35a54a9cd6f4282823f1316ce7cd1eb1ed37385f77",
+ "size": 5107
},
{
"url": "https://support.claude.com/en/articles/16824617-turn-on-data-retention-for-a-workspace-in-a-zero-data-retention-organization",
@@ -10670,8 +10670,8 @@
"url": "https://support.claude.com/en/articles/16893491-get-started-with-smart-reports",
"status": "success",
"path": "support/16893491-get-started-with-smart-reports.md",
- "sha256": "bd505d6f8299fda7b39bca7a47f75fcee591fae4f85e7cb5a6900ac586b7d5e0",
- "size": 14110
+ "sha256": "f52935f6b4ec7e783fcbe87d5b316575c090eae658287a891ee96b4430d42631",
+ "size": 14114
},
{
"url": "https://support.claude.com/en/articles/16923645-get-started-with-claude-docs",
@@ -10701,26 +10701,33 @@
"sha256": "7956afb76c5f40ad66939492b066be447d92a35034a35ca048b14afb2b46a33a",
"size": 2812
},
+ {
+ "url": "https://support.claude.com/en/articles/16989529-invite-people-outside-your-organization-to-an-artifact",
+ "status": "success",
+ "path": "support/16989529-invite-people-outside-your-organization-to-an-artifact.md",
+ "sha256": "8efb13b417cbc692daf3440f5cc5cd96d82e659480815b38d953088bf2de9a1e",
+ "size": 7430
+ },
{
"url": "https://claude.com/docs/claude-science/admin-controls",
"status": "success",
"path": "claude/claude-science/admin-controls.md",
- "sha256": "1deeeed1b46c27a0f140a78b84613ca84008ad24471009fa63d9ce52e1668a58",
- "size": 60406
+ "sha256": "06ed167b61f6cd8448f8f85f8f4d4885be60fb8448ad6162734059261b1a1d65",
+ "size": 60438
},
{
"url": "https://claude.com/docs/claude-science/artifacts",
"status": "success",
"path": "claude/claude-science/artifacts.md",
- "sha256": "35f7d26d1115d1fee394600474e3f71045ad3e959344d46bd62bf3ffc7a9df93",
- "size": 2914
+ "sha256": "c4a28213dc7e961ab55db2390122edd01a5125b57fd518bc65eff1e2eacfd805",
+ "size": 2945
},
{
"url": "https://claude.com/docs/claude-science/changelog",
"status": "success",
"path": "claude/claude-science/changelog.md",
- "sha256": "c77b98aa131717924043047d95097db69ce3aeb542c4bc7da41b1e014a45f4fe",
- "size": 12174
+ "sha256": "40150519f2ad3b35bc1cfa2b95f774f5e543978b24c0063f68bbd6a51987242f",
+ "size": 13112
},
{
"url": "https://claude.com/docs/claude-science/cloud-storage",
@@ -10796,8 +10803,8 @@
"url": "https://claude.com/docs/claude-science/get-started",
"status": "success",
"path": "claude/claude-science/get-started.md",
- "sha256": "23a6c45b184e464881bfc248d16bc05e9f110d2eae3a4db3ae3421568a51689e",
- "size": 11382
+ "sha256": "56509a0a36760c3129be6c3d0fd8fe0253c4b0e9406b45ef0b75ea2771ea6502",
+ "size": 11414
},
{
"url": "https://claude.com/docs/claude-science/glossary",
@@ -10845,8 +10852,8 @@
"url": "https://claude.com/docs/claude-science/multiple-computers",
"status": "success",
"path": "claude/claude-science/multiple-computers.md",
- "sha256": "1d9d8f07cd5c546142a16ca949ddd4cb4b5875eba1f3d06041dd74bf0c84aa0b",
- "size": 4068
+ "sha256": "f1083d87bf232e7734b87303be52fc436679df85ad2c2d454dced0fd04312152",
+ "size": 4145
},
{
"url": "https://claude.com/docs/claude-science/network-requirements",
@@ -11685,8 +11692,8 @@
"url": "https://claude.com/docs/cowork/changelog",
"status": "success",
"path": "claude/cowork/changelog.md",
- "sha256": "41f057e52e1c84a008fb9caa27f7d8ac270760ebf44940dea43429dcf4198482",
- "size": 155342
+ "sha256": "7f4b6ace4532ee57dafeab5abbf0a1ba0f431ba3deb5542265d6efd652b9769e",
+ "size": 155328
},
{
"url": "https://claude.com/docs/cowork/guide/dispatch",
@@ -11755,8 +11762,8 @@
"url": "https://claude.com/docs/government/changelog",
"status": "success",
"path": "claude/government/changelog.md",
- "sha256": "7723c08ba21574a90359e242c1f11aac7a5a5c6d4ee816ad34265b59dbed89c6",
- "size": 9020
+ "sha256": "57156a27e4f83df07725dcd1d6afc2788edc61dab0b6e3bc60d374867085aca9",
+ "size": 10600
},
{
"url": "https://claude.com/docs/government/config/overview",
@@ -12119,8 +12126,8 @@
"url": "https://claude.com/docs/third-party/claude-desktop/admin-console",
"status": "success",
"path": "claude/third-party/claude-desktop/admin-console.md",
- "sha256": "751d9b96b5579dd44632f2367614f423a27f7353bc71d47e0bd2be1bfcbfef50",
- "size": 64208
+ "sha256": "153b1ad87e2eb4023eb692dd305df445b2253281796f46247166242994f673c6",
+ "size": 63826
},
{
"url": "https://claude.com/docs/third-party/claude-desktop/bedrock",
@@ -12140,8 +12147,8 @@
"url": "https://claude.com/docs/third-party/claude-desktop/browser",
"status": "success",
"path": "claude/third-party/claude-desktop/browser.md",
- "sha256": "4e7223f587b5ce85994cfb559cb27f6be442c9d299c88468248c1493b5224256",
- "size": 10345
+ "sha256": "e3d10bd35e8b02b82a136ef7cb7bf382422c8660a5c40146e025894e2f0ca5bc",
+ "size": 10368
},
{
"url": "https://claude.com/docs/third-party/claude-desktop/built-in-connectors",
@@ -12301,8 +12308,8 @@
"url": "https://claude.com/docs/third-party/claude-desktop/local-access",
"status": "success",
"path": "claude/third-party/claude-desktop/local-access.md",
- "sha256": "fbfd7494f9c906c4075db938590336f9d62d5e816187e7a85d25252cf8c26322",
- "size": 7643
+ "sha256": "90ed98efcb2392fabe55d467f8fbb04bb32f52edff06cbe54c7c3bf823e8b5b2",
+ "size": 7957
},
{
"url": "https://claude.com/docs/third-party/claude-desktop/mantle",
@@ -12322,7 +12329,7 @@
"url": "https://claude.com/docs/third-party/claude-desktop/mdm",
"status": "success",
"path": "claude/third-party/claude-desktop/mdm.md",
- "sha256": "d8d2219cd8ac4b26bfba49cbd7ae9368e76fb234137f2fe1e040c64a50c9375a",
+ "sha256": "ea6e41e9b18e4dc7d3efe62a0887a76c2781b09fed0066385b083d802bf170c1",
"size": 17198
},
{
@@ -12378,8 +12385,8 @@
"url": "https://code.claude.com/docs/en/desktop-changelog",
"status": "success",
"path": "en/docs/claude-code/desktop-changelog.md",
- "sha256": "bfc2f76c8b2b58d3ad2f02610373670d670439b059e9e2409d0d2532c6d5d8bd",
- "size": 103453
+ "sha256": "622a094b23496a6dafc308b0ce9e466e96423bd3f5707faff25183313a75ef40",
+ "size": 103817
},
{
"url": "https://code.claude.com/docs/en/slash-commands",
@@ -12392,8 +12399,8 @@
"url": "https://code.claude.com/docs/en/web-scheduled-tasks",
"status": "success",
"path": "en/docs/claude-code/web-scheduled-tasks.md",
- "sha256": "d76aa5af0d53c71ec2496c591db62a2774baf98e4455e5876adc328eaf1e5d2d",
- "size": 33670
+ "sha256": "a893163ca0f7d804962a6b304a30944fa95c84f781c7d61b59b38de2d3b51fc0",
+ "size": 35382
},
{
"url": "https://code.claude.com/docs/en/ultraplan",
@@ -12434,8 +12441,8 @@
"url": "https://platform.claude.com/docs/en/api/java/beta",
"status": "success",
"path": "en/api/java/beta.md",
- "sha256": "96079b1673582b539b33008c9c787a4540223d865b6c7d29f9807ccce5720e3c",
- "size": 2421710
+ "sha256": "04dd4cd3f3be8cdcf53898bb29522a24593ed16c1a2b53cb9df5519bd09dbaca",
+ "size": 2421692
},
{
"url": "https://platform.claude.com/docs/en/api/java/models",
@@ -12462,8 +12469,8 @@
"url": "https://platform.claude.com/docs/en/api/go/beta",
"status": "success",
"path": "en/api/go/beta.md",
- "sha256": "65db7c78d3ccd8e39e5da39a8f6bfab06bd69f454793621d08896a3d69b8caa8",
- "size": 2861231
+ "sha256": "ef5c84caf507a1f41fbdeec0cffac47962de8cce16c6c4e0a2ed7204b2d7700f",
+ "size": 2861213
},
{
"url": "https://platform.claude.com/docs/en/api/go/models",
@@ -12490,8 +12497,8 @@
"url": "https://platform.claude.com/docs/en/api/csharp/beta",
"status": "success",
"path": "en/api/csharp/beta.md",
- "sha256": "4e443bbe4305a9608ccec850f74536edb3a2769a7283d0728b7ac5f9c1c0a0be",
- "size": 2418757
+ "sha256": "006a5d3b7bbe5a6199ca9ce5268fa45ce24890b8ccb70c2ff6c9839bdad11990",
+ "size": 2418739
},
{
"url": "https://platform.claude.com/docs/en/api/csharp/models",
@@ -12518,8 +12525,8 @@
"url": "https://platform.claude.com/docs/en/api/typescript/beta",
"status": "success",
"path": "en/api/typescript/beta.md",
- "sha256": "740bb7dfa5e78bc0e1fa7331a9dd39df2aeaa77256335c685a3924b3ea68f5bf",
- "size": 2373543
+ "sha256": "7f782aae74103b65437557c468dc0545ad446f8179d0e46043da538eefdeefe7",
+ "size": 2373525
},
{
"url": "https://platform.claude.com/docs/en/api/typescript/models",
@@ -12546,8 +12553,8 @@
"url": "https://platform.claude.com/docs/en/api/ruby/beta",
"status": "success",
"path": "en/api/ruby/beta.md",
- "sha256": "a39325514dbd27eba6bd58b52e5a8319e2c3ffd016c0619d48ad104f438d21a3",
- "size": 2218426
+ "sha256": "e456e19c2d0020f3cbe782fd596ffaee98308f1ac6c9b78d69e5143d03d8878a",
+ "size": 2218408
},
{
"url": "https://platform.claude.com/docs/en/api/ruby/models",
@@ -12602,8 +12609,8 @@
"url": "https://platform.claude.com/docs/en/api/python/beta",
"status": "success",
"path": "en/api/python/beta.md",
- "sha256": "24459fb5ac974ee28dec22c18780b693674a4d6490f3a18707912107a864d4d4",
- "size": 2278827
+ "sha256": "5db9c63d612c43021ddb28a4374dafa79c9fcd835c82b26c945be94498582948",
+ "size": 2278809
},
{
"url": "https://platform.claude.com/docs/en/api/python/models",
@@ -13743,8 +13750,8 @@
"url": "https://platform.claude.com/docs/en/api/python/beta/messages",
"status": "success",
"path": "en/api/python/beta/messages.md",
- "sha256": "987f4ac45d0fbfae7128cef3615fa35a1fb086b4f5799135305df812304afd41",
- "size": 1428427
+ "sha256": "2ecb31a27a59d77b6a00908bf0138e718929d5ef9fef484564ea4d3072cbe2b7",
+ "size": 1428388
},
{
"url": "https://platform.claude.com/docs/en/api/python/beta/tunnels",
@@ -14191,22 +14198,22 @@
"url": "https://platform.claude.com/docs/en/api/python/beta/messages/create",
"status": "success",
"path": "en/api/python/beta/messages/create.md",
- "sha256": "63b5f3833b40dea51a23dfe5a98342c0ca869ca7694e168f4643423fcacbfe51",
- "size": 199212
+ "sha256": "ab99d94ce8d1fb9389554392827981a594c1ba9a2d17efb5b1a6bfd26ec26e0d",
+ "size": 199206
},
{
"url": "https://platform.claude.com/docs/en/api/python/beta/messages/batches",
"status": "success",
"path": "en/api/python/beta/messages/batches.md",
- "sha256": "d330303f472a30727e2d63ebdabc67483551cda375932433b4c0382f7bb805fb",
- "size": 427297
+ "sha256": "cc9673eb03d2cf347e65a4b69c8686f1bbd68c77e2007291f4ed7f2a879bca93",
+ "size": 427291
},
{
"url": "https://platform.claude.com/docs/en/api/python/beta/messages/count_tokens",
"status": "success",
"path": "en/api/python/beta/messages/count_tokens.md",
- "sha256": "9fdc04a2ebe901dc7c5f84220f59aa39bb814b28ddd734f37b4f3cd3c93b51de",
- "size": 122905
+ "sha256": "df24f2a15770d266b451e53de193dcb16f6ca307d561193fd1f8e7d8c24e6db4",
+ "size": 122899
},
{
"url": "https://platform.claude.com/docs/en/api/python/beta/deployment_runs/list",
@@ -14548,8 +14555,8 @@
"url": "https://platform.claude.com/docs/en/api/python/beta/messages/batches/create",
"status": "success",
"path": "en/api/python/beta/messages/batches/create.md",
- "sha256": "af72fa40c4e42c5ce76d6cedb0efb4ebf2abdb1bff2c150c50079495c75c84e1",
- "size": 142875
+ "sha256": "a191ca48cec2aae3fe645cc172aa5e49643b26156926fff75b4f96d826a2d6c2",
+ "size": 142869
},
{
"url": "https://platform.claude.com/docs/en/api/python/beta/messages/batches/results",
@@ -14814,8 +14821,8 @@
"url": "https://platform.claude.com/docs/en/api/cli/beta/messages",
"status": "success",
"path": "en/api/cli/beta/messages.md",
- "sha256": "eeba94fb26abd7c6cc424b0b6b7f354a29978fa6eec1dc58cb81f73a88b6c891",
- "size": 1116046
+ "sha256": "7e7ffbf94295707e66a00e198f1ab1ae25735c9694525e0d2188abaa55271313",
+ "size": 1116025
},
{
"url": "https://platform.claude.com/docs/en/api/cli/beta/tunnels",
@@ -15885,8 +15892,8 @@
"url": "https://platform.claude.com/docs/en/api/ruby/beta/messages",
"status": "success",
"path": "en/api/ruby/beta/messages.md",
- "sha256": "8a6ee57cf1fdf60b236811fde538719401a6ce9deb139598dc52947b6a4b7a1b",
- "size": 1314585
+ "sha256": "84a924cc0005f143a8ced2ecd94ec5249d7023a90488ee955fe5af642e20f37a",
+ "size": 1314546
},
{
"url": "https://platform.claude.com/docs/en/api/ruby/beta/tunnels",
@@ -16333,22 +16340,22 @@
"url": "https://platform.claude.com/docs/en/api/ruby/beta/messages/create",
"status": "success",
"path": "en/api/ruby/beta/messages/create.md",
- "sha256": "6083080110df0e373bf42ab23785b35f848229790c330278e8c6f1cd31f08bc9",
- "size": 187945
+ "sha256": "d2c719527ba777f28c8b1ed5c0cced55e0bc7f6c5d581516660f15de880b7904",
+ "size": 187939
},
{
"url": "https://platform.claude.com/docs/en/api/ruby/beta/messages/batches",
"status": "success",
"path": "en/api/ruby/beta/messages/batches.md",
- "sha256": "baed10e5493ed91882250446de0e72f63c4f57c37f6e75c75fd46f85643615e6",
- "size": 389407
+ "sha256": "94b0244893957bda3deb4eaf87ffe81258e5f74a3c5932fb7c3682b0ab20901b",
+ "size": 389401
},
{
"url": "https://platform.claude.com/docs/en/api/ruby/beta/messages/count_tokens",
"status": "success",
"path": "en/api/ruby/beta/messages/count_tokens.md",
- "sha256": "6feed5d184071166775a17e4ee02d750f43ed30f94e81f1c61a23509f081f790",
- "size": 117321
+ "sha256": "1e7fac71ede8943f75cdd9e05204333e6dccb08a2b86beab257dac92562b3c40",
+ "size": 117315
},
{
"url": "https://platform.claude.com/docs/en/api/ruby/beta/deployment_runs/list",
@@ -16690,8 +16697,8 @@
"url": "https://platform.claude.com/docs/en/api/ruby/beta/messages/batches/create",
"status": "success",
"path": "en/api/ruby/beta/messages/batches/create.md",
- "sha256": "535c69a592c806ee870c349dc7b4a3093c1cf3ab87bbf68cdfffe22a941ac9c0",
- "size": 138434
+ "sha256": "4267478862daf9e3f0554499fa4b5abe5f35ab677bc66ece0dca7c387287f52d",
+ "size": 138428
},
{
"url": "https://platform.claude.com/docs/en/api/ruby/beta/messages/batches/results",
@@ -16956,8 +16963,8 @@
"url": "https://platform.claude.com/docs/en/api/typescript/beta/messages",
"status": "success",
"path": "en/api/typescript/beta/messages.md",
- "sha256": "2df732c4d0e6c3ffa8d51199a58eab82028bc7ee06bc23fd315610b678b12caa",
- "size": 1410738
+ "sha256": "bd831ca6f93f2c607699aac5be199527f75927ee186d20bc1fbf1d6bf477b29b",
+ "size": 1410699
},
{
"url": "https://platform.claude.com/docs/en/api/typescript/beta/tunnels",
@@ -17404,22 +17411,22 @@
"url": "https://platform.claude.com/docs/en/api/typescript/beta/messages/create",
"status": "success",
"path": "en/api/typescript/beta/messages/create.md",
- "sha256": "9b3fb55ba36027a1e32049e3f7370e894b0532dde8cdb1520cebcc4d579f8d57",
- "size": 207917
+ "sha256": "d11490c7272982dbbffeb68c56b3297905ace41bc1eabaf60b20b9d0192734fa",
+ "size": 207911
},
{
"url": "https://platform.claude.com/docs/en/api/typescript/beta/messages/batches",
"status": "success",
"path": "en/api/typescript/beta/messages/batches.md",
- "sha256": "054a13c309765efc907105adf49d93cbfb69f35d6409b2cb890008a040c7483c",
- "size": 428601
+ "sha256": "b65fe9209212356f63ccd2c58686a529603271d6ffd791b2cff7754cbc876b8e",
+ "size": 428595
},
{
"url": "https://platform.claude.com/docs/en/api/typescript/beta/messages/count_tokens",
"status": "success",
"path": "en/api/typescript/beta/messages/count_tokens.md",
- "sha256": "66b1f202a38674fa64c3dacb86a26fe8a0d626540d6d03e4b06f76df383cab35",
- "size": 125667
+ "sha256": "a6be4f77da4b7586a76052951c1858160332945dd38364a6688d27a519d6a359",
+ "size": 125661
},
{
"url": "https://platform.claude.com/docs/en/api/typescript/beta/deployment_runs/list",
@@ -17761,8 +17768,8 @@
"url": "https://platform.claude.com/docs/en/api/typescript/beta/messages/batches/create",
"status": "success",
"path": "en/api/typescript/beta/messages/batches/create.md",
- "sha256": "5f74dba9f30765c49608ae568cd025573acf958dc11a1140215cad2f07b6b04b",
- "size": 147183
+ "sha256": "6eb550efe66cf4443d32622a5efad21ed2b6e7bbab774f3df38562b4e1b5d0fe",
+ "size": 147177
},
{
"url": "https://platform.claude.com/docs/en/api/typescript/beta/messages/batches/results",
@@ -18027,8 +18034,8 @@
"url": "https://platform.claude.com/docs/en/api/csharp/beta/messages",
"status": "success",
"path": "en/api/csharp/beta/messages.md",
- "sha256": "ff73717f866cc0a3cd6ed5ced83fb518471d12fc5146612b632c3783a0a13041",
- "size": 1364941
+ "sha256": "09dc1a9be7828546971f37d613665e24fcdc93afb389ae4278c260dfa49aa38d",
+ "size": 1364902
},
{
"url": "https://platform.claude.com/docs/en/api/csharp/beta/tunnels",
@@ -18475,22 +18482,22 @@
"url": "https://platform.claude.com/docs/en/api/csharp/beta/messages/create",
"status": "success",
"path": "en/api/csharp/beta/messages/create.md",
- "sha256": "ecf139e8c384e5b58bca77ee6c7c343acabe2259ec25e3a93a8c9e8c2612a67c",
- "size": 190593
+ "sha256": "ebc0e049834b80044e15b57eac7f7c583abdcab4a07967535d83856b50b39aa5",
+ "size": 190587
},
{
"url": "https://platform.claude.com/docs/en/api/csharp/beta/messages/batches",
"status": "success",
"path": "en/api/csharp/beta/messages/batches.md",
- "sha256": "38daafbb242ea03b2473e7aa4225b01f5f3c1e4f2bbd6e5807cb8bdfb43d329b",
- "size": 422674
+ "sha256": "264ce310c092482ab7d3247c9191a2ffd13f7f9e813c5b697d3ca3a7ca45aad1",
+ "size": 422668
},
{
"url": "https://platform.claude.com/docs/en/api/csharp/beta/messages/count_tokens",
"status": "success",
"path": "en/api/csharp/beta/messages/count_tokens.md",
- "sha256": "ad93b8d8733e08775aa7179a0893fd7a8aece8138ae2ade970dc805fb616d655",
- "size": 118051
+ "sha256": "c87b89b741fd8db502bcabe9f2bc1a4dd02246385089f73150060bfffc4e0181",
+ "size": 118045
},
{
"url": "https://platform.claude.com/docs/en/api/csharp/beta/deployment_runs/list",
@@ -18832,8 +18839,8 @@
"url": "https://platform.claude.com/docs/en/api/csharp/beta/messages/batches/create",
"status": "success",
"path": "en/api/csharp/beta/messages/batches/create.md",
- "sha256": "c2378691986f84d993d45e1acb50d21ef561f375c649d32f7595351744d460d6",
- "size": 153129
+ "sha256": "cda69a655988ae39d242c08bf29098e7190a4ef07929c247ca1a2142e2199d52",
+ "size": 153123
},
{
"url": "https://platform.claude.com/docs/en/api/csharp/beta/messages/batches/results",
@@ -19098,8 +19105,8 @@
"url": "https://platform.claude.com/docs/en/api/go/beta/messages",
"status": "success",
"path": "en/api/go/beta/messages.md",
- "sha256": "68915ee9861b81bd9729feb724820c7eef6f50ed64876eed7bbb342fc507adb2",
- "size": 1561920
+ "sha256": "489f947589e768f31b7020f964e54d75427269c2210cd445cf4c103d52c80422",
+ "size": 1561881
},
{
"url": "https://platform.claude.com/docs/en/api/go/beta/tunnels",
@@ -19546,22 +19553,22 @@
"url": "https://platform.claude.com/docs/en/api/go/beta/messages/create",
"status": "success",
"path": "en/api/go/beta/messages/create.md",
- "sha256": "503fece798141b204004cd1289527456ed4f2beeb8c47ae82f711d6e035fc002",
- "size": 216134
+ "sha256": "9a4e937ad67e8332719ea2470b19001ddfdae27c8b6b682f90b83da321b80eb9",
+ "size": 216128
},
{
"url": "https://platform.claude.com/docs/en/api/go/beta/messages/batches",
"status": "success",
"path": "en/api/go/beta/messages/batches.md",
- "sha256": "d7baedcf0b6a83b0554a1fec3a1f263b344438d40da8ef7216129219dead08ce",
- "size": 482481
+ "sha256": "0cd87979bec233d45620ce3b77b594330c0abd3256a63fd207f2ee2572d56577",
+ "size": 482475
},
{
"url": "https://platform.claude.com/docs/en/api/go/beta/messages/count_tokens",
"status": "success",
"path": "en/api/go/beta/messages/count_tokens.md",
- "sha256": "74cf7c4cb366fa312e1aa351823d7670c909785ebf67972b05865c76bc065a12",
- "size": 135645
+ "sha256": "68da3dcee598f766064e84c907a81d67458a5c5b4e32632ec7a02969db707521",
+ "size": 135639
},
{
"url": "https://platform.claude.com/docs/en/api/go/beta/deployment_runs/list",
@@ -19903,8 +19910,8 @@
"url": "https://platform.claude.com/docs/en/api/go/beta/messages/batches/create",
"status": "success",
"path": "en/api/go/beta/messages/batches/create.md",
- "sha256": "f1179b8dd9b97ee1f5bef4bed38189ea41d7a6dd50fe2fa611fd7060558bd9c9",
- "size": 166049
+ "sha256": "ec79c921163af5ffae7e2d4d644084e91fb812481155ea1be5539e4fea5dd325",
+ "size": 166043
},
{
"url": "https://platform.claude.com/docs/en/api/go/beta/messages/batches/results",
@@ -20169,8 +20176,8 @@
"url": "https://platform.claude.com/docs/en/api/java/beta/messages",
"status": "success",
"path": "en/api/java/beta/messages.md",
- "sha256": "b772ceeb8a00030d5c7df7ee62bc740fb17e229fdb0a2b93851385d8637b6d6e",
- "size": 1354064
+ "sha256": "147dfd18fc74a5dbe3ba454a5abc41f45cfeaa6142f49425af52adf2e52817f8",
+ "size": 1354025
},
{
"url": "https://platform.claude.com/docs/en/api/java/beta/tunnels",
@@ -20617,22 +20624,22 @@
"url": "https://platform.claude.com/docs/en/api/java/beta/messages/create",
"status": "success",
"path": "en/api/java/beta/messages/create.md",
- "sha256": "cd7f3bd908bc9f654183206ffae09ecb217fccdd2b3e357d73fb4dbd4e04fe7e",
- "size": 190704
+ "sha256": "b6c2bcfdc858e7392514e3644a41ccdabc6123faed9edac1323ac29b8a448da7",
+ "size": 190698
},
{
"url": "https://platform.claude.com/docs/en/api/java/beta/messages/batches",
"status": "success",
"path": "en/api/java/beta/messages/batches.md",
- "sha256": "7665a64b748cbb424c66232dd9cb7b485f02a899f31f43b76603b0df1b93afd6",
- "size": 412511
+ "sha256": "8173aedf91171376870f25683b519548c07ed5f58002c679c88a91c9b7c80cb0",
+ "size": 412505
},
{
"url": "https://platform.claude.com/docs/en/api/java/beta/messages/count_tokens",
"status": "success",
"path": "en/api/java/beta/messages/count_tokens.md",
- "sha256": "e823486e0f0ba89bef866977b262e850dac68195000d171310e63e3777413280",
- "size": 119846
+ "sha256": "7028776a111b194deeb9c65c34e325ce054ed66a581ca67114e0045a3c93a5e1",
+ "size": 119840
},
{
"url": "https://platform.claude.com/docs/en/api/java/beta/deployment_runs/list",
@@ -20974,8 +20981,8 @@
"url": "https://platform.claude.com/docs/en/api/java/beta/messages/batches/create",
"status": "success",
"path": "en/api/java/beta/messages/batches/create.md",
- "sha256": "d3c56e184c0d4104239e3535313d97f85e54d446e712931f6968127b3bd3a99e",
- "size": 148954
+ "sha256": "8376eb727c83e941b2f035c283bb27660267027e2407108bb251ffb8890f8de4",
+ "size": 148948
},
{
"url": "https://platform.claude.com/docs/en/api/java/beta/messages/batches/results",
@@ -22062,6 +22069,13 @@
"sha256": "d47af79826c1c84ec7e6be4ea6762e3c2dd5b278c688b8c7529abd1985013955",
"size": 37001
},
+ {
+ "url": "https://raw.githubusercontent.com/anthropics/claude-cookbooks/main/misc/admin_api.ipynb",
+ "status": "success",
+ "path": "github/claude-cookbooks/misc/admin_api.ipynb",
+ "sha256": "811d86c13d33c00c8ccdf438503407777e83fd0b3a8141bc8e84bdbf4f828a54",
+ "size": 30006
+ },
{
"url": "https://raw.githubusercontent.com/anthropics/claude-cookbooks/main/misc/batch_processing.ipynb",
"status": "success",
@@ -23361,8 +23375,8 @@
"url": "https://raw.githubusercontent.com/anthropics/claude-plugins-official/main/.claude-plugin/marketplace.json",
"status": "success",
"path": "github/claude-plugins-official/.claude-plugin/marketplace.json",
- "sha256": "74378cf575a218858e5c14542dd42f5dccf1516eb75c79b6f2d458c222b93671",
- "size": 184357
+ "sha256": "5b62acfe976404b7479884ddd35cda088b94a3b7ebc1948a1fd593fa21cb668a",
+ "size": 185864
},
{
"url": "https://raw.githubusercontent.com/anthropics/claude-plugins-official/main/.github/bump-tracking.json",
@@ -26028,8 +26042,8 @@
"url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/README.md",
"status": "success",
"path": "github/claude-quickstarts/README.md",
- "sha256": "bcb8f5071ca1b4e739c8eb1028ba8981e040791779a7d9df63ada1926f9e4f98",
- "size": 6739
+ "sha256": "d8e370c472227cb0fe99cdc714bf81d69291ccfa9ac9c9cf2c7d6e00a0a4a2b2",
+ "size": 8516
},
{
"url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/agents/README.md",
@@ -26133,8 +26147,8 @@
"url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/README.md",
"status": "success",
"path": "github/claude-quickstarts/managed-agents/README.md",
- "sha256": "cdfaac934d4a4ca72067be9f3da4ed8567053c92c171f1b3f92eb16e18076d9b",
- "size": 4013
+ "sha256": "652da57b8fabf1e9925a84d0da31c4cd1ed3ab998f819785d9a8863f5c9a7758",
+ "size": 5625
},
{
"url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/assistant-ui/CLAUDE.md",
@@ -26234,6 +26248,69 @@
"sha256": "1ba56fcc1e2b3503e21fc54eea7615729ffa7e0d0096363a13ab8c6c97dcb03d",
"size": 3986
},
+ {
+ "url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/linear/CLAUDE.md",
+ "status": "success",
+ "path": "github/claude-quickstarts/managed-agents/linear/CLAUDE.md",
+ "sha256": "c045d7859ce73ab5a329f30d9d1e92da35fa38de61cf3e57b15862a08c37ab85",
+ "size": 2546
+ },
+ {
+ "url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/linear/README.md",
+ "status": "success",
+ "path": "github/claude-quickstarts/managed-agents/linear/README.md",
+ "sha256": "2d37e0cea927b4868fea93b847c3409ad48110286745935ac8310dad6dd70ad5",
+ "size": 2989
+ },
+ {
+ "url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/linear/skill.md",
+ "status": "success",
+ "path": "github/claude-quickstarts/managed-agents/linear/skill.md",
+ "sha256": "2cd07930612e7bd4994456d32f60cb8c1f54e92dd4e54a1f24ca855108ac0791",
+ "size": 14655
+ },
+ {
+ "url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/mcp-server-typescript/CLAUDE.md",
+ "status": "success",
+ "path": "github/claude-quickstarts/managed-agents/mcp-server-typescript/CLAUDE.md",
+ "sha256": "ae5ee1acc0ca42e192ca44e9b4a89a5d01c7893a481e9912ebccb0115220ec1b",
+ "size": 1750
+ },
+ {
+ "url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/mcp-server-typescript/README.md",
+ "status": "success",
+ "path": "github/claude-quickstarts/managed-agents/mcp-server-typescript/README.md",
+ "sha256": "dd84c79efdb83e24125fb8d5e3a1ebe5bd1176b6bd2be4c1dba9e0b24580e235",
+ "size": 4965
+ },
+ {
+ "url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/mcp-server-typescript/skill.md",
+ "status": "success",
+ "path": "github/claude-quickstarts/managed-agents/mcp-server-typescript/skill.md",
+ "sha256": "f72bee2abdaf6f84a7b0f5ccec3799fa1614e27112f8e91c7d530d4f6e823e41",
+ "size": 12816
+ },
+ {
+ "url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/roadtrip-planner/CLAUDE.md",
+ "status": "success",
+ "path": "github/claude-quickstarts/managed-agents/roadtrip-planner/CLAUDE.md",
+ "sha256": "918edaa0467819a968e95886f94961662a6db91d5dfeb2763a1f42c0f03f50f8",
+ "size": 4370
+ },
+ {
+ "url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/roadtrip-planner/README.md",
+ "status": "success",
+ "path": "github/claude-quickstarts/managed-agents/roadtrip-planner/README.md",
+ "sha256": "ee318e6c907ce7775fd5877d5e080002866d9435eadbd19d3d1cbb0390c51580",
+ "size": 17613
+ },
+ {
+ "url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/roadtrip-planner/skill.md",
+ "status": "success",
+ "path": "github/claude-quickstarts/managed-agents/roadtrip-planner/skill.md",
+ "sha256": "b2bdde9e87f518410eebe112af8c3986170d71ae49cf2f980cf51c0477866de0",
+ "size": 8470
+ },
{
"url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/self-hosted-sandboxes/CLAUDE.md",
"status": "success",
@@ -26301,8 +26378,8 @@
"url": "https://raw.githubusercontent.com/anthropics/claude-quickstarts/main/managed-agents/slack/skill.md",
"status": "success",
"path": "github/claude-quickstarts/managed-agents/slack/skill.md",
- "sha256": "433de65f739490d049932bdce54d05c416a4ab0a2cf3a89e54d41b6420b01822",
- "size": 10641
+ "sha256": "12cc9b69dc48c2698610ba77e53998229dece2c3cb4e1e9fa3831682c7bbfe4c",
+ "size": 12190
},
{
"url": "https://raw.githubusercontent.com/anthropics/claude-code-action/main/.claude/agents/code-quality-reviewer.md",
@@ -26910,8 +26987,8 @@
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-python/main/CHANGELOG.md",
"status": "success",
"path": "github/anthropic-sdk-python/CHANGELOG.md",
- "sha256": "ce25b202ed3c8c8e012464ec7eaa06c7c55598e8e52bdf81fe28fee00176058f",
- "size": 246567
+ "sha256": "5d7a4086d4f054b43e5f66113143fe54502006d9e5a1ca716ad86f21763f0e14",
+ "size": 249526
},
{
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-python/main/CONTRIBUTING.md",
@@ -26945,8 +27022,8 @@
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-python/main/api.md",
"status": "success",
"path": "github/anthropic-sdk-python/api.md",
- "sha256": "6dd7f98696867be4b7282ba493dab7190c9007dd3cc2dae300d797a60731e240",
- "size": 110286
+ "sha256": "7d56519d194185a5c49d0d141fc40098b2fa640f7d6ddd1fa161c1bd3320956d",
+ "size": 110542
},
{
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-python/main/examples/greeting-SKILL.md",
@@ -26987,15 +27064,15 @@
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-python/main/tools.md",
"status": "success",
"path": "github/anthropic-sdk-python/tools.md",
- "sha256": "9afb94b4bc43d47d9b44e66ab8f13dc032b125fe2f41847e325145a0f57a64c4",
- "size": 3474
+ "sha256": "b57e8b185f9f3e3fbc5efbc959e9e67e6c670da5347ea942e8a816453198280b",
+ "size": 6407
},
{
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/CHANGELOG.md",
"status": "success",
"path": "github/anthropic-sdk-typescript/CHANGELOG.md",
- "sha256": "747e8d8a0d97bb9d0ca6e739a8ddf13e2efe3d0e57723f292032244eed3558d2",
- "size": 222683
+ "sha256": "6f837f68f33971db80413e1c33973a45b90090badd8dd34ecd6cfa455bdde0f6",
+ "size": 226903
},
{
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/CLAUDE.md",
@@ -27036,8 +27113,8 @@
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/api.md",
"status": "success",
"path": "github/anthropic-sdk-typescript/api.md",
- "sha256": "70faba63c3adfc883fab82cd5d7895e9e7d6e38be59bef91dc3d544a89887193",
- "size": 152382
+ "sha256": "3758abfec2e92882ab413bb49e5473edc2284655aa423b272057e525534ffec2",
+ "size": 153076
},
{
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/ecosystem-tests/README.md",
@@ -27057,15 +27134,15 @@
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/helpers.md",
"status": "success",
"path": "github/anthropic-sdk-typescript/helpers.md",
- "sha256": "6515cd8358cd841f01657d0569d5861abea1110537f678fcf59b49bbc41ea155",
- "size": 24449
+ "sha256": "8108ef093d89bbb52aad8949e3e3634c816d3b1a5a19a21d5f9c3c282e3f92cf",
+ "size": 28036
},
{
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/aws-sdk/CHANGELOG.md",
"status": "success",
"path": "github/anthropic-sdk-typescript/packages/aws-sdk/CHANGELOG.md",
- "sha256": "e4d9b1a55b6fdfc117e5a1224831b2bd448bcc2745ca0900fbfecde43de93c0c",
- "size": 10881
+ "sha256": "54bed17b35bea5581598a5e703303ef385fa462f3d931a4a72386bd723329569",
+ "size": 11411
},
{
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/aws-sdk/README.md",
@@ -27078,8 +27155,8 @@
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/bedrock-sdk/CHANGELOG.md",
"status": "success",
"path": "github/anthropic-sdk-typescript/packages/bedrock-sdk/CHANGELOG.md",
- "sha256": "6c804aff516a2e47faa0066c5bba310905f9c382bfac4e7edf822375c43adc7d",
- "size": 49421
+ "sha256": "5ca39d9643ce9376f6b81d5b54ab254a69f28f8ac7b10b6db2f477e2338a7418",
+ "size": 50253
},
{
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/bedrock-sdk/README.md",
@@ -27092,8 +27169,8 @@
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/foundry-sdk/CHANGELOG.md",
"status": "success",
"path": "github/anthropic-sdk-typescript/packages/foundry-sdk/CHANGELOG.md",
- "sha256": "53a109dc73972a7985165a4497d5a2b18857003c62df85e920651048e0a3168e",
- "size": 7118
+ "sha256": "98f1cef0e3a7ec2f41fda56760c0512a8b0ea7a44f0175e0b473ab613f60414b",
+ "size": 7664
},
{
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/foundry-sdk/README.md",
@@ -27106,8 +27183,8 @@
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/google-cloud-sdk/CHANGELOG.md",
"status": "success",
"path": "github/anthropic-sdk-typescript/packages/google-cloud-sdk/CHANGELOG.md",
- "sha256": "31f3126261b8bc7176191afdb04bb722c635c13bd4dcc85f523ee32a23630a71",
- "size": 5375
+ "sha256": "14521b7dacf2fb0e27efc96026c6cc3f67ef2ded2aafbe14b08fce1228ddaa7b",
+ "size": 5946
},
{
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/google-cloud-sdk/README.md",
@@ -27120,8 +27197,8 @@
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/vertex-sdk/CHANGELOG.md",
"status": "success",
"path": "github/anthropic-sdk-typescript/packages/vertex-sdk/CHANGELOG.md",
- "sha256": "7394c8a458bff349947dad65358542560acf41a53436eaea376e6a6040f24281",
- "size": 28805
+ "sha256": "70ea8c3db8c58b02bf2069dcc58b50bb7b8fbf6ee938cab8de546d01649791cb",
+ "size": 29355
},
{
"url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/vertex-sdk/README.md",
@@ -28130,8 +28207,8 @@
}
],
"summary": {
- "total": 4120,
- "downloaded": 3880,
+ "total": 4131,
+ "downloaded": 3891,
"skipped": 0,
"failed": 0,
"dead": 240,
diff --git a/content/CHANGELOG.md b/content/CHANGELOG.md
index 73440d356f..6d69d78db4 100644
--- a/content/CHANGELOG.md
+++ b/content/CHANGELOG.md
@@ -1,5 +1,100 @@
# Changelog
+## 2.1.278
+
+- Changed auto mode for Claude API and Enterprise users, and on Bedrock, Vertex, Foundry and gateways, to default to the server-side classifier, which does not charge for classifier overhead (`CLAUDE_CODE_AUTO_MODE_SERVER=0` opts out on Bedrock, Vertex, Foundry and gateways); warns on billed fallback. See https://code.claude.com/docs/en/auto-mode-classifier-billing
+- Added an `Auto mode server` row to `/status` showing whether this session's auto mode classifier runs on the server
+
+## 2.1.277
+
+- Added AGENTS.md support: in a project with no CLAUDE.md, Claude Code reads AGENTS.md instead; change it under "Project instructions" in `/config` (not yet on Bedrock, Vertex or Foundry)
+- Added `CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY=1` for Claude apps gateways whose only egress is a forward proxy: every outbound request hands the proxy the hostname instead of resolving it locally
+- Added an optional `headers:` map on Claude apps gateway upstreams, to send static headers to a proxy you run in front of a provider
+- Added a line saying a background task's update is waiting when it finishes while a panel such as `/tasks` is open
+- Fixed `claude -p` and Agent SDK sessions that could hang with no result after an internal error; they now report the error and exit with code 1
+- Fixed conversations failing every request with "text content blocks must be non-empty" when an earlier assistant turn held an empty text block beside other content, including after `--resume`
+- Fixed being unexpectedly logged out when an older Claude Code build (for example an IDE extension's bundled CLI) runs on the same machine as the current one
+- Fixed interactive start-up hanging or showing an error for `ANTHROPIC_API_KEY` users when `~/.claude.json` holds a malformed `customApiKeyResponses` value
+- Fixed update checks erroring every 30 minutes, and `claude update` hanging when a minimum or maximum version is set, if a proxy returns an invalid version; a malformed `minimumVersion` is now ignored
+- Fixed `claude update` on winget- or apk-managed installs reporting "up to date" when the version lookup failed
+- Fixed `claude plugin install` sometimes failing and breaking the installed copy when reinstalling a plugin version that a session or another program was using; an unchanged copy is now left alone
+- Fixed Grep and Glob reporting no matches when the search could not start because the system was out of processes, memory or file handles; they now return an error saying so
+- Fixed the Write tool silently ending the turn as a declined permission when the target path is an existing directory; it now reports a clear error
+- Fixed the Edit tool treating an escaped backslash followed by `uXXXX` text as a `\uXXXX` escape, which could make an edit of a non-ASCII character rewrite an escaped backslash sequence instead
+- Fixed the Edit tool reporting "Invalid regular expression: regular expression too large" instead of "String not found in file" when a very large edit containing non-ASCII text did not match the file
+- Fixed a turn ending early with "Path contains null bytes" when a tool call's file path contained `\u0000` written as an escape sequence; escaped control characters now stay as literal text
+- Fixed background sessions (`claude --bg`) exiting when a plugin's LSP server exited or closed its stdin
+- Fixed a crash ("Type error") when opening `/mcp` or `/plugin manage` with a malformed `claudeAiMcpEverConnected` value in `~/.claude.json`
+- Fixed a crash at launch when `~/.claude.json` holds a malformed `theme` value
+- Fixed a crash ("unrecoverable interface error") when the prompt held text containing terminal color codes, for example a prompt recalled from history or text loaded from the external editor
+- Fixed a crash when resuming a session whose saved history holds an assistant message stored as a plain string
+- Fixed sessions on slow or heavily loaded machines sometimes exiting with "Claude Code exited after an unrecoverable interface error" when the first spinner appeared
+- Fixed a rare case where the screen could stop updating for the rest of the session after an internal rendering error
+- Fixed a rare case on Windows where a turn could stop with an error such as "Out of memory" right after Claude replied, so that reply's tool calls never ran
+- Fixed sessions continued after `/clear` (restart, `--continue`, `--resume`) missing part of their first message when a SessionStart hook printed output, causing a full prompt-cache miss
+- Fixed messages from other agents (such as a subagent's SendMessage) that arrived mid-turn showing up below the "Ran N shell commands" row instead of where they arrived
+- Fixed the "copied" notice not appearing after drag-selecting text in the fullscreen `/resume` picker and other panels that cover the prompt area
+- Fixed `$TMPDIR` expanding empty in Bash commands that run outside the sandbox while sandboxing is enabled
+- Fixed WebFetch and WebSearch in Cowork cloud sessions not telling Claude why a request was refused, such as a used-up fetch budget or an admin policy
+- Fixed the Claude apps gateway's telemetry relay ignoring a collector hostname or domain listed in `NO_PROXY` when a proxy is set
+- Fixed one malformed `strictKnownMarketplaces` or `blockedMarketplaces` entry silently disabling the whole enterprise marketplace policy
+- Fixed failed auto-updates leaving large staged downloads behind in `~/.cache/claude/staging`
+- Fixed `/plugin` not stripping terminal control characters from messages on the Installed tab, such as the error of a failed plugin update
+- Fixed `/plugin` → Installed and `/skills` crashing when a skill or legacy command is named like a built-in Object property such as `constructor` or `toString`
+- Fixed `/plugin` closing with no message when every install in a multi-select failed
+- Fixed uninstalled plugins reappearing as "failed to load" rows in `/plugin` Installed, and Remove not clearing such a row
+- Fixed plugins from the official marketplace being recorded without their commit in `installed_plugins.json`, and `installed_plugins.json` keeping the old commit after updating a pinned-commit plugin
+- Fixed plugin reload previews keeping every previewed copy of a plugin archive unpacked until exit, and overwriting the cached `--plugin-url` archive a reload falls back to when its download fails
+- Fixed Remote Control session bookkeeping failing when `~/.claude.json` holds a malformed placeholder record
+- Fixed the error after a revoked claude.ai login blaming an expired Anthropic profile; it now leads with `/login`
+- Fixed typed or pasted text occasionally coming out scrambled in the `claude agents` dispatch input during key repeat or very fast input
+- Fixed a crash ("unrecoverable interface error") when resuming a session whose saved transcript contains a stop hook summary without a well-formed hook list
+- Fixed Enter on a selected agent panel row doing nothing when `keybindings.json` rebinds Enter in the Chat context, for example to `chat:queueSubmit`
+- Fixed PDF page reads on Windows failing when the working folder's path is long (about 120 characters or more)
+- Fixed a headless resume (`claude -p --resume`, the SDK, a VS Code extension window reload) starting the session's cost and usage totals at zero; headless sessions now save their totals at exit
+- Fixed project skills from the main repository not loading in `--worktree` sessions when `.claude/skills` is untracked
+- Fixed a `sandbox.excludedCommands` glob exempting an entire compound Bash command from the sandbox when only one part matched; every part must now match
+- Fixed resumed subagents and teammates re-rendering the MCP tool definitions they had loaded, which broke prompt caching for that agent
+- Fixed rate-limited artifact publishes telling Claude to stop retrying; Claude is now told nothing was published and when to send the same publish again
+- Fixed attachments recorded earlier in a conversation being re-rendered after a resume or relaunch, which dropped extended thinking and missed the prompt cache
+- Fixed Console sign-in showing only "Request failed with status code 400" when the server refuses to create an API key; it now shows the server's message
+- Fixed messages typed while Claude is still working sometimes being ignored by the model
+- Improved session start-up for SDK and headless (`-p`) use: the first turn no longer waits on the per-directory CLAUDE.md lookup
+- Improved the Claude apps gateway's loopback error messages to name `CLAUDE_GATEWAY_ALLOW_LOOPBACK`
+- Improved `/plugin` Installed: an MCP server listed apart from its plugin now shows which plugin it belongs to
+- Improved `claude plugin install` on an already-installed plugin: it now says when the marketplace offers a newer version and names the `claude plugin update` command
+- Improved the startup notice overflow line under the logo: it now reads "N more notices hidden" instead of "+N more · /status"
+- Improved prompt handling: invisible Unicode formatting and tag characters in a prompt are removed and the cleaned prompt is shown for review before it is sent
+- Improved `/ultrareview` when there's nothing to review: messages say which case you're in, offer a command that reviews your latest commit, and a new repository's first commit is reviewed in full
+- Improved artifact link handling so Claude reads claude.ai artifact links with the Artifact tool instead of WebFetch when that tool is available
+- Improved the dangerous-rm permission prompt to name the flagged rm command and suggest a `${VAR:?}` guard, so headless runs can recover
+- Improved the Artifact tool's permission prompts: shorter sentences, pages and artifacts named by title or file name, and links listed after the text
+- Changed Fable to always appear in `/model` on the Anthropic API; it is greyed out only when your organization's settings disable it
+- Changed the Bash sandbox instructions on Bedrock, Vertex and Foundry to the first-party wording, which frames the sandbox as the boundary of what the task was given
+- Changed `/ultrareview` in non-interactive sessions to refuse when the repository has no base branch or shared history
+- Changed subagent results to reach the main agent under a header marking them as subagent output, with the result indented, so text in a subagent's result cannot pass as the session's own instructions
+- Changed workflow scripts' computed `agent()` prompts on Bedrock, Vertex and Foundry to reach the subagent framed as script-authored text, so the safety classifier does not read them as the user
+- Removed the background Haiku auto-title request from `claude -p` runs launched outside an SDK or IDE
+- Removed the deprecated TaskOutput tool; Claude reads a background task's output file with Read instead, and the `taskOutputMaxChars` setting and `TASK_MAX_OUTPUT_LENGTH` no longer have any effect
+- [VSCode] Added a Sign out row to the panel menu, with `/logout` in the typed command menu
+- [VSCode] Added background shells and other running tasks to the agent map, each with a Stop, and a typed `/tasks` that opens it
+- [VSCode] Added a Copy response button on responses and a typed `/copy`
+- [VSCode] Added a one-time notice when inactive sessions are archived automatically, and an "Unarchive all" action on the Archived sessions group
+- [VSCode] Added the session's cost and token usage to the Account & usage dialog and the session manager where plan limits do not apply (Vertex, Bedrock, Foundry, API key)
+- [VSCode] Fixed the "General config" menu row showing `/config` usage text instead of opening settings, and made typed `/mcp`, `/hooks`, `/memory`, `/rewind` and similar commands open their dialogs
+- [VSCode] Fixed the effort slider's level not persisting into later sessions on a model that already had a level saved with `/effort`
+- [VSCode] Fixed Auto missing from the mode picker for conversations opened in an already-used panel when the saved model setting is a differently-cased alias such as "Sonnet"
+- [VSCode] Fixed `/fast` not saving fast mode as the default, so it was lost when the extension relaunched Claude Code
+- [Claude Code on the web] Added Personal and Organization sections to the environment picker on Team and Enterprise plans, and admins can now share a personal environment with the organization
+- [Claude Code on the web] Changed organization environments to open as a read-only summary from the Code tab on Team and Enterprise plans, with editing under Admin settings → Cloud environments
+- [Claude Code on the web] Fixed a cloud environment saved with Custom network access and no domains silently reverting to Trusted; the dialog now asks for at least one domain
+- [Claude Code on the web] Changed the admin Claude Code setting labeled "Web" to "Cloud sessions" and removed the redundant read-only Mobile row beneath it
+- [Claude Tag] Fixed routines created in a Slack channel on an Enterprise Grid org-wide install failing to read other public channels in their workspace when they ran
+- [Claude Tag] Fixed the "Learn more" links on credential presets in Claude Tag access bundles to open each vendor's credential-setup page instead of a generic API reference
+- [Claude Tag] Changed the Pylon credential preset in Claude Tag access bundles so admins can point it at Pylon's EU host
+- [Claude Tag] Fixed Google Cloud credential forms in Claude Tag access bundles: a refused key file now says why, the website and scopes stay locked, and a rejected rotation keeps the pasted key
+- [Claude Tag] Fixed the network events log in Claude Tag admin settings showing no response status for requests through connections that use AWS signing, client certificates or a custom CA
+
## 2.1.276
- Fixed every request failing with `400 … Input tag 'advisor_20260301'` when `ANTHROPIC_BASE_URL` points at a proxy or gateway (2.1.275 regression)
@@ -4421,7 +4516,7 @@
- Improved `@`-mention typeahead to rank source files above MCP resources with similar names
- Improved PowerShell tool prompt with version-appropriate syntax guidance (5.1 vs 7+)
- Changed `Edit` to work on files viewed via `Bash` with `sed -n` or `cat`, without requiring a separate `Read` call first
-- Changed hook output over 50K characters to be saved to disk with a file path + preview instead of being injected directly into context
+- Changed hook output over 10,000 characters to be saved to disk with a file path + a 2,000-character preview instead of being injected directly into context
- Changed `cleanupPeriodDays: 0` in settings.json to be rejected with a validation error — it previously silently disabled transcript persistence
- Changed thinking summaries to no longer be generated by default in interactive sessions — set `showThinkingSummaries: true` in settings.json to restore
- Documented `TaskCreated` hook event and its blocking behavior
diff --git a/content/claude-code-manifest.json b/content/claude-code-manifest.json
index fb44f0aaf7..a653785963 100644
--- a/content/claude-code-manifest.json
+++ b/content/claude-code-manifest.json
@@ -6,25 +6,25 @@
"url": "https://github.com/anthropics/claude-code/issues"
},
"dist": {
- "shasum": "e79ef89036ba8ed956dd96caefd3d7c33c0d6b2e",
- "tarball": "https://registry.npmjs.org/@anthropic-ai/claude-code/-/claude-code-2.1.276.tgz",
+ "shasum": "f4067f95f4925cd3c2ba8dc55f4376e0185c2fc7",
+ "tarball": "https://registry.npmjs.org/@anthropic-ai/claude-code/-/claude-code-2.1.278.tgz",
"fileCount": 7,
- "integrity": "sha512-xgVXCbFdqOhSAcMTSC61gjL1jCQuoAA4TNU1I7Dmf/yuYcDxHf796r6LaB3Jswm1floKnP1V+/zfphtDlPdlkg==",
+ "integrity": "sha512-mfNRqC0GaEXqmP97NiwJBeYBmRuqe2VzgLUreUUaEhyJxJWx2Z6ClW1tBOncGNNXdhj6EY4LPvUIWP+oq311CA==",
"signatures": [
{
- "sig": "MEQCIHpQecH4nUAWz2gdptLi7Hkijv8qqo6w4SpaMQFb8/r4AiB9SAdWawkJ8tZQJcLGtLmcfKgiKJqb/QNWy3VRSKhFPw==",
+ "sig": "MEUCIQC81P1jcplrC28ZU4b5Y3T9Rj1A3p+8CoLXO7HAW7cJvgIgf/SppAye4NZ+E1rjLF6pE2T95KaNtRyicn05mASL5So=",
"keyid": "SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"
},
{
- "sig": "MEYCIQDpDrFKX+GwAUKAaVUiw28rCktGotEsu5n1A+Y118S4fwIhAJumek2Xs69jPwQAgCvNUL16e+XFW0wGNRS59+UlVUBE",
+ "sig": "MEQCIBeX9mnR4kKUNu3WvxUjI7diymPZpYgGHaYHeRlngVqgAiBig2fuXebNVEYirEx14d6RW8b3G5DU9EeexCkfLaCQxA==",
"keyid": "SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"
}
],
- "unpackedSize": 186461
+ "unpackedSize": 184119
},
"name": "@anthropic-ai/claude-code",
"type": "module",
- "_from": "file:staged-npm/anthropic-ai-claude-code-2.1.276.tgz",
+ "_from": "file:staged-npm/anthropic-ai-claude-code-2.1.278.tgz",
"author": {
"name": "Anthropic",
"email": "support@anthropic.com"
@@ -42,8 +42,8 @@
"email": "wolffiex@anthropic.com"
},
"homepage": "https://github.com/anthropics/claude-code",
- "_resolved": "/home/runner/work/claude-cli-internal/claude-cli-internal/staged-npm/anthropic-ai-claude-code-2.1.276.tgz",
- "_integrity": "sha512-xgVXCbFdqOhSAcMTSC61gjL1jCQuoAA4TNU1I7Dmf/yuYcDxHf796r6LaB3Jswm1floKnP1V+/zfphtDlPdlkg==",
+ "_resolved": "/home/runner/work/claude-cli-internal/claude-cli-internal/staged-npm/anthropic-ai-claude-code-2.1.278.tgz",
+ "_integrity": "sha512-mfNRqC0GaEXqmP97NiwJBeYBmRuqe2VzgLUreUUaEhyJxJWx2Z6ClW1tBOncGNNXdhj6EY4LPvUIWP+oq311CA==",
"_npmVersion": "11.19.0",
"description": "Use Claude, Anthropic's AI assistant, right from your terminal. Claude can understand your codebase, edit files, run terminal commands, and handle entire workflows for you.",
"directories": {},
@@ -106,19 +106,19 @@
"_hasShrinkwrap": false,
"readmeFilename": "README.md",
"optionalDependencies": {
- "@anthropic-ai/claude-code-linux-x64": "2.1.276",
- "@anthropic-ai/claude-code-win32-x64": "2.1.276",
- "@anthropic-ai/claude-code-darwin-x64": "2.1.276",
- "@anthropic-ai/claude-code-linux-arm64": "2.1.276",
- "@anthropic-ai/claude-code-win32-arm64": "2.1.276",
- "@anthropic-ai/claude-code-darwin-arm64": "2.1.276",
- "@anthropic-ai/claude-code-linux-x64-musl": "2.1.276",
- "@anthropic-ai/claude-code-linux-arm64-musl": "2.1.276"
+ "@anthropic-ai/claude-code-linux-x64": "2.1.278",
+ "@anthropic-ai/claude-code-win32-x64": "2.1.278",
+ "@anthropic-ai/claude-code-darwin-x64": "2.1.278",
+ "@anthropic-ai/claude-code-linux-arm64": "2.1.278",
+ "@anthropic-ai/claude-code-win32-arm64": "2.1.278",
+ "@anthropic-ai/claude-code-darwin-arm64": "2.1.278",
+ "@anthropic-ai/claude-code-linux-x64-musl": "2.1.278",
+ "@anthropic-ai/claude-code-linux-arm64-musl": "2.1.278"
},
"_npmOperationalInternal": {
- "tmp": "tmp/claude-code_2.1.276_1789695571884_0.43057377569820776",
+ "tmp": "tmp/claude-code_2.1.278_1789782539674_0.9072426105006208",
"host": "s3://npm-registry-packages-npm-production"
},
- "_id": "@anthropic-ai/claude-code@2.1.276",
- "version": "2.1.276"
+ "_id": "@anthropic-ai/claude-code@2.1.278",
+ "version": "2.1.278"
}
\ No newline at end of file
diff --git a/content/claude/claude-science/admin-controls.md b/content/claude/claude-science/admin-controls.md
index 13bc6f21eb..93a1a5adca 100644
--- a/content/claude/claude-science/admin-controls.md
+++ b/content/claude/claude-science/admin-controls.md
@@ -81,7 +81,7 @@ To stop members from adding their own skills, turn off the **Allow custom skills
A member who used Claude Science under another sign-in on the same computer (for example, a personal plan before joining your organization) can access the projects, sessions, and artifacts from that sign-in and move it into the app's folder for your organization on that computer (see [Access work from another sign-in on your computer](/docs/claude-science/multiple-computers#access-work-from-another-sign-in-on-your-computer)). The **Allow members to access Claude Science work previously saved on their computer** switch decides whether the app offers this access. It's on by default for Team organizations and off by default for Enterprise organizations, and organizations with HIPAA compliance enabled can't turn it on.
-The access happens on the member's computer and uploads nothing. Claude Science work the app accesses will follow your organization's settings from then on. Content your organization doesn't allow isn't copied or moved and stays in its original folder, and credentials such as API keys and connector sign-ins are never copied or moved. When the switch is off, the app doesn't offer the access, and its **Import work on this computer** setting is grayed out with a note that it's off for your organization.
+The access happens on the member's computer and uploads nothing. Claude Science work the app accesses will follow your organization's settings from then on. Content your organization doesn't allow isn't copied or moved and stays in its original folder, and credentials such as API keys and connector sign-ins are never copied or moved. When the switch is off, the app doesn't offer the access, and its **Access previously saved Claude Science work on this computer** setting is grayed out with a note that it's off for your organization.
### Network allowlist
diff --git a/content/claude/claude-science/artifacts.md b/content/claude/claude-science/artifacts.md
index 4a017dd975..9ed237f66c 100644
--- a/content/claude/claude-science/artifacts.md
+++ b/content/claude/claude-science/artifacts.md
@@ -12,7 +12,7 @@ An artifact is a file Claude saves into the project: a figure, processed dataset
Click a linked file in the conversation to open it in a tab beside the chat. HTML artifacts have zoom controls, including fit to width; images zoom up to their native resolution. Open **Files** in the sidebar for a searchable grid of every artifact in the project. From an artifact's menu you can: Open, Open beside session, **View in context**, **Provenance**, Versions, **Copy link**, **Star**, **Rename**, **Download**, or **Delete**. Renaming doesn't break links. **Delete** removes all versions permanently.
-Files you attach or drop into the composer are listed under **Your uploads**.
+Files you attach or drop into the composer, and images you paste into it, are listed under **Your uploads**.
To copy artifacts outside the app, use **Download** for a single file, or open the project's folder under \~/.claude-science and copy the files directly.
diff --git a/content/claude/claude-science/changelog.md b/content/claude/claude-science/changelog.md
index 8bbabd931e..207d2af4cb 100644
--- a/content/claude/claude-science/changelog.md
+++ b/content/claude/claude-science/changelog.md
@@ -6,6 +6,17 @@
> Release notes for Claude Science, including new features, improvements, and bug fixes by version.
+
+ * Tables in Markdown files now show as a compact grid; a long table keeps its header row in view, and row labels stay in view when you scroll sideways
+ * Tabs in the right pane can be reordered by dragging, or with Ctrl/Cmd+Shift+Left/Right
+ * Pasted images are now saved to your uploads, so Claude can keep working with them later in the conversation
+ * When Claude redraws a figure several times in one turn, the chat keeps only the newest one open; open an earlier step to see its draft
+ * Closing Settings or Customize by clicking outside it no longer drops an edit you were still typing
+ * "View in context" on a file version that a different session saved now opens the file's own session instead of an empty screen
+ * Project settings are now clearer with helper text
+ * Home screen: project rows now show running sessions in gray like the session cards
+
+
* If your organization is in Anthropic's Life Sciences Verification Program (beta), you can now [choose a use case](/docs/claude-science/safeguards#choose-a-use-case) for your sessions
* Saved credentials now reach Claude's code only when it asks for them and you approve. They're no longer present in every cell
diff --git a/content/claude/claude-science/get-started.md b/content/claude/claude-science/get-started.md
index a2edd9cbf8..72df8d603f 100644
--- a/content/claude/claude-science/get-started.md
+++ b/content/claude/claude-science/get-started.md
@@ -92,5 +92,5 @@ After sign-in, a setup wizard walks you through enabling connectors and skills,
* The Windows app reports that it couldn't set up the app window engine: the first launch downloads that engine from `downloads.claude.ai`, and this usually means the app couldn't reach it. Check the internet connection, and on a corporate network ask IT to allow that domain (see [Network requirements](/docs/claude-science/network-requirements)).
* Linux refuses to start: a sandbox dependency is missing (install bubblewrap and socat as shown in the Install section), too old, or blocked. Check your bubblewrap version with `bwrap --version`, then match the error message to its fix in the [Linux troubleshooting table](/docs/claude-science/run-on-remote-linux-server#troubleshooting).
* Projects from another computer don't appear: by design, Claude Science keeps your work on the computer where it's installed, so each computer starts with its own projects. Your earlier projects are still on the other computer. See [Use Claude Science on more than one computer](/docs/claude-science/multiple-computers).
-* Projects you created under another sign-in on this computer don't appear automatically, for example, after you move from a personal plan to your organization's Team plan: your earlier projects are still in that sign-in's folder. Select the **Review** button on the banner at the top of the home screen, or select **Review** next to **Import work on this computer** under **Settings** > **General** > **Account**, to access them. On Team and Enterprise plans, if there's no banner and the setting is grayed out, your admin controls it. See [Access work from another sign-in on your computer](/docs/claude-science/multiple-computers#access-work-from-another-sign-in-on-your-computer).
+* Projects you created under another sign-in on this computer don't appear automatically, for example, after you move from a personal plan to your organization's Team plan: your earlier projects are still in that sign-in's folder. Select the **Review** button on the banner at the top of the home screen, or select **Review** next to **Access previously saved Claude Science work on this computer** under **Settings** > **General** > **Account**, to access them. On Team and Enterprise plans, if there's no banner and the setting is grayed out, your admin controls it. See [Access work from another sign-in on your computer](/docs/claude-science/multiple-computers#access-work-from-another-sign-in-on-your-computer).
* Sign-in stops at claude.ai: your account is on the Free plan (upgrade required), the redirect couldn't return (use Paste a code), or your Team or Enterprise organization hasn't [enabled Claude Science](/docs/claude-science/enable-claude-science) yet.
diff --git a/content/claude/claude-science/multiple-computers.md b/content/claude/claude-science/multiple-computers.md
index c4ce2f0493..642a4f90c9 100644
--- a/content/claude/claude-science/multiple-computers.md
+++ b/content/claude/claude-science/multiple-computers.md
@@ -20,6 +20,6 @@ To take a single result to another computer, choose **Download** from the artifa
## Access work from another sign-in on your computer
-Claude Science keeps the work from each sign-in in its own folder on your computer. When you sign in to a different organization or personal account on that computer (for example, a Team plan after a personal plan), a banner at the top of the home screen offers to import the earlier work. Select the **Review** button on the banner, select the folders to access, choose **Copy** (the original folder keeps the work too) or **Move** (what's accessed is then removed from the original folder), and select **Import**. To access later instead, select **Review** next to **Import work on this computer** under **Settings** > **General** > **Account**.
+Claude Science keeps the work from each sign-in in its own folder on your computer. When you sign in to a different organization or personal account on that computer (for example, a Team plan after a personal plan), a banner at the top of the home screen offers access to the earlier work. Select the **Review** button on the banner, select the folders to access, choose the **Copy** option (the original folder keeps the work too) or the **Move** option (what's accessed is then removed from the original folder), and select the **Copy** or **Move** button. To access later instead, select **Review** next to **Access previously saved Claude Science work on this computer** under **Settings** > **General** > **Account**.
-The access happens entirely on your computer and uploads nothing. Credentials such as API keys and connector sign-ins aren't copied or moved and stay in their original folder. On Team and Enterprise plans, your admin controls whether the app offers importing (it's off by default on Enterprise plans). Content your organization doesn't allow, such as memory, isn't copied or moved and stays in its original folder (see [Previously saved Claude Science work](/docs/claude-science/admin-controls#previously-saved-claude-science-work)).
+The access happens entirely on your computer and uploads nothing. Credentials such as API keys and connector sign-ins aren't copied or moved and stay in their original folder. On Team and Enterprise plans, your admin controls whether the app offers this access (it's off by default on Enterprise plans). Content your organization doesn't allow, such as memory, isn't copied or moved and stays in its original folder (see [Previously saved Claude Science work](/docs/claude-science/admin-controls#previously-saved-claude-science-work)).
diff --git a/content/claude/cowork/changelog.md b/content/claude/cowork/changelog.md
index e0dff5df31..d536012257 100644
--- a/content/claude/cowork/changelog.md
+++ b/content/claude/cowork/changelog.md
@@ -982,7 +982,7 @@
**Code**
* Added iOS Simulator support: Claude Code can build your iOS app, launch the simulator, and verify the result without leaving the session.
- * Added iOS Simulator and Android Emulator buttons to the session titlebar when the agent launches an app on a device, so the pane is one click to reopen.
+ * Added an iOS Simulator button to the session titlebar when the agent launches an app in the simulator, so the pane is one click to reopen.
* Added Pause Project, which pauses a project's coordinator and new session spawning from settings and shows a Resume banner above the composer.
* Added screenshot annotation in the composer: click a staged image, open the pencil, and draw with pen, shapes, text, and colors before sending.
* Improved how large sessions open: the newest messages paint first while older history loads in the background.
diff --git a/content/claude/government/changelog.md b/content/claude/government/changelog.md
index 93ebd1ed71..c36981921b 100644
--- a/content/claude/government/changelog.md
+++ b/content/claude/government/changelog.md
@@ -6,6 +6,19 @@
> Release notes for Claude for Government
+
+ * Fixed members not being reactivated after they are re-enabled in your identity provider.
+ * Changed SCIM provisioning to reject requests to deactivate an organization's primary owner or a tenant's last admin until ownership is transferred or another admin is added.
+ * Changed SCIM provisioning to return an error that says what to do first when an identity provider deactivates or changes the email address of a member who is not yet linked to their directory entry.
+ * Changed sign-in for accounts outside any organization that still held a Primary Owner role without being a tenant admin: they now sign in like any other member.
+ * Changed sign-in: a network that starts sign-ins unusually fast is briefly told to try again.
+ * Added a check of the Issuer against what your identity provider publishes when you save OIDC single sign-on.
+ * Added a Test sign-in button to the Single sign-on settings on the tenant portal's Identity and access page, so a tenant admin can check their own sign-in through their identity provider.
+ * Added **Sign out everywhere** to each member's row menu on the Users page, which ends all of that member's sessions; the Compliance API records it as `user.sessions_revoked`.
+ * Added the option to enforce settings whose values are hidden after saving, such as Telemetry headers, from the Admin Console.
+ * Added the **Claude Desktop home** setting on the Config page, which sets Chat, Advanced file analysis, and Cowork in Claude Desktop together. It needs Claude Desktop 1.52386.0 or later.
+
+
* Fixed directory provisioning (SCIM) rejecting some of the user updates that Microsoft Entra ID sends by default.
* Changed what removing a tenant admin does for someone who is not yet in an organization: they can no longer request an emailed sign-in link and are placed by the sign-in routing rules at their next single sign-on, like any other member.
diff --git a/content/claude/third-party/claude-desktop/admin-console.md b/content/claude/third-party/claude-desktop/admin-console.md
index b23380556b..7babc9a2c6 100644
--- a/content/claude/third-party/claude-desktop/admin-console.md
+++ b/content/claude/third-party/claude-desktop/admin-console.md
@@ -94,7 +94,7 @@ From the console you can set the same [configuration keys](/docs/third-party/cla
| Page | What you configure there |
| ----------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Connection** | The inference provider ([gateway](/docs/third-party/claude-desktop/gateway), [Amazon Bedrock](/docs/third-party/claude-desktop/bedrock), [Bedrock Mantle](/docs/third-party/claude-desktop/mantle), [Google Cloud's Agent Platform](/docs/third-party/claude-desktop/vertex), or [Microsoft Foundry](/docs/third-party/claude-desktop/foundry)), its endpoint, region, or project, how users authenticate to it, custom request headers, and, under **Models**, the model list, default model, model discovery, and cost-estimate rates. **Desktop sign-in** on this page holds the **Require this organization in Claude Desktop** switch described under [Users in more than one Claude organization](#users-in-more-than-one-claude-organization). |
-| **Workspace** | Whether Chat, Cowork, and Code are each available, the folders and network hosts the app may use, permission modes and built-in tool policy, whether users may add their own skills and plugins, and organization instructions |
+| **Capabilities** | Whether Chat, Cowork, and Code are each available, the folders and network hosts the app may use, permission modes and built-in tool policy, the [built-in browser](/docs/third-party/claude-desktop/browser#manage-the-built-in-browser-from-the-enterprise-admin-console) and its site permissions, whether users may add their own skills and plugins, and organization instructions |
| **Connectors** | Managed MCP servers, including the [built-in connectors](/docs/third-party/claude-desktop/built-in-connectors), whether users may add their own MCP servers, desktop extension policy, and [**Claude.ai data import**](/docs/third-party/claude-desktop/import) |
| **Telemetry & updates** | Which telemetry categories go to Anthropic, whether users' apps report [usage analytics](#usage-analytics) to your organization, OpenTelemetry export to your collector, update policy, the [configuration relaunch window](#configuration-updates), and the configuration re-check interval |
| **Limits** | A per-user token limit and its window |
@@ -105,8 +105,6 @@ The console refuses API keys, tokens, and secrets anywhere in the configuration,
Most of these settings can also differ per group of users, on the **Permission policies** page under **People**, as described under [Per-group permission policies](#per-group-permission-policies).
-To turn on the built-in browser, open the **Capabilities** page in **Organization settings**, outside the **Desktop 3P** section, and turn on the **Built-in browser** switch under **Data sources**, as described under [Manage the built-in browser from the Enterprise Admin Console](/docs/third-party/claude-desktop/browser#manage-the-built-in-browser-from-the-enterprise-admin-console).
-
### Choose how users authenticate to your provider
diff --git a/content/claude/third-party/claude-desktop/browser.md b/content/claude/third-party/claude-desktop/browser.md
index 7ca9a3a7dc..b9c7603158 100644
--- a/content/claude/third-party/claude-desktop/browser.md
+++ b/content/claude/third-party/claude-desktop/browser.md
@@ -34,11 +34,11 @@ Pages load directly from the user's device, so your network's proxy, firewall, a
### Turn on the built-in browser
-The built-in browser is off by default. Set [`builtinBrowserEnabled`](/docs/third-party/claude-desktop/configuration#builtinbrowserenabled) to `true` in your managed configuration, under **General restrictions** in the **Workspace** section of the [in-app configuration window](/docs/third-party/claude-desktop/in-app-configuration). The change takes effect after Claude Desktop restarts.
+The built-in browser is off by default. Set [`builtinBrowserEnabled`](/docs/third-party/claude-desktop/configuration#builtinbrowserenabled) to `true` in your managed configuration, under **Built-in browser** in the **Capabilities** section of the [in-app configuration window](/docs/third-party/claude-desktop/in-app-configuration). The change takes effect after Claude Desktop restarts.
Also allow `releases.claude.com` through your firewall, because Claude Desktop contacts it for the [site safety check](#site-safety-check). If the app can't complete a check, users can keep browsing the site, but Claude can't read or act on it.
-If your devices use a [bootstrap server](/docs/third-party/claude-desktop/bootstrap), set the key in the configuration the server returns, because a value set only on the device leaves the browser off. If you manage the app from the Enterprise Admin Console, use [the console's **Built-in browser** switch](#manage-the-built-in-browser-from-the-enterprise-admin-console) instead.
+If your devices use a [bootstrap server](/docs/third-party/claude-desktop/bootstrap), set the key in the configuration the server returns, because a value set only on the device leaves the browser off. If you manage the app from the Enterprise Admin Console, [turn it on from the console](#manage-the-built-in-browser-from-the-enterprise-admin-console) instead.
### Restrict which sites Claude can open
@@ -69,7 +69,7 @@ The example is plain JSON, which is the form a [bootstrap server](/docs/third-pa
### Manage the built-in browser from the Enterprise Admin Console
-If you manage the app from the [Enterprise Admin Console](/docs/third-party/claude-desktop/admin-console), you control the built-in browser from the console instead of with these keys. In **Organization settings** on claude.ai, open the **Capabilities** page and turn on the **Built-in browser** switch under **Data sources**. The change takes effect when users restart Claude Desktop. Also allow `releases.claude.com` through your firewall, because Claude Desktop contacts it for the [site safety check](#site-safety-check).
+If you manage the app from the [Enterprise Admin Console](/docs/third-party/claude-desktop/admin-console), you control the built-in browser from the console instead of with these keys. In **Organization settings** on claude.ai, open the **Capabilities** page in the **Desktop 3P** section. Under **Built-in browser**, turn on the **Allow the built-in browser** switch. The change takes effect when users restart Claude Desktop. Also allow `releases.claude.com` through your firewall, because Claude Desktop contacts it for the [site safety check](#site-safety-check).
Once the switch is on, **Browser site permissions** appears below it. Click the **Manage site permissions** button to choose whether Claude can act on every site except the ones you block, or only on the sites you allow, and add those sites in the same dialog. These are the same site permissions [Claude in Chrome](#claude-in-chrome) uses, and changes to them apply without a restart.
diff --git a/content/claude/third-party/claude-desktop/local-access.md b/content/claude/third-party/claude-desktop/local-access.md
index e40c3107e1..8cac00d3ca 100644
--- a/content/claude/third-party/claude-desktop/local-access.md
+++ b/content/claude/third-party/claude-desktop/local-access.md
@@ -53,6 +53,10 @@ The agent cannot attach a network-drive path on its own; only the user can, thro
On macOS, network mounts under `/Volumes/` are currently treated as local folders.
+## Removable drives on Windows
+
+Users can attach a folder on a removable drive, such as a USB stick or an SD card, and file tools work there. The sandbox does not mount removable drives, so shell commands cannot reach them. Copy the relevant files to a local folder before running a script or build against them.
+
## WSL
You do not need Windows Subsystem for Linux (WSL) to run Claude Desktop or Cowork. On Windows, Cowork's sandbox runs on the operating system's built-in virtualization, which the [readiness check](/docs/third-party/claude-desktop/installation#check-device-readiness) verifies. Install the macOS or Windows package (see [System requirements](/docs/third-party/claude-desktop/installation#system-requirements)); there is no installation path inside WSL. Run the Windows app and work with WSL files from there.
diff --git a/content/claude/third-party/claude-desktop/mdm.md b/content/claude/third-party/claude-desktop/mdm.md
index 822dafce65..fe25b7309a 100644
--- a/content/claude/third-party/claude-desktop/mdm.md
+++ b/content/claude/third-party/claude-desktop/mdm.md
@@ -41,7 +41,7 @@ The window is organized into sections in the left sidebar. Work through them in
| Section | What you set |
| ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Connection** | Inference provider (Gateway, Claude API, Google Cloud's Agent Platform, Bedrock, Bedrock Mantle, or Foundry) and its credentials
Model list
Organization UUID
Optional credential-helper script |
-| **Workspace** | Which of Cowork, Code, and Chat are available
Allowed egress hosts for the sandbox
Disabled built-in tools
Allowed workspace folders |
+| **Capabilities** | Which of Cowork, Code, and Chat are available
Allowed egress hosts for the sandbox
Disabled built-in tools
Allowed workspace folders |
| **Connectors** | Managed MCP servers pushed to all users
Whether users can add their own local MCP servers
Whether desktop extensions (`.mcpb`) are allowed
Whether unsigned extensions are rejected |
| **Telemetry & updates** | OpenTelemetry collector endpoint
Whether auto-updates are blocked, and the enforcement window if not
The three Anthropic-bound telemetry toggles (essential, nonessential, nonessential services) |
| **Limits** | Per-device token cap and its window length
Retention periods after which idle chats, Cowork tasks, and Code sessions are deleted, and the hold that suspends deletion |
diff --git a/content/en/about-claude/model-deprecations.md b/content/en/about-claude/model-deprecations.md
index 921d3da420..bafa7dac4b 100644
--- a/content/en/about-claude/model-deprecations.md
+++ b/content/en/about-claude/model-deprecations.md
@@ -71,9 +71,12 @@ At some point, Anthropic hopes to make past models publicly available again. In
Current and recently retired models are listed in the following table with their status:
| API model name | Current state | Deprecated | Tentative retirement date |
-| -------------------------- | ------------- | ----------------- | ---------------------------------- |
+| :------------------------- | :------------ | :---------------- | :--------------------------------- |
| claude-fable-5-1 | Active | N/A | Not sooner than September 1, 2027 |
+| claude-mythos-5-1 | Active | N/A | Not sooner than September 1, 2027 |
| claude-fable-5 | Active | N/A | Not sooner than June 9, 2027 |
+| claude-mythos-5 | Active | N/A | Not sooner than June 9, 2027 |
+| claude-mythos-preview | Deprecated | June 9, 2026 | To be announced |
| claude-opus-5 | Active | N/A | Not sooner than July 24, 2027 |
| claude-opus-4-8 | Active | N/A | Not sooner than May 28, 2027 |
| claude-opus-4-7 | Active | N/A | Not sooner than April 16, 2027 |
diff --git a/content/en/agents-and-tools/agent-skills/quickstart.md b/content/en/agents-and-tools/agent-skills/quickstart.md
index 361a6097e7..d5278cf397 100644
--- a/content/en/agents-and-tools/agent-skills/quickstart.md
+++ b/content/en/agents-and-tools/agent-skills/quickstart.md
@@ -29,7 +29,7 @@ Pre-built Agent Skills extend Claude's capabilities with specialized expertise f
First, check what Skills are available. Use the Skills API to list all Anthropic-managed Skills. Each language tab is an excerpt from one continuous script, with any imports and client setup at the top:
-
+
```bash cURL
# List Anthropic-managed Skills
curl --fail-with-body -sS "https://api.anthropic.com/v1/skills?source=anthropic" \
diff --git a/content/en/api/beta.md b/content/en/api/beta.md
index e1decd48b3..f2551da61b 100644
--- a/content/en/api/beta.md
+++ b/content/en/api/beta.md
@@ -2499,7 +2499,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -2541,7 +2541,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `BetaToolChangeMCPToolsetReference object`
@@ -8772,7 +8772,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -8814,7 +8814,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `BetaToolChangeMCPToolsetReference object`
@@ -12733,7 +12733,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -12775,7 +12775,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `BetaToolChangeMCPToolsetReference object`
@@ -65362,7 +65362,7 @@ curl https://api.anthropic.com/v1/skills \
-H 'Content-Type: multipart/form-data' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
- -F files='["Example data"]'
+ -F 'files[]=@/path/to/file'
```
##### Response (200)
@@ -66166,7 +66166,7 @@ curl https://api.anthropic.com/v1/skills/$SKILL_ID/versions \
-H 'Content-Type: multipart/form-data' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
- -F files='["Example data"]'
+ -F 'files[]=@/path/to/file'
```
##### Response (200)
@@ -83431,7 +83431,7 @@ archived tunnels are excluded unless `include_archived` is set.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -83580,6 +83580,7 @@ archived tunnels are excluded unless `include_archived` is set.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -83622,7 +83623,7 @@ Retrieve a single tunnel in the caller's organization by ID.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -83767,6 +83768,7 @@ Retrieve a single tunnel in the caller's organization by ID.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -83809,7 +83811,7 @@ tunnel returns the existing record unchanged.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -83955,6 +83957,7 @@ tunnel returns the existing record unchanged.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -83997,7 +84000,7 @@ access logs.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -84120,6 +84123,7 @@ access logs.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/reveal_token \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -84157,7 +84161,7 @@ restarted after rotation must use the new value. An optional
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -84288,6 +84292,7 @@ restarted after rotation must use the new value. An optional
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/rotate_token \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -84328,7 +84333,7 @@ holds at most two non-archived certificates.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -84483,6 +84488,7 @@ holds at most two non-archived certificates.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"ca_certificate_pem": "-----BEGIN CERTIFICATE-----\nMIIBexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexa\n...illustrative placeholder, not a real certificate...\n-----END CERTIFICATE-----\n"
@@ -84545,7 +84551,7 @@ Archived certificates are excluded unless `include_archived` is set.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -84694,6 +84700,7 @@ Archived certificates are excluded unless `include_archived` is set.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -84740,7 +84747,7 @@ Retrieve a single certificate registered on a tunnel by ID.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -84885,6 +84892,7 @@ Retrieve a single certificate registered on a tunnel by ID.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -84930,7 +84938,7 @@ certificate is added.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -85076,6 +85084,7 @@ certificate is added.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -88374,11 +88383,15 @@ curl https://api.anthropic.com/v1/organizations/analytics/artifacts \
**POST** `/v1/organizations/spend_limits`
-Set a per-user spend limit override.
+Set a spend limit.
Upsert keyed on (scope, period): setting a limit that already exists
-overwrites it in place. Only `scope.type: "user"` is accepted; seat-tier,
-group, and organization-level defaults are configured in claude.ai.
+overwrites it in place. A Claude Enterprise organization sets `user`
+limits. Its seat-tier, group, and organization-level defaults are configured
+in claude.ai. A Claude Console organization sets `organization` and
+`workspace` limits, which are monthly and always carry an amount. Setting those
+limits is in an early access preview. To request access, contact your
+Anthropic account team.
#### Body parameters
@@ -88386,19 +88399,43 @@ group, and organization-level defaults are configured in claude.ai.
Limit amount as a non-negative integer decimal string in the minor unit of the organization's billing currency (cents for USD): "50000" is $500.00. `null` sets an explicit no-limit override for this scope and `period` only — each period resolves independently, so caps for other periods still apply.
-- `scope: object`
+- `scope: User or Organization or Workspace`
- Scope selecting a single member of the organization.
+ What the limit applies to. Claude Enterprise organizations set `user` limits. Claude Console organizations set `organization` and `workspace` limits. Any other combination returns 400. Setting `organization` and `workspace` limits through the API is in an early access preview. To request access, contact your Anthropic account team.
- - `type: "user"`
+ - `User object`
- Scope type. Always `user` for this scope.
+ Scope selecting a single member of the organization.
- default: user
+ - `type: "user"`
- - `user_id: string`
+ Scope type. Always `user` for this scope.
- Tagged ID of the member the spend limit applies to.
+ default: user
+
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
- `period: optional "daily" or "monthly" or "weekly"`
@@ -88448,7 +88485,7 @@ group, and organization-level defaults are configured in claude.ai.
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -88496,6 +88533,20 @@ group, and organization-level defaults are configured in claude.ai.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -88589,7 +88640,7 @@ Retrieve a spend limit by ID.
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -88637,6 +88688,20 @@ Retrieve a spend limit by ID.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -88673,11 +88738,13 @@ curl https://api.anthropic.com/v1/organizations/spend_limits/$SPEND_LIMIT_ID \
**DELETE** `/v1/organizations/spend_limits/{spend_limit_id}`
-Delete a per-user spend limit override.
+Delete a spend limit.
-The member falls back to any inherited spend limit at that period.
-Seat-tier, group, and organization-level rows cannot be deleted via
-this endpoint.
+For a Claude Enterprise organization, this deletes a per-user override, and
+the member falls back to any inherited spend limit at that period. Its
+seat-tier, group, and organization-level rows cannot be deleted via this
+endpoint. A Claude Console organization deletes its organization and
+workspace limits. Deleting them through the API is in an early access preview.
#### Path parameters
@@ -88755,35 +88822,47 @@ Paginates by member, so a member's periods never split across pages.
- `data: array of BetaSpendSummary`
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -88807,21 +88886,67 @@ Paginates by member, so a member's periods never split across pages.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -88867,6 +88992,20 @@ Paginates by member, so a member's periods never split across pages.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `next_page: string or null`
@@ -89048,35 +89187,47 @@ Requests whose requester is no longer a member are excluded.
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -89100,21 +89251,67 @@ Requests whose requester is no longer a member are excluded.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -89160,6 +89357,20 @@ Requests whose requester is no longer a member are excluded.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -89351,35 +89562,47 @@ requester at the request's period.
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -89403,21 +89626,67 @@ requester at the request's period.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -89463,6 +89732,20 @@ requester at the request's period.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -89697,7 +89980,7 @@ the member was blocked on. Anthropic emails the requester unless
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -89745,6 +90028,20 @@ the member was blocked on. Anthropic emails the requester unless
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -89755,35 +90052,47 @@ the member was blocked on. Anthropic emails the requester unless
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -89807,21 +90116,67 @@ the member was blocked on. Anthropic emails the requester unless
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -89867,6 +90222,20 @@ the member was blocked on. Anthropic emails the requester unless
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -90073,35 +90442,47 @@ Idempotent on `denied`; denying an already-`approved` request returns
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -90125,21 +90506,67 @@ Idempotent on `denied`; denying an already-`approved` request returns
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -90185,6 +90612,20 @@ Idempotent on `denied`; denying an already-`approved` request returns
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
diff --git a/content/en/api/beta/messages.md b/content/en/api/beta/messages.md
index 8d7a48a632..d59eb13535 100644
--- a/content/en/api/beta/messages.md
+++ b/content/en/api/beta/messages.md
@@ -1318,7 +1318,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -1360,7 +1360,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `BetaToolChangeMCPToolsetReference object`
@@ -7591,7 +7591,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -7633,7 +7633,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `BetaToolChangeMCPToolsetReference object`
@@ -16961,7 +16961,7 @@ curl https://api.anthropic.com/v1/messages/count_tokens \
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -17003,7 +17003,7 @@ curl https://api.anthropic.com/v1/messages/count_tokens \
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `BetaToolChangeMCPToolsetReference object`
@@ -23603,7 +23603,7 @@ curl https://api.anthropic.com/v1/messages/count_tokens \
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -23645,7 +23645,7 @@ curl https://api.anthropic.com/v1/messages/count_tokens \
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `BetaToolChangeMCPToolsetReference object`
@@ -30434,7 +30434,7 @@ curl https://api.anthropic.com/v1/messages/count_tokens \
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -30501,7 +30501,7 @@ curl https://api.anthropic.com/v1/messages/count_tokens \
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -32401,7 +32401,7 @@ curl https://api.anthropic.com/v1/messages/count_tokens \
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -40138,7 +40138,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -40180,7 +40180,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `BetaToolChangeMCPToolsetReference object`
diff --git a/content/en/api/beta/messages/batches.md b/content/en/api/beta/messages/batches.md
index 6958c58fd1..2989cf3747 100644
--- a/content/en/api/beta/messages/batches.md
+++ b/content/en/api/beta/messages/batches.md
@@ -1338,7 +1338,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -1380,7 +1380,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `BetaToolChangeMCPToolsetReference object`
diff --git a/content/en/api/beta/messages/batches/create.md b/content/en/api/beta/messages/batches/create.md
index 5598dedd4a..e00bb46cf4 100644
--- a/content/en/api/beta/messages/batches/create.md
+++ b/content/en/api/beta/messages/batches/create.md
@@ -1336,7 +1336,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -1378,7 +1378,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `BetaToolChangeMCPToolsetReference object`
diff --git a/content/en/api/beta/messages/count_tokens.md b/content/en/api/beta/messages/count_tokens.md
index 3f3574f855..964ae2a21b 100644
--- a/content/en/api/beta/messages/count_tokens.md
+++ b/content/en/api/beta/messages/count_tokens.md
@@ -1304,7 +1304,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -1346,7 +1346,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `BetaToolChangeMCPToolsetReference object`
diff --git a/content/en/api/beta/messages/create.md b/content/en/api/beta/messages/create.md
index f12624e9d8..676a552bca 100644
--- a/content/en/api/beta/messages/create.md
+++ b/content/en/api/beta/messages/create.md
@@ -1316,7 +1316,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -1358,7 +1358,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `BetaToolChangeMCPToolReference object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `BetaToolChangeMCPToolsetReference object`
diff --git a/content/en/api/beta/organization.md b/content/en/api/beta/organization.md
index b86be03a91..5d114b7293 100644
--- a/content/en/api/beta/organization.md
+++ b/content/en/api/beta/organization.md
@@ -11736,7 +11736,7 @@ archived tunnels are excluded unless `include_archived` is set.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -11885,6 +11885,7 @@ archived tunnels are excluded unless `include_archived` is set.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -11927,7 +11928,7 @@ Retrieve a single tunnel in the caller's organization by ID.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -12072,6 +12073,7 @@ Retrieve a single tunnel in the caller's organization by ID.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -12114,7 +12116,7 @@ tunnel returns the existing record unchanged.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -12260,6 +12262,7 @@ tunnel returns the existing record unchanged.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -12302,7 +12305,7 @@ access logs.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -12425,6 +12428,7 @@ access logs.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/reveal_token \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -12462,7 +12466,7 @@ restarted after rotation must use the new value. An optional
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -12593,6 +12597,7 @@ restarted after rotation must use the new value. An optional
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/rotate_token \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -12633,7 +12638,7 @@ holds at most two non-archived certificates.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -12788,6 +12793,7 @@ holds at most two non-archived certificates.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"ca_certificate_pem": "-----BEGIN CERTIFICATE-----\nMIIBexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexa\n...illustrative placeholder, not a real certificate...\n-----END CERTIFICATE-----\n"
@@ -12850,7 +12856,7 @@ Archived certificates are excluded unless `include_archived` is set.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -12999,6 +13005,7 @@ Archived certificates are excluded unless `include_archived` is set.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -13045,7 +13052,7 @@ Retrieve a single certificate registered on a tunnel by ID.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -13190,6 +13197,7 @@ Retrieve a single certificate registered on a tunnel by ID.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -13235,7 +13243,7 @@ certificate is added.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -13381,6 +13389,7 @@ certificate is added.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -16679,11 +16688,15 @@ curl https://api.anthropic.com/v1/organizations/analytics/artifacts \
**POST** `/v1/organizations/spend_limits`
-Set a per-user spend limit override.
+Set a spend limit.
Upsert keyed on (scope, period): setting a limit that already exists
-overwrites it in place. Only `scope.type: "user"` is accepted; seat-tier,
-group, and organization-level defaults are configured in claude.ai.
+overwrites it in place. A Claude Enterprise organization sets `user`
+limits. Its seat-tier, group, and organization-level defaults are configured
+in claude.ai. A Claude Console organization sets `organization` and
+`workspace` limits, which are monthly and always carry an amount. Setting those
+limits is in an early access preview. To request access, contact your
+Anthropic account team.
#### Body parameters
@@ -16691,19 +16704,43 @@ group, and organization-level defaults are configured in claude.ai.
Limit amount as a non-negative integer decimal string in the minor unit of the organization's billing currency (cents for USD): "50000" is $500.00. `null` sets an explicit no-limit override for this scope and `period` only — each period resolves independently, so caps for other periods still apply.
-- `scope: object`
+- `scope: User or Organization or Workspace`
- Scope selecting a single member of the organization.
+ What the limit applies to. Claude Enterprise organizations set `user` limits. Claude Console organizations set `organization` and `workspace` limits. Any other combination returns 400. Setting `organization` and `workspace` limits through the API is in an early access preview. To request access, contact your Anthropic account team.
- - `type: "user"`
+ - `User object`
- Scope type. Always `user` for this scope.
+ Scope selecting a single member of the organization.
- default: user
+ - `type: "user"`
- - `user_id: string`
+ Scope type. Always `user` for this scope.
+
+ default: user
+
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
- Tagged ID of the member the spend limit applies to.
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
- `period: optional "daily" or "monthly" or "weekly"`
@@ -16753,7 +16790,7 @@ group, and organization-level defaults are configured in claude.ai.
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -16801,6 +16838,20 @@ group, and organization-level defaults are configured in claude.ai.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -16894,7 +16945,7 @@ Retrieve a spend limit by ID.
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -16942,6 +16993,20 @@ Retrieve a spend limit by ID.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -16978,11 +17043,13 @@ curl https://api.anthropic.com/v1/organizations/spend_limits/$SPEND_LIMIT_ID \
**DELETE** `/v1/organizations/spend_limits/{spend_limit_id}`
-Delete a per-user spend limit override.
+Delete a spend limit.
-The member falls back to any inherited spend limit at that period.
-Seat-tier, group, and organization-level rows cannot be deleted via
-this endpoint.
+For a Claude Enterprise organization, this deletes a per-user override, and
+the member falls back to any inherited spend limit at that period. Its
+seat-tier, group, and organization-level rows cannot be deleted via this
+endpoint. A Claude Console organization deletes its organization and
+workspace limits. Deleting them through the API is in an early access preview.
#### Path parameters
@@ -17060,35 +17127,47 @@ Paginates by member, so a member's periods never split across pages.
- `data: array of BetaSpendSummary`
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -17112,21 +17191,67 @@ Paginates by member, so a member's periods never split across pages.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -17172,6 +17297,20 @@ Paginates by member, so a member's periods never split across pages.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `next_page: string or null`
@@ -17353,35 +17492,47 @@ Requests whose requester is no longer a member are excluded.
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -17405,21 +17556,67 @@ Requests whose requester is no longer a member are excluded.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -17465,6 +17662,20 @@ Requests whose requester is no longer a member are excluded.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -17656,35 +17867,47 @@ requester at the request's period.
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -17708,21 +17931,67 @@ requester at the request's period.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -17768,6 +18037,20 @@ requester at the request's period.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -18002,7 +18285,7 @@ the member was blocked on. Anthropic emails the requester unless
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -18050,6 +18333,20 @@ the member was blocked on. Anthropic emails the requester unless
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -18060,35 +18357,47 @@ the member was blocked on. Anthropic emails the requester unless
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -18112,21 +18421,67 @@ the member was blocked on. Anthropic emails the requester unless
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -18172,6 +18527,20 @@ the member was blocked on. Anthropic emails the requester unless
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -18378,35 +18747,47 @@ Idempotent on `denied`; denying an already-`approved` request returns
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -18430,21 +18811,67 @@ Idempotent on `denied`; denying an already-`approved` request returns
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -18490,6 +18917,20 @@ Idempotent on `denied`; denying an already-`approved` request returns
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
diff --git a/content/en/api/beta/organization/mcp_tunnels.md b/content/en/api/beta/organization/mcp_tunnels.md
index 4fa85de621..2de3d4d172 100644
--- a/content/en/api/beta/organization/mcp_tunnels.md
+++ b/content/en/api/beta/organization/mcp_tunnels.md
@@ -48,7 +48,7 @@ archived tunnels are excluded unless `include_archived` is set.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -197,6 +197,7 @@ archived tunnels are excluded unless `include_archived` is set.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -239,7 +240,7 @@ Retrieve a single tunnel in the caller's organization by ID.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -384,6 +385,7 @@ Retrieve a single tunnel in the caller's organization by ID.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -426,7 +428,7 @@ tunnel returns the existing record unchanged.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -572,6 +574,7 @@ tunnel returns the existing record unchanged.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -614,7 +617,7 @@ access logs.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -737,6 +740,7 @@ access logs.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/reveal_token \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -774,7 +778,7 @@ restarted after rotation must use the new value. An optional
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -905,6 +909,7 @@ restarted after rotation must use the new value. An optional
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/rotate_token \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -1008,7 +1013,7 @@ holds at most two non-archived certificates.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -1163,6 +1168,7 @@ holds at most two non-archived certificates.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"ca_certificate_pem": "-----BEGIN CERTIFICATE-----\nMIIBexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexa\n...illustrative placeholder, not a real certificate...\n-----END CERTIFICATE-----\n"
@@ -1225,7 +1231,7 @@ Archived certificates are excluded unless `include_archived` is set.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -1374,6 +1380,7 @@ Archived certificates are excluded unless `include_archived` is set.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -1420,7 +1427,7 @@ Retrieve a single certificate registered on a tunnel by ID.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -1565,6 +1572,7 @@ Retrieve a single certificate registered on a tunnel by ID.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -1610,7 +1618,7 @@ certificate is added.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -1756,6 +1764,7 @@ certificate is added.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
diff --git a/content/en/api/beta/organization/mcp_tunnels/archive.md b/content/en/api/beta/organization/mcp_tunnels/archive.md
index fef4aeb56f..46ba376ed6 100644
--- a/content/en/api/beta/organization/mcp_tunnels/archive.md
+++ b/content/en/api/beta/organization/mcp_tunnels/archive.md
@@ -28,7 +28,7 @@ tunnel returns the existing record unchanged.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -174,6 +174,7 @@ tunnel returns the existing record unchanged.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
diff --git a/content/en/api/beta/organization/mcp_tunnels/list.md b/content/en/api/beta/organization/mcp_tunnels/list.md
index 16eba312f3..915faeef88 100644
--- a/content/en/api/beta/organization/mcp_tunnels/list.md
+++ b/content/en/api/beta/organization/mcp_tunnels/list.md
@@ -46,7 +46,7 @@ archived tunnels are excluded unless `include_archived` is set.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -195,6 +195,7 @@ archived tunnels are excluded unless `include_archived` is set.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
diff --git a/content/en/api/beta/organization/mcp_tunnels/retrieve.md b/content/en/api/beta/organization/mcp_tunnels/retrieve.md
index 292f499af1..dea3b126e5 100644
--- a/content/en/api/beta/organization/mcp_tunnels/retrieve.md
+++ b/content/en/api/beta/organization/mcp_tunnels/retrieve.md
@@ -23,7 +23,7 @@ Retrieve a single tunnel in the caller's organization by ID.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -168,6 +168,7 @@ Retrieve a single tunnel in the caller's organization by ID.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
diff --git a/content/en/api/beta/organization/mcp_tunnels/reveal_token.md b/content/en/api/beta/organization/mcp_tunnels/reveal_token.md
index 98f15a0698..965e0d0b18 100644
--- a/content/en/api/beta/organization/mcp_tunnels/reveal_token.md
+++ b/content/en/api/beta/organization/mcp_tunnels/reveal_token.md
@@ -28,7 +28,7 @@ access logs.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -151,6 +151,7 @@ access logs.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/reveal_token \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
diff --git a/content/en/api/beta/organization/mcp_tunnels/rotate_token.md b/content/en/api/beta/organization/mcp_tunnels/rotate_token.md
index c08cd16293..185961ad0e 100644
--- a/content/en/api/beta/organization/mcp_tunnels/rotate_token.md
+++ b/content/en/api/beta/organization/mcp_tunnels/rotate_token.md
@@ -27,7 +27,7 @@ restarted after rotation must use the new value. An optional
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -158,6 +158,7 @@ restarted after rotation must use the new value. An optional
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/rotate_token \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
diff --git a/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates.md b/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates.md
index 78f35e4dfb..85838c965c 100644
--- a/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates.md
+++ b/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates.md
@@ -30,7 +30,7 @@ holds at most two non-archived certificates.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -185,6 +185,7 @@ holds at most two non-archived certificates.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"ca_certificate_pem": "-----BEGIN CERTIFICATE-----\nMIIBexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexa\n...illustrative placeholder, not a real certificate...\n-----END CERTIFICATE-----\n"
@@ -247,7 +248,7 @@ Archived certificates are excluded unless `include_archived` is set.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -396,6 +397,7 @@ Archived certificates are excluded unless `include_archived` is set.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -442,7 +444,7 @@ Retrieve a single certificate registered on a tunnel by ID.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -587,6 +589,7 @@ Retrieve a single certificate registered on a tunnel by ID.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
@@ -632,7 +635,7 @@ certificate is added.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -778,6 +781,7 @@ certificate is added.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
diff --git a/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/archive.md b/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/archive.md
index 8d7e100235..12f175d0ed 100644
--- a/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/archive.md
+++ b/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/archive.md
@@ -31,7 +31,7 @@ certificate is added.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -177,6 +177,7 @@ certificate is added.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \
-X POST \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
diff --git a/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/create.md b/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/create.md
index e5d3bc0dc7..0e51716011 100644
--- a/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/create.md
+++ b/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/create.md
@@ -28,7 +28,7 @@ holds at most two non-archived certificates.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -183,6 +183,7 @@ holds at most two non-archived certificates.
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"ca_certificate_pem": "-----BEGIN CERTIFICATE-----\nMIIBexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexa\n...illustrative placeholder, not a real certificate...\n-----END CERTIFICATE-----\n"
diff --git a/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/list.md b/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/list.md
index 05b5fc553a..1c98b7489b 100644
--- a/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/list.md
+++ b/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/list.md
@@ -45,7 +45,7 @@ Archived certificates are excluded unless `include_archived` is set.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -194,6 +194,7 @@ Archived certificates are excluded unless `include_archived` is set.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
diff --git a/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/retrieve.md b/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/retrieve.md
index 89dd3f3ac5..7fe952ac44 100644
--- a/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/retrieve.md
+++ b/content/en/api/beta/organization/mcp_tunnels/tunnel_certificates/retrieve.md
@@ -27,7 +27,7 @@ Retrieve a single certificate registered on a tunnel by ID.
- `"anthropic-beta": array of AnthropicBeta`
- Optional header to specify the beta version(s) you want to use.
+ This endpoint is in beta: requests must send `mcp-tunnels-2026-05-19` in this header.
- `string`
@@ -172,6 +172,7 @@ Retrieve a single certificate registered on a tunnel by ID.
```bash
curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \
-H 'anthropic-version: 2023-06-01' \
+ -H 'anthropic-beta: mcp-tunnels-2026-05-19' \
-H "X-Api-Key: $ANTHROPIC_API_KEY"
```
diff --git a/content/en/api/beta/organization/spend_limits.md b/content/en/api/beta/organization/spend_limits.md
index ee041cbe3d..278b2d8a9b 100644
--- a/content/en/api/beta/organization/spend_limits.md
+++ b/content/en/api/beta/organization/spend_limits.md
@@ -9,11 +9,15 @@ url: https://platform.claude.com/docs/en/api/beta/organization/spend_limits
**POST** `/v1/organizations/spend_limits`
-Set a per-user spend limit override.
+Set a spend limit.
Upsert keyed on (scope, period): setting a limit that already exists
-overwrites it in place. Only `scope.type: "user"` is accepted; seat-tier,
-group, and organization-level defaults are configured in claude.ai.
+overwrites it in place. A Claude Enterprise organization sets `user`
+limits. Its seat-tier, group, and organization-level defaults are configured
+in claude.ai. A Claude Console organization sets `organization` and
+`workspace` limits, which are monthly and always carry an amount. Setting those
+limits is in an early access preview. To request access, contact your
+Anthropic account team.
### Body parameters
@@ -21,19 +25,43 @@ group, and organization-level defaults are configured in claude.ai.
Limit amount as a non-negative integer decimal string in the minor unit of the organization's billing currency (cents for USD): "50000" is $500.00. `null` sets an explicit no-limit override for this scope and `period` only — each period resolves independently, so caps for other periods still apply.
-- `scope: object`
+- `scope: User or Organization or Workspace`
- Scope selecting a single member of the organization.
+ What the limit applies to. Claude Enterprise organizations set `user` limits. Claude Console organizations set `organization` and `workspace` limits. Any other combination returns 400. Setting `organization` and `workspace` limits through the API is in an early access preview. To request access, contact your Anthropic account team.
- - `type: "user"`
+ - `User object`
- Scope type. Always `user` for this scope.
+ Scope selecting a single member of the organization.
- default: user
+ - `type: "user"`
- - `user_id: string`
+ Scope type. Always `user` for this scope.
+
+ default: user
+
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
- Tagged ID of the member the spend limit applies to.
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
- `period: optional "daily" or "monthly" or "weekly"`
@@ -83,7 +111,7 @@ group, and organization-level defaults are configured in claude.ai.
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -131,6 +159,20 @@ group, and organization-level defaults are configured in claude.ai.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -224,7 +266,7 @@ Retrieve a spend limit by ID.
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -272,6 +314,20 @@ Retrieve a spend limit by ID.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -308,11 +364,13 @@ curl https://api.anthropic.com/v1/organizations/spend_limits/$SPEND_LIMIT_ID \
**DELETE** `/v1/organizations/spend_limits/{spend_limit_id}`
-Delete a per-user spend limit override.
+Delete a spend limit.
-The member falls back to any inherited spend limit at that period.
-Seat-tier, group, and organization-level rows cannot be deleted via
-this endpoint.
+For a Claude Enterprise organization, this deletes a per-user override, and
+the member falls back to any inherited spend limit at that period. Its
+seat-tier, group, and organization-level rows cannot be deleted via this
+endpoint. A Claude Console organization deletes its organization and
+workspace limits. Deleting them through the API is in an early access preview.
### Path parameters
@@ -390,35 +448,47 @@ Paginates by member, so a member's periods never split across pages.
- `data: array of BetaSpendSummary`
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -442,21 +512,67 @@ Paginates by member, so a member's periods never split across pages.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -502,6 +618,20 @@ Paginates by member, so a member's periods never split across pages.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `next_page: string or null`
@@ -588,7 +718,7 @@ curl https://api.anthropic.com/v1/organizations/spend_limits/effective \
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -636,6 +766,20 @@ curl https://api.anthropic.com/v1/organizations/spend_limits/effective \
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -648,35 +792,47 @@ curl https://api.anthropic.com/v1/organizations/spend_limits/effective \
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -700,21 +856,67 @@ curl https://api.anthropic.com/v1/organizations/spend_limits/effective \
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -760,6 +962,20 @@ curl https://api.anthropic.com/v1/organizations/spend_limits/effective \
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
### Spend Limit Delete Response
@@ -909,35 +1125,47 @@ Requests whose requester is no longer a member are excluded.
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -961,21 +1189,67 @@ Requests whose requester is no longer a member are excluded.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -1021,6 +1295,20 @@ Requests whose requester is no longer a member are excluded.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -1212,35 +1500,47 @@ requester at the request's period.
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -1264,21 +1564,67 @@ requester at the request's period.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -1324,6 +1670,20 @@ requester at the request's period.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -1558,7 +1918,7 @@ the member was blocked on. Anthropic emails the requester unless
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -1606,6 +1966,20 @@ the member was blocked on. Anthropic emails the requester unless
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -1616,35 +1990,47 @@ the member was blocked on. Anthropic emails the requester unless
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -1668,21 +2054,67 @@ the member was blocked on. Anthropic emails the requester unless
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -1728,6 +2160,20 @@ the member was blocked on. Anthropic emails the requester unless
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -1934,35 +2380,47 @@ Idempotent on `denied`; denying an already-`approved` request returns
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -1986,21 +2444,67 @@ Idempotent on `denied`; denying an already-`approved` request returns
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -2046,6 +2550,20 @@ Idempotent on `denied`; denying an already-`approved` request returns
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
diff --git a/content/en/api/beta/organization/spend_limits/create.md b/content/en/api/beta/organization/spend_limits/create.md
index 2c44b36d6c..b47d752173 100644
--- a/content/en/api/beta/organization/spend_limits/create.md
+++ b/content/en/api/beta/organization/spend_limits/create.md
@@ -7,11 +7,15 @@ url: https://platform.claude.com/docs/en/api/beta/organization/spend_limits/crea
**POST** `/v1/organizations/spend_limits`
-Set a per-user spend limit override.
+Set a spend limit.
Upsert keyed on (scope, period): setting a limit that already exists
-overwrites it in place. Only `scope.type: "user"` is accepted; seat-tier,
-group, and organization-level defaults are configured in claude.ai.
+overwrites it in place. A Claude Enterprise organization sets `user`
+limits. Its seat-tier, group, and organization-level defaults are configured
+in claude.ai. A Claude Console organization sets `organization` and
+`workspace` limits, which are monthly and always carry an amount. Setting those
+limits is in an early access preview. To request access, contact your
+Anthropic account team.
## Body parameters
@@ -19,19 +23,43 @@ group, and organization-level defaults are configured in claude.ai.
Limit amount as a non-negative integer decimal string in the minor unit of the organization's billing currency (cents for USD): "50000" is $500.00. `null` sets an explicit no-limit override for this scope and `period` only — each period resolves independently, so caps for other periods still apply.
-- `scope: object`
+- `scope: User or Organization or Workspace`
- Scope selecting a single member of the organization.
+ What the limit applies to. Claude Enterprise organizations set `user` limits. Claude Console organizations set `organization` and `workspace` limits. Any other combination returns 400. Setting `organization` and `workspace` limits through the API is in an early access preview. To request access, contact your Anthropic account team.
- - `type: "user"`
+ - `User object`
- Scope type. Always `user` for this scope.
+ Scope selecting a single member of the organization.
- default: user
+ - `type: "user"`
- - `user_id: string`
+ Scope type. Always `user` for this scope.
- Tagged ID of the member the spend limit applies to.
+ default: user
+
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
- `period: optional "daily" or "monthly" or "weekly"`
@@ -81,7 +109,7 @@ group, and organization-level defaults are configured in claude.ai.
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -129,6 +157,20 @@ group, and organization-level defaults are configured in claude.ai.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
diff --git a/content/en/api/beta/organization/spend_limits/delete.md b/content/en/api/beta/organization/spend_limits/delete.md
index f09e86ad51..daec575f62 100644
--- a/content/en/api/beta/organization/spend_limits/delete.md
+++ b/content/en/api/beta/organization/spend_limits/delete.md
@@ -7,11 +7,13 @@ url: https://platform.claude.com/docs/en/api/beta/organization/spend_limits/dele
**DELETE** `/v1/organizations/spend_limits/{spend_limit_id}`
-Delete a per-user spend limit override.
+Delete a spend limit.
-The member falls back to any inherited spend limit at that period.
-Seat-tier, group, and organization-level rows cannot be deleted via
-this endpoint.
+For a Claude Enterprise organization, this deletes a per-user override, and
+the member falls back to any inherited spend limit at that period. Its
+seat-tier, group, and organization-level rows cannot be deleted via this
+endpoint. A Claude Console organization deletes its organization and
+workspace limits. Deleting them through the API is in an early access preview.
## Path parameters
diff --git a/content/en/api/beta/organization/spend_limits/increase_requests.md b/content/en/api/beta/organization/spend_limits/increase_requests.md
index 549edbd512..adb071103b 100644
--- a/content/en/api/beta/organization/spend_limits/increase_requests.md
+++ b/content/en/api/beta/organization/spend_limits/increase_requests.md
@@ -140,35 +140,47 @@ Requests whose requester is no longer a member are excluded.
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -192,21 +204,67 @@ Requests whose requester is no longer a member are excluded.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -252,6 +310,20 @@ Requests whose requester is no longer a member are excluded.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -443,35 +515,47 @@ requester at the request's period.
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -495,21 +579,67 @@ requester at the request's period.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -555,6 +685,20 @@ requester at the request's period.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -789,7 +933,7 @@ the member was blocked on. Anthropic emails the requester unless
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -837,6 +981,20 @@ the member was blocked on. Anthropic emails the requester unless
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -847,35 +1005,47 @@ the member was blocked on. Anthropic emails the requester unless
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -899,21 +1069,67 @@ the member was blocked on. Anthropic emails the requester unless
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
+
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
- Tagged ID of the member the spend limit applies to.
+ - `workspace_id: string`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -959,6 +1175,20 @@ the member was blocked on. Anthropic emails the requester unless
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -1165,35 +1395,47 @@ Idempotent on `denied`; denying an already-`approved` request returns
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -1217,21 +1459,67 @@ Idempotent on `denied`; denying an already-`approved` request returns
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -1277,6 +1565,20 @@ Idempotent on `denied`; denying an already-`approved` request returns
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -1450,35 +1752,47 @@ curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$S
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -1502,21 +1816,67 @@ curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$S
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -1562,6 +1922,20 @@ curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$S
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
@@ -1708,7 +2082,7 @@ curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$S
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -1756,6 +2130,20 @@ curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$S
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -1766,35 +2154,47 @@ curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$S
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -1818,21 +2218,67 @@ curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$S
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
+
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -1878,6 +2324,20 @@ curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$S
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
diff --git a/content/en/api/beta/organization/spend_limits/increase_requests/approve.md b/content/en/api/beta/organization/spend_limits/increase_requests/approve.md
index 45d24b476d..065f372053 100644
--- a/content/en/api/beta/organization/spend_limits/increase_requests/approve.md
+++ b/content/en/api/beta/organization/spend_limits/increase_requests/approve.md
@@ -170,7 +170,7 @@ the member was blocked on. Anthropic emails the requester unless
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -218,6 +218,20 @@ the member was blocked on. Anthropic emails the requester unless
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
@@ -228,35 +242,47 @@ the member was blocked on. Anthropic emails the requester unless
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -280,21 +306,67 @@ the member was blocked on. Anthropic emails the requester unless
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
+
+ - `User object`
+
+ Scope selecting a single member of the organization.
- Scope selecting a single member of the organization.
+ - `type: "user"`
+
+ Scope type. Always `user` for this scope.
- - `type: "user"`
+ default: user
- Scope type. Always `user` for this scope.
+ - `user_id: string`
- default: user
+ Tagged ID of the member the spend limit applies to.
- - `user_id: string`
+ - `SeatTier object`
- Tagged ID of the member the spend limit applies to.
+ - `type: "seat_tier"`
+
+ default: seat_tier
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -340,6 +412,20 @@ the member was blocked on. Anthropic emails the requester unless
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
diff --git a/content/en/api/beta/organization/spend_limits/increase_requests/deny.md b/content/en/api/beta/organization/spend_limits/increase_requests/deny.md
index 2e423a32bd..f42803a6cd 100644
--- a/content/en/api/beta/organization/spend_limits/increase_requests/deny.md
+++ b/content/en/api/beta/organization/spend_limits/increase_requests/deny.md
@@ -124,35 +124,47 @@ Idempotent on `denied`; denying an already-`approved` request returns
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -176,21 +188,67 @@ Idempotent on `denied`; denying an already-`approved` request returns
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -236,6 +294,20 @@ Idempotent on `denied`; denying an already-`approved` request returns
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
diff --git a/content/en/api/beta/organization/spend_limits/increase_requests/list.md b/content/en/api/beta/organization/spend_limits/increase_requests/list.md
index a9b094b5a2..8b52d639bc 100644
--- a/content/en/api/beta/organization/spend_limits/increase_requests/list.md
+++ b/content/en/api/beta/organization/spend_limits/increase_requests/list.md
@@ -138,35 +138,47 @@ Requests whose requester is no longer a member are excluded.
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -190,21 +202,67 @@ Requests whose requester is no longer a member are excluded.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -250,6 +308,20 @@ Requests whose requester is no longer a member are excluded.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
diff --git a/content/en/api/beta/organization/spend_limits/increase_requests/retrieve.md b/content/en/api/beta/organization/spend_limits/increase_requests/retrieve.md
index 9ad65b3948..83053bc9c5 100644
--- a/content/en/api/beta/organization/spend_limits/increase_requests/retrieve.md
+++ b/content/en/api/beta/organization/spend_limits/increase_requests/retrieve.md
@@ -120,35 +120,47 @@ requester at the request's period.
Per-member effective-limit report row (`GET /spend_limits/effective`).
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -172,21 +184,67 @@ requester at the request's period.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
- Scope selecting a single member of the organization.
+ - `User object`
- - `type: "user"`
+ Scope selecting a single member of the organization.
- Scope type. Always `user` for this scope.
+ - `type: "user"`
- default: user
+ Scope type. Always `user` for this scope.
- - `user_id: string`
+ default: user
- Tagged ID of the member the spend limit applies to.
+ - `user_id: string`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ Tagged ID of the member the spend limit applies to.
+
+ - `SeatTier object`
+
+ - `type: "seat_tier"`
+
+ default: seat_tier
+
+ - `seat_tier: string`
+
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -232,6 +290,20 @@ requester at the request's period.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `status: "approved" or "denied" or "pending"`
diff --git a/content/en/api/beta/organization/spend_limits/list_effective.md b/content/en/api/beta/organization/spend_limits/list_effective.md
index 748477d949..bddbf1903b 100644
--- a/content/en/api/beta/organization/spend_limits/list_effective.md
+++ b/content/en/api/beta/organization/spend_limits/list_effective.md
@@ -47,35 +47,47 @@ Paginates by member, so a member's periods never split across pages.
- `data: array of BetaSpendSummary`
- - `actor: object`
+ - `actor: UserActor or ScopedAPIKeyActor`
- A user within the organization. `name` and `email_address` are
- null when the underlying account is unavailable or has been deleted;
- `deleted` is true only for deleted accounts.
+ - `UserActor object`
- - `type: "user_actor"`
+ A user within the organization. `name` and `email_address` are
+ null when the underlying account is unavailable or has been deleted;
+ `deleted` is true only for deleted accounts.
- Actor type. Always `user_actor`.
+ - `type: "user_actor"`
- default: user_actor
+ Actor type. Always `user_actor`.
- - `deleted: boolean`
+ default: user_actor
- True only when the underlying account has been deleted.
+ - `deleted: boolean`
- default: false
+ True only when the underlying account has been deleted.
- - `email_address: string or null`
+ default: false
- The user's email address. Null when the account is unavailable or has been deleted.
+ - `email_address: string or null`
- - `name: string or null`
+ The user's email address. Null when the account is unavailable or has been deleted.
- The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
+ - `name: string or null`
- - `user_id: string`
+ The user's current display name. Null when the account is unavailable, has been deleted, or has no name set.
- Tagged ID of the user.
+ - `user_id: string`
+
+ Tagged ID of the user.
+
+ - `ScopedAPIKeyActor object`
+
+ A scoped Admin API key acting on behalf of the organization.
+
+ - `type: "scoped_api_key_actor"`
+
+ default: scoped_api_key_actor
+
+ - `scoped_api_key_id: string`
- `amount: string or null`
@@ -99,21 +111,67 @@ Paginates by member, so a member's periods never split across pages.
The member's spend so far in the current period, as a non-negative decimal string in the minor unit of `currency` (cents for USD). May carry fractional minor units up to three decimal places (e.g. `"12050.5"`) — metered usage is not rounded to whole cents. Reads as `"0"` when the spend reading is temporarily unavailable.
- - `scope: object`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
+
+ - `User object`
+
+ Scope selecting a single member of the organization.
+
+ - `type: "user"`
+
+ Scope type. Always `user` for this scope.
+
+ default: user
- Scope selecting a single member of the organization.
+ - `user_id: string`
- - `type: "user"`
+ Tagged ID of the member the spend limit applies to.
- Scope type. Always `user` for this scope.
+ - `SeatTier object`
- default: user
+ - `type: "seat_tier"`
- - `user_id: string`
+ default: seat_tier
- Tagged ID of the member the spend limit applies to.
+ - `seat_tier: string`
- - `source: User or SeatTier or RBACGroup or 2 more`
+ - `RBACGroup object`
+
+ - `type: "rbac_group"`
+
+ default: rbac_group
+
+ - `rbac_group_id: string`
+
+ - `OrganizationService object`
+
+ - `type: "organization_service"`
+
+ default: organization_service
+
+ - `service: string`
+
+ - `Organization object`
+
+ - `type: "organization"`
+
+ default: organization
+
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
+ - `source: User or SeatTier or RBACGroup or 3 more`
- `User object`
@@ -159,6 +217,20 @@ Paginates by member, so a member's periods never split across pages.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `spend_limit_id: string`
- `next_page: string or null`
diff --git a/content/en/api/beta/organization/spend_limits/retrieve.md b/content/en/api/beta/organization/spend_limits/retrieve.md
index 43450323b3..ddd966530a 100644
--- a/content/en/api/beta/organization/spend_limits/retrieve.md
+++ b/content/en/api/beta/organization/spend_limits/retrieve.md
@@ -55,7 +55,7 @@ Retrieve a spend limit by ID.
- `"weekly"`
- - `scope: User or SeatTier or RBACGroup or 2 more`
+ - `scope: User or SeatTier or RBACGroup or 3 more`
What the limit applies to. A tagged union on `type`; each variant carries the identifier for its scope.
@@ -103,6 +103,20 @@ Retrieve a spend limit by ID.
default: organization
+ - `Workspace object`
+
+ Scope selecting one workspace of a Claude Console organization.
+
+ - `type: "workspace"`
+
+ Scope type. Always `workspace` for this scope.
+
+ default: workspace
+
+ - `workspace_id: string`
+
+ Tagged ID of the workspace the spend limit applies to.
+
- `updated_at: string`
RFC 3339 datetime at which the spend limit was last modified.
diff --git a/content/en/api/beta/skills.md b/content/en/api/beta/skills.md
index 5bbaee97b5..25434144f4 100644
--- a/content/en/api/beta/skills.md
+++ b/content/en/api/beta/skills.md
@@ -206,7 +206,7 @@ curl https://api.anthropic.com/v1/skills \
-H 'Content-Type: multipart/form-data' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
- -F files='["Example data"]'
+ -F 'files[]=@/path/to/file'
```
#### Response (200)
@@ -1123,7 +1123,7 @@ curl https://api.anthropic.com/v1/skills/$SKILL_ID/versions \
-H 'Content-Type: multipart/form-data' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
- -F files='["Example data"]'
+ -F 'files[]=@/path/to/file'
```
##### Response (200)
diff --git a/content/en/api/beta/skills/create.md b/content/en/api/beta/skills/create.md
index fd2febe59c..495fd3fccb 100644
--- a/content/en/api/beta/skills/create.md
+++ b/content/en/api/beta/skills/create.md
@@ -204,7 +204,7 @@ curl https://api.anthropic.com/v1/skills \
-H 'Content-Type: multipart/form-data' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
- -F files='["Example data"]'
+ -F 'files[]=@/path/to/file'
```
### Response (200)
diff --git a/content/en/api/beta/skills/versions.md b/content/en/api/beta/skills/versions.md
index 3c4eb00b8e..9928a8a8d7 100644
--- a/content/en/api/beta/skills/versions.md
+++ b/content/en/api/beta/skills/versions.md
@@ -180,7 +180,7 @@ curl https://api.anthropic.com/v1/skills/$SKILL_ID/versions \
-H 'Content-Type: multipart/form-data' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
- -F files='["Example data"]'
+ -F 'files[]=@/path/to/file'
```
#### Response (200)
diff --git a/content/en/api/beta/skills/versions/create.md b/content/en/api/beta/skills/versions/create.md
index 9cce178db8..908257c77b 100644
--- a/content/en/api/beta/skills/versions/create.md
+++ b/content/en/api/beta/skills/versions/create.md
@@ -178,7 +178,7 @@ curl https://api.anthropic.com/v1/skills/$SKILL_ID/versions \
-H 'Content-Type: multipart/form-data' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
- -F files='["Example data"]'
+ -F 'files[]=@/path/to/file'
```
### Response (200)
diff --git a/content/en/api/cli/beta/messages.md b/content/en/api/cli/beta/messages.md
index 7878a7a48b..c12aa9d17c 100644
--- a/content/en/api/cli/beta/messages.md
+++ b/content/en/api/cli/beta/messages.md
@@ -10338,7 +10338,7 @@ ant beta:messages count-tokens \
- `beta_tool_change_mcp_tool_reference: object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -10393,7 +10393,7 @@ ant beta:messages count-tokens \
- `beta_tool_change_mcp_tool_reference: object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `beta_tool_change_mcp_toolset_reference: object`
@@ -17739,7 +17739,7 @@ ant beta:messages count-tokens \
- `beta_tool_change_mcp_tool_reference: object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -17794,7 +17794,7 @@ ant beta:messages count-tokens \
- `beta_tool_change_mcp_tool_reference: object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `beta_tool_change_mcp_toolset_reference: object`
@@ -25401,7 +25401,7 @@ ant beta:messages count-tokens \
- `beta_tool_change_mcp_tool_reference: object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -25468,7 +25468,7 @@ ant beta:messages count-tokens \
- `beta_tool_change_mcp_tool_reference: object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -27335,7 +27335,7 @@ ant beta:messages count-tokens \
- `beta_tool_change_mcp_tool_reference: object`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
diff --git a/content/en/api/compliance.md b/content/en/api/compliance.md
index a6c18ee4e9..70b0723a07 100644
--- a/content/en/api/compliance.md
+++ b/content/en/api/compliance.md
@@ -19,7 +19,7 @@ compliance activities that can be filtered by various criteria.
#### Query parameters
-- `activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 501 more`
+- `activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 503 more`
Filter activities by type. See the response `data` schema for the additional fields each type returns. Cannot be combined with `exclude_activity_types[]`.
@@ -823,6 +823,14 @@ compliance activities that can be filtered by various criteria.
Webhook signature validation failed.
+ - `"github_app_installation_linked"`
+
+ An installation of the Claude GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Claude Code features act on that GitHub account's repositories.
+
+ - `"github_app_installation_unlinked"`
+
+ An installation of the Claude GitHub App was unlinked from the organization, so the organization's Claude Code features can no longer act on that GitHub account's repositories through it.
+
- `"github_token_import"`
A user attempted to import a personal GitHub access token for use with Claude Code. The `result` field indicates the outcome of the import (imported, rejected, or failed).
@@ -2094,7 +2102,7 @@ compliance activities that can be filtered by various criteria.
format: date-time
-- `exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 501 more`
+- `exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 503 more`
Exclude activities of these types. Cannot be combined with `activity_types[]`.
@@ -2898,6 +2906,14 @@ compliance activities that can be filtered by various criteria.
Webhook signature validation failed.
+ - `"github_app_installation_linked"`
+
+ An installation of the Claude GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Claude Code features act on that GitHub account's repositories.
+
+ - `"github_app_installation_unlinked"`
+
+ An installation of the Claude GitHub App was unlinked from the organization, so the organization's Claude Code features can no longer act on that GitHub account's repositories through it.
+
- `"github_token_import"`
A user attempted to import a personal GitHub access token for use with Claude Code. The `result` field indicates the outcome of the import (imported, rejected, or failed).
@@ -4161,7 +4177,7 @@ compliance activities that can be filtered by various criteria.
#### Returns
-- `data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 501 more`
+- `data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 503 more`
List of activity records. Each element's `type` field identifies which activity it is and which additional fields are present.
@@ -45057,6 +45073,494 @@ compliance activities that can be filtered by various criteria.
Name of the GitHub repository the integration is connected to, when known.
+ - `GitHubAppInstallationLinked object`
+
+ An installation of the Claude GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Claude Code features act on that GitHub account's repositories.
+
+ - `type: optional "github_app_installation_linked"`
+
+ default: github_app_installation_linked
+
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+
+ - `APIActor object`
+
+ - `type: optional "api_actor"`
+
+ default: api_actor
+
+ - `api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `UserActor object`
+
+ - `type: optional "user_actor"`
+
+ default: user_actor
+
+ - `email_address: string`
+
+ format: email
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `user_id: string`
+
+ - `UnauthenticatedUserActor object`
+
+ - `type: optional "unauthenticated_user_actor"`
+
+ default: unauthenticated_user_actor
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `unauthenticated_email_address: optional string or null`
+
+ format: email
+
+ - `AnthropicActor object`
+
+ - `type: optional "anthropic_actor"`
+
+ default: anthropic_actor
+
+ - `email_address: optional string or null`
+
+ format: email
+
+ - `SystemActor object`
+
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
+
+ - `type: optional "system_actor"`
+
+ default: system_actor
+
+ - `service: optional string or null`
+
+ Name of the automated process that performed the action, when known.
+
+ - `AdminAPIKeyActor object`
+
+ - `type: optional "admin_api_key_actor"`
+
+ default: admin_api_key_actor
+
+ - `admin_api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `ServiceAccountActor object`
+
+ - `type: optional "service_account_actor"`
+
+ default: service_account_actor
+
+ - `ip_address: string`
+
+ - `service_account_id: string`
+
+ - `user_agent: string`
+
+ - `ScimDirectorySyncActor object`
+
+ - `type: optional "scim_directory_sync_actor"`
+
+ default: scim_directory_sync_actor
+
+ - `directory_id: string`
+
+ - `workos_event_id: string`
+
+ - `idp_connection_type: optional string or null`
+
+ - `FederatedIdentityActor object`
+
+ A federated external workload authenticated via a verified OIDC token.
+
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
+
+ - `type: optional "federated_identity_actor"`
+
+ default: federated_identity_actor
+
+ - `issuer: string`
+
+ - `subject: string`
+
+ - `audience: optional array of string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `FederatedActor object`
+
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
+
+ - `type: optional "federated_actor"`
+
+ default: federated_actor
+
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+
+ - `FederatedActorAwsProvider object`
+
+ Asserting party: the AWS account the organization is bound to.
+
+ - `type: optional "aws"`
+
+ default: aws
+
+ - `account_id: string`
+
+ - `signed_principal: string`
+
+ The AWS-signed ARN of the IAM principal that requested the token.
+
+ - `FederatedActorAzureProvider object`
+
+ Asserting party: the Azure subscription the organization is bound to.
+
+ - `type: optional "azure"`
+
+ default: azure
+
+ - `subscription_id: string`
+
+ - `FederatedActorGcpProvider object`
+
+ Asserting party: the GCP project the organization is bound to.
+
+ - `type: optional "gcp"`
+
+ default: gcp
+
+ - `project_number: string`
+
+ - `FederatedActorOidcProvider object`
+
+ Asserting party: a customer-registered OIDC federation issuer.
+
+ - `type: optional "oidc"`
+
+ default: oidc
+
+ - `issuer: optional string or null`
+
+ The federation issuer's URL. Null when the presented credential failed verification.
+
+ - `ip_address: optional string or null`
+
+ - `subject: optional string or null`
+
+ The provider's verified identifier for the caller; its form depends on the provider.
+
+ - `user_agent: optional string or null`
+
+ - `AttestedDeviceActor object`
+
+ An attested mobile device authenticated via Apple App Attest.
+
+ - `type: optional "attested_device_actor"`
+
+ default: attested_device_actor
+
+ - `external_client_id: string`
+
+ - `kid_hash: string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `github_installation_id: number`
+
+ Numeric GitHub ID of the installation that was linked
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
+
+ - `created_at: optional string`
+
+ When this activity occurred.
+
+ format: date-time
+
+ - `github_account_login: optional string or null`
+
+ Login of the GitHub organization or user account the App is installed on
+
+ - `github_account_type: optional string or null`
+
+ Whether that GitHub account is an organization or a user account, as reported by GitHub ("Organization" or "User")
+
+ - `organization_id: optional string or null`
+
+ Organization ID this activity is associated with
+
+ - `organization_uuid: optional string or null`
+
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+
+ - `GitHubAppInstallationUnlinked object`
+
+ An installation of the Claude GitHub App was unlinked from the organization, so the organization's Claude Code features can no longer act on that GitHub account's repositories through it.
+
+ - `type: optional "github_app_installation_unlinked"`
+
+ default: github_app_installation_unlinked
+
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+
+ - `APIActor object`
+
+ - `type: optional "api_actor"`
+
+ default: api_actor
+
+ - `api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `UserActor object`
+
+ - `type: optional "user_actor"`
+
+ default: user_actor
+
+ - `email_address: string`
+
+ format: email
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `user_id: string`
+
+ - `UnauthenticatedUserActor object`
+
+ - `type: optional "unauthenticated_user_actor"`
+
+ default: unauthenticated_user_actor
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `unauthenticated_email_address: optional string or null`
+
+ format: email
+
+ - `AnthropicActor object`
+
+ - `type: optional "anthropic_actor"`
+
+ default: anthropic_actor
+
+ - `email_address: optional string or null`
+
+ format: email
+
+ - `SystemActor object`
+
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
+
+ - `type: optional "system_actor"`
+
+ default: system_actor
+
+ - `service: optional string or null`
+
+ Name of the automated process that performed the action, when known.
+
+ - `AdminAPIKeyActor object`
+
+ - `type: optional "admin_api_key_actor"`
+
+ default: admin_api_key_actor
+
+ - `admin_api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `ServiceAccountActor object`
+
+ - `type: optional "service_account_actor"`
+
+ default: service_account_actor
+
+ - `ip_address: string`
+
+ - `service_account_id: string`
+
+ - `user_agent: string`
+
+ - `ScimDirectorySyncActor object`
+
+ - `type: optional "scim_directory_sync_actor"`
+
+ default: scim_directory_sync_actor
+
+ - `directory_id: string`
+
+ - `workos_event_id: string`
+
+ - `idp_connection_type: optional string or null`
+
+ - `FederatedIdentityActor object`
+
+ A federated external workload authenticated via a verified OIDC token.
+
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
+
+ - `type: optional "federated_identity_actor"`
+
+ default: federated_identity_actor
+
+ - `issuer: string`
+
+ - `subject: string`
+
+ - `audience: optional array of string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `FederatedActor object`
+
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
+
+ - `type: optional "federated_actor"`
+
+ default: federated_actor
+
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+
+ - `FederatedActorAwsProvider object`
+
+ Asserting party: the AWS account the organization is bound to.
+
+ - `type: optional "aws"`
+
+ default: aws
+
+ - `account_id: string`
+
+ - `signed_principal: string`
+
+ The AWS-signed ARN of the IAM principal that requested the token.
+
+ - `FederatedActorAzureProvider object`
+
+ Asserting party: the Azure subscription the organization is bound to.
+
+ - `type: optional "azure"`
+
+ default: azure
+
+ - `subscription_id: string`
+
+ - `FederatedActorGcpProvider object`
+
+ Asserting party: the GCP project the organization is bound to.
+
+ - `type: optional "gcp"`
+
+ default: gcp
+
+ - `project_number: string`
+
+ - `FederatedActorOidcProvider object`
+
+ Asserting party: a customer-registered OIDC federation issuer.
+
+ - `type: optional "oidc"`
+
+ default: oidc
+
+ - `issuer: optional string or null`
+
+ The federation issuer's URL. Null when the presented credential failed verification.
+
+ - `ip_address: optional string or null`
+
+ - `subject: optional string or null`
+
+ The provider's verified identifier for the caller; its form depends on the provider.
+
+ - `user_agent: optional string or null`
+
+ - `AttestedDeviceActor object`
+
+ An attested mobile device authenticated via Apple App Attest.
+
+ - `type: optional "attested_device_actor"`
+
+ default: attested_device_actor
+
+ - `external_client_id: string`
+
+ - `kid_hash: string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `github_installation_id: number`
+
+ Numeric GitHub ID of the installation that was unlinked
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
+
+ - `created_at: optional string`
+
+ When this activity occurred.
+
+ format: date-time
+
+ - `github_account_login: optional string or null`
+
+ Login of the GitHub organization or user account the App is installed on
+
+ - `github_account_type: optional string or null`
+
+ Whether that GitHub account is an organization or a user account, as reported by GitHub ("Organization" or "User")
+
+ - `organization_id: optional string or null`
+
+ Organization ID this activity is associated with
+
+ - `organization_uuid: optional string or null`
+
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+
- `GitHubTokenImport object`
A user attempted to import a personal GitHub access token for use with Claude Code. The `result` field indicates the outcome of the import (imported, rejected, or failed).
@@ -80321,7 +80825,7 @@ compliance activities that can be filtered by various criteria.
- `ClaudeCodeWebEnabled object`
- The Claude Code on the web setting was changed for the organization.
+ The Claude Code cloud sessions setting was changed for the organization.
- `type: optional "claude_code_web_enabled"`
@@ -125050,6 +125554,10 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+ - `tunnel_token_id: optional string or null`
+
+ Id of the tunnel token issued with the tunnel and returned once in the create response; set only when creating the tunnel also issued its token, and absent for a tunnel whose token is revealed separately
+
- `TunnelTokenMinted object`
An OAuth bearer token for the tunnel management API was minted.
diff --git a/content/en/api/compliance/activities.md b/content/en/api/compliance/activities.md
index ff912bb86c..4f32147aa9 100644
--- a/content/en/api/compliance/activities.md
+++ b/content/en/api/compliance/activities.md
@@ -17,7 +17,7 @@ compliance activities that can be filtered by various criteria.
### Query parameters
-- `activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 501 more`
+- `activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 503 more`
Filter activities by type. See the response `data` schema for the additional fields each type returns. Cannot be combined with `exclude_activity_types[]`.
@@ -821,6 +821,14 @@ compliance activities that can be filtered by various criteria.
Webhook signature validation failed.
+ - `"github_app_installation_linked"`
+
+ An installation of the Claude GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Claude Code features act on that GitHub account's repositories.
+
+ - `"github_app_installation_unlinked"`
+
+ An installation of the Claude GitHub App was unlinked from the organization, so the organization's Claude Code features can no longer act on that GitHub account's repositories through it.
+
- `"github_token_import"`
A user attempted to import a personal GitHub access token for use with Claude Code. The `result` field indicates the outcome of the import (imported, rejected, or failed).
@@ -2092,7 +2100,7 @@ compliance activities that can be filtered by various criteria.
format: date-time
-- `exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 501 more`
+- `exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 503 more`
Exclude activities of these types. Cannot be combined with `activity_types[]`.
@@ -2896,6 +2904,14 @@ compliance activities that can be filtered by various criteria.
Webhook signature validation failed.
+ - `"github_app_installation_linked"`
+
+ An installation of the Claude GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Claude Code features act on that GitHub account's repositories.
+
+ - `"github_app_installation_unlinked"`
+
+ An installation of the Claude GitHub App was unlinked from the organization, so the organization's Claude Code features can no longer act on that GitHub account's repositories through it.
+
- `"github_token_import"`
A user attempted to import a personal GitHub access token for use with Claude Code. The `result` field indicates the outcome of the import (imported, rejected, or failed).
@@ -4159,7 +4175,7 @@ compliance activities that can be filtered by various criteria.
### Returns
-- `data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 501 more`
+- `data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 503 more`
List of activity records. Each element's `type` field identifies which activity it is and which additional fields are present.
@@ -45055,13 +45071,13 @@ compliance activities that can be filtered by various criteria.
Name of the GitHub repository the integration is connected to, when known.
- - `GitHubTokenImport object`
+ - `GitHubAppInstallationLinked object`
- A user attempted to import a personal GitHub access token for use with Claude Code. The `result` field indicates the outcome of the import (imported, rejected, or failed).
+ An installation of the Claude GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Claude Code features act on that GitHub account's repositories.
- - `type: optional "github_token_import"`
+ - `type: optional "github_app_installation_linked"`
- default: github_token_import
+ default: github_app_installation_linked
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -45269,29 +45285,253 @@ compliance activities that can be filtered by various criteria.
- `user_agent: optional string or null`
- - `result: "failed_internal" or "imported" or "rejected_feature_disabled" or 5 more`
+ - `github_installation_id: number`
- The outcome of the import.
+ Numeric GitHub ID of the installation that was linked
- - `"failed_internal"`
+ - `id: optional string`
- - `"imported"`
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- - `"rejected_feature_disabled"`
+ - `created_at: optional string`
- - `"rejected_invalid_credential"`
+ When this activity occurred.
- - `"rejected_missing_repo_scope"`
+ format: date-time
- - `"rejected_tenant_not_ready"`
+ - `github_account_login: optional string or null`
- - `"rejected_zdr_policy"`
+ Login of the GitHub organization or user account the App is installed on
- - `"unspecified"`
+ - `github_account_type: optional string or null`
- - `source: string`
+ Whether that GitHub account is an organization or a user account, as reported by GitHub ("Organization" or "User")
- How the token was imported.
+ - `organization_id: optional string or null`
+
+ Organization ID this activity is associated with
+
+ - `organization_uuid: optional string or null`
+
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+
+ - `GitHubAppInstallationUnlinked object`
+
+ An installation of the Claude GitHub App was unlinked from the organization, so the organization's Claude Code features can no longer act on that GitHub account's repositories through it.
+
+ - `type: optional "github_app_installation_unlinked"`
+
+ default: github_app_installation_unlinked
+
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+
+ - `APIActor object`
+
+ - `type: optional "api_actor"`
+
+ default: api_actor
+
+ - `api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `UserActor object`
+
+ - `type: optional "user_actor"`
+
+ default: user_actor
+
+ - `email_address: string`
+
+ format: email
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `user_id: string`
+
+ - `UnauthenticatedUserActor object`
+
+ - `type: optional "unauthenticated_user_actor"`
+
+ default: unauthenticated_user_actor
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `unauthenticated_email_address: optional string or null`
+
+ format: email
+
+ - `AnthropicActor object`
+
+ - `type: optional "anthropic_actor"`
+
+ default: anthropic_actor
+
+ - `email_address: optional string or null`
+
+ format: email
+
+ - `SystemActor object`
+
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
+
+ - `type: optional "system_actor"`
+
+ default: system_actor
+
+ - `service: optional string or null`
+
+ Name of the automated process that performed the action, when known.
+
+ - `AdminAPIKeyActor object`
+
+ - `type: optional "admin_api_key_actor"`
+
+ default: admin_api_key_actor
+
+ - `admin_api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `ServiceAccountActor object`
+
+ - `type: optional "service_account_actor"`
+
+ default: service_account_actor
+
+ - `ip_address: string`
+
+ - `service_account_id: string`
+
+ - `user_agent: string`
+
+ - `ScimDirectorySyncActor object`
+
+ - `type: optional "scim_directory_sync_actor"`
+
+ default: scim_directory_sync_actor
+
+ - `directory_id: string`
+
+ - `workos_event_id: string`
+
+ - `idp_connection_type: optional string or null`
+
+ - `FederatedIdentityActor object`
+
+ A federated external workload authenticated via a verified OIDC token.
+
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
+
+ - `type: optional "federated_identity_actor"`
+
+ default: federated_identity_actor
+
+ - `issuer: string`
+
+ - `subject: string`
+
+ - `audience: optional array of string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `FederatedActor object`
+
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
+
+ - `type: optional "federated_actor"`
+
+ default: federated_actor
+
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+
+ - `FederatedActorAwsProvider object`
+
+ Asserting party: the AWS account the organization is bound to.
+
+ - `type: optional "aws"`
+
+ default: aws
+
+ - `account_id: string`
+
+ - `signed_principal: string`
+
+ The AWS-signed ARN of the IAM principal that requested the token.
+
+ - `FederatedActorAzureProvider object`
+
+ Asserting party: the Azure subscription the organization is bound to.
+
+ - `type: optional "azure"`
+
+ default: azure
+
+ - `subscription_id: string`
+
+ - `FederatedActorGcpProvider object`
+
+ Asserting party: the GCP project the organization is bound to.
+
+ - `type: optional "gcp"`
+
+ default: gcp
+
+ - `project_number: string`
+
+ - `FederatedActorOidcProvider object`
+
+ Asserting party: a customer-registered OIDC federation issuer.
+
+ - `type: optional "oidc"`
+
+ default: oidc
+
+ - `issuer: optional string or null`
+
+ The federation issuer's URL. Null when the presented credential failed verification.
+
+ - `ip_address: optional string or null`
+
+ - `subject: optional string or null`
+
+ The provider's verified identifier for the caller; its form depends on the provider.
+
+ - `user_agent: optional string or null`
+
+ - `AttestedDeviceActor object`
+
+ An attested mobile device authenticated via Apple App Attest.
+
+ - `type: optional "attested_device_actor"`
+
+ default: attested_device_actor
+
+ - `external_client_id: string`
+
+ - `kid_hash: string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `github_installation_id: number`
+
+ Numeric GitHub ID of the installation that was unlinked
- `id: optional string`
@@ -45303,13 +45543,13 @@ compliance activities that can be filtered by various criteria.
format: date-time
- - `github_username: optional string or null`
+ - `github_account_login: optional string or null`
- The GitHub username the imported token authenticates as, when known.
+ Login of the GitHub organization or user account the App is installed on
- - `granted_scopes: optional string or null`
+ - `github_account_type: optional string or null`
- The scopes granted to the imported token, when available.
+ Whether that GitHub account is an organization or a user account, as reported by GitHub ("Organization" or "User")
- `organization_id: optional string or null`
@@ -45319,17 +45559,281 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `token_fingerprint_sha256: optional string or null`
-
- Org-scoped SHA-256 of the submitted token: `sha256(org_uuid || 0x00 || token)`, lowercase-hex-encoded, where `org_uuid` is the organization's UUID as a dashed lowercase string, `0x00` is a single zero byte, and `token` is the submitted value's raw bytes. Per-org correlation only — the same token in two orgs produces distinct fingerprints. Set only when the submitted value carries a known GitHub PAT prefix (a high-entropy token format); unset for all other submissions, including rejected non-PAT input.
-
- - `ClaudeGdriveIntegrationCreated object`
+ - `GitHubTokenImport object`
- A Google Drive integration was enabled for the organization.
+ A user attempted to import a personal GitHub access token for use with Claude Code. The `result` field indicates the outcome of the import (imported, rejected, or failed).
- - `type: optional "claude_gdrive_integration_created"`
+ - `type: optional "github_token_import"`
- default: claude_gdrive_integration_created
+ default: github_token_import
+
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+
+ - `APIActor object`
+
+ - `type: optional "api_actor"`
+
+ default: api_actor
+
+ - `api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `UserActor object`
+
+ - `type: optional "user_actor"`
+
+ default: user_actor
+
+ - `email_address: string`
+
+ format: email
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `user_id: string`
+
+ - `UnauthenticatedUserActor object`
+
+ - `type: optional "unauthenticated_user_actor"`
+
+ default: unauthenticated_user_actor
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `unauthenticated_email_address: optional string or null`
+
+ format: email
+
+ - `AnthropicActor object`
+
+ - `type: optional "anthropic_actor"`
+
+ default: anthropic_actor
+
+ - `email_address: optional string or null`
+
+ format: email
+
+ - `SystemActor object`
+
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
+
+ - `type: optional "system_actor"`
+
+ default: system_actor
+
+ - `service: optional string or null`
+
+ Name of the automated process that performed the action, when known.
+
+ - `AdminAPIKeyActor object`
+
+ - `type: optional "admin_api_key_actor"`
+
+ default: admin_api_key_actor
+
+ - `admin_api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `ServiceAccountActor object`
+
+ - `type: optional "service_account_actor"`
+
+ default: service_account_actor
+
+ - `ip_address: string`
+
+ - `service_account_id: string`
+
+ - `user_agent: string`
+
+ - `ScimDirectorySyncActor object`
+
+ - `type: optional "scim_directory_sync_actor"`
+
+ default: scim_directory_sync_actor
+
+ - `directory_id: string`
+
+ - `workos_event_id: string`
+
+ - `idp_connection_type: optional string or null`
+
+ - `FederatedIdentityActor object`
+
+ A federated external workload authenticated via a verified OIDC token.
+
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
+
+ - `type: optional "federated_identity_actor"`
+
+ default: federated_identity_actor
+
+ - `issuer: string`
+
+ - `subject: string`
+
+ - `audience: optional array of string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `FederatedActor object`
+
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
+
+ - `type: optional "federated_actor"`
+
+ default: federated_actor
+
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+
+ - `FederatedActorAwsProvider object`
+
+ Asserting party: the AWS account the organization is bound to.
+
+ - `type: optional "aws"`
+
+ default: aws
+
+ - `account_id: string`
+
+ - `signed_principal: string`
+
+ The AWS-signed ARN of the IAM principal that requested the token.
+
+ - `FederatedActorAzureProvider object`
+
+ Asserting party: the Azure subscription the organization is bound to.
+
+ - `type: optional "azure"`
+
+ default: azure
+
+ - `subscription_id: string`
+
+ - `FederatedActorGcpProvider object`
+
+ Asserting party: the GCP project the organization is bound to.
+
+ - `type: optional "gcp"`
+
+ default: gcp
+
+ - `project_number: string`
+
+ - `FederatedActorOidcProvider object`
+
+ Asserting party: a customer-registered OIDC federation issuer.
+
+ - `type: optional "oidc"`
+
+ default: oidc
+
+ - `issuer: optional string or null`
+
+ The federation issuer's URL. Null when the presented credential failed verification.
+
+ - `ip_address: optional string or null`
+
+ - `subject: optional string or null`
+
+ The provider's verified identifier for the caller; its form depends on the provider.
+
+ - `user_agent: optional string or null`
+
+ - `AttestedDeviceActor object`
+
+ An attested mobile device authenticated via Apple App Attest.
+
+ - `type: optional "attested_device_actor"`
+
+ default: attested_device_actor
+
+ - `external_client_id: string`
+
+ - `kid_hash: string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `result: "failed_internal" or "imported" or "rejected_feature_disabled" or 5 more`
+
+ The outcome of the import.
+
+ - `"failed_internal"`
+
+ - `"imported"`
+
+ - `"rejected_feature_disabled"`
+
+ - `"rejected_invalid_credential"`
+
+ - `"rejected_missing_repo_scope"`
+
+ - `"rejected_tenant_not_ready"`
+
+ - `"rejected_zdr_policy"`
+
+ - `"unspecified"`
+
+ - `source: string`
+
+ How the token was imported.
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
+
+ - `created_at: optional string`
+
+ When this activity occurred.
+
+ format: date-time
+
+ - `github_username: optional string or null`
+
+ The GitHub username the imported token authenticates as, when known.
+
+ - `granted_scopes: optional string or null`
+
+ The scopes granted to the imported token, when available.
+
+ - `organization_id: optional string or null`
+
+ Organization ID this activity is associated with
+
+ - `organization_uuid: optional string or null`
+
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+
+ - `token_fingerprint_sha256: optional string or null`
+
+ Org-scoped SHA-256 of the submitted token: `sha256(org_uuid || 0x00 || token)`, lowercase-hex-encoded, where `org_uuid` is the organization's UUID as a dashed lowercase string, `0x00` is a single zero byte, and `token` is the submitted value's raw bytes. Per-org correlation only — the same token in two orgs produces distinct fingerprints. Set only when the submitted value carries a known GitHub PAT prefix (a high-entropy token format); unset for all other submissions, including rejected non-PAT input.
+
+ - `ClaudeGdriveIntegrationCreated object`
+
+ A Google Drive integration was enabled for the organization.
+
+ - `type: optional "claude_gdrive_integration_created"`
+
+ default: claude_gdrive_integration_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -80319,7 +80823,7 @@ compliance activities that can be filtered by various criteria.
- `ClaudeCodeWebEnabled object`
- The Claude Code on the web setting was changed for the organization.
+ The Claude Code cloud sessions setting was changed for the organization.
- `type: optional "claude_code_web_enabled"`
@@ -125048,6 +125552,10 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+ - `tunnel_token_id: optional string or null`
+
+ Id of the tunnel token issued with the tunnel and returned once in the create response; set only when creating the tunnel also issued its token, and absent for a tunnel whose token is revealed separately
+
- `TunnelTokenMinted object`
An OAuth bearer token for the tunnel management API was minted.
@@ -125498,20 +126006,977 @@ compliance activities that can be filtered by various criteria.
- `user_agent: optional string or null`
- - `tunnel_id: string`
-
- - `tunnel_token_id: string`
-
+ - `tunnel_id: string`
+
+ - `tunnel_token_id: string`
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
+
+ - `created_at: optional string`
+
+ When this activity occurred.
+
+ format: date-time
+
+ - `organization_id: optional string or null`
+
+ Organization ID this activity is associated with
+
+ - `organization_uuid: optional string or null`
+
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+
+ - `TunnelTokenRevoked object`
+
+ An OAuth bearer token for the tunnel management API was revoked.
+
+ - `type: optional "tunnel_token_revoked"`
+
+ default: tunnel_token_revoked
+
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+
+ - `APIActor object`
+
+ - `type: optional "api_actor"`
+
+ default: api_actor
+
+ - `api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `UserActor object`
+
+ - `type: optional "user_actor"`
+
+ default: user_actor
+
+ - `email_address: string`
+
+ format: email
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `user_id: string`
+
+ - `UnauthenticatedUserActor object`
+
+ - `type: optional "unauthenticated_user_actor"`
+
+ default: unauthenticated_user_actor
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `unauthenticated_email_address: optional string or null`
+
+ format: email
+
+ - `AnthropicActor object`
+
+ - `type: optional "anthropic_actor"`
+
+ default: anthropic_actor
+
+ - `email_address: optional string or null`
+
+ format: email
+
+ - `SystemActor object`
+
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
+
+ - `type: optional "system_actor"`
+
+ default: system_actor
+
+ - `service: optional string or null`
+
+ Name of the automated process that performed the action, when known.
+
+ - `AdminAPIKeyActor object`
+
+ - `type: optional "admin_api_key_actor"`
+
+ default: admin_api_key_actor
+
+ - `admin_api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `ServiceAccountActor object`
+
+ - `type: optional "service_account_actor"`
+
+ default: service_account_actor
+
+ - `ip_address: string`
+
+ - `service_account_id: string`
+
+ - `user_agent: string`
+
+ - `ScimDirectorySyncActor object`
+
+ - `type: optional "scim_directory_sync_actor"`
+
+ default: scim_directory_sync_actor
+
+ - `directory_id: string`
+
+ - `workos_event_id: string`
+
+ - `idp_connection_type: optional string or null`
+
+ - `FederatedIdentityActor object`
+
+ A federated external workload authenticated via a verified OIDC token.
+
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
+
+ - `type: optional "federated_identity_actor"`
+
+ default: federated_identity_actor
+
+ - `issuer: string`
+
+ - `subject: string`
+
+ - `audience: optional array of string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `FederatedActor object`
+
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
+
+ - `type: optional "federated_actor"`
+
+ default: federated_actor
+
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+
+ - `FederatedActorAwsProvider object`
+
+ Asserting party: the AWS account the organization is bound to.
+
+ - `type: optional "aws"`
+
+ default: aws
+
+ - `account_id: string`
+
+ - `signed_principal: string`
+
+ The AWS-signed ARN of the IAM principal that requested the token.
+
+ - `FederatedActorAzureProvider object`
+
+ Asserting party: the Azure subscription the organization is bound to.
+
+ - `type: optional "azure"`
+
+ default: azure
+
+ - `subscription_id: string`
+
+ - `FederatedActorGcpProvider object`
+
+ Asserting party: the GCP project the organization is bound to.
+
+ - `type: optional "gcp"`
+
+ default: gcp
+
+ - `project_number: string`
+
+ - `FederatedActorOidcProvider object`
+
+ Asserting party: a customer-registered OIDC federation issuer.
+
+ - `type: optional "oidc"`
+
+ default: oidc
+
+ - `issuer: optional string or null`
+
+ The federation issuer's URL. Null when the presented credential failed verification.
+
+ - `ip_address: optional string or null`
+
+ - `subject: optional string or null`
+
+ The provider's verified identifier for the caller; its form depends on the provider.
+
+ - `user_agent: optional string or null`
+
+ - `AttestedDeviceActor object`
+
+ An attested mobile device authenticated via Apple App Attest.
+
+ - `type: optional "attested_device_actor"`
+
+ default: attested_device_actor
+
+ - `external_client_id: string`
+
+ - `kid_hash: string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `token_id: string`
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
+
+ - `created_at: optional string`
+
+ When this activity occurred.
+
+ format: date-time
+
+ - `organization_id: optional string or null`
+
+ Organization ID this activity is associated with
+
+ - `organization_uuid: optional string or null`
+
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+
+ - `token_name: optional string or null`
+
+ Name the administrator gave the token when it was created, if any
+
+ - `TunnelTokenRotated object`
+
+ The Cloudflare connector secret for a tunnel was rotated.
+
+ `tunnel_token_id` is the id of the *newly-issued* token. The previous
+ token is invalidated by the rotation and its id is not recorded here.
+
+ - `type: optional "tunnel_token_rotated"`
+
+ default: tunnel_token_rotated
+
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+
+ - `APIActor object`
+
+ - `type: optional "api_actor"`
+
+ default: api_actor
+
+ - `api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `UserActor object`
+
+ - `type: optional "user_actor"`
+
+ default: user_actor
+
+ - `email_address: string`
+
+ format: email
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `user_id: string`
+
+ - `UnauthenticatedUserActor object`
+
+ - `type: optional "unauthenticated_user_actor"`
+
+ default: unauthenticated_user_actor
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `unauthenticated_email_address: optional string or null`
+
+ format: email
+
+ - `AnthropicActor object`
+
+ - `type: optional "anthropic_actor"`
+
+ default: anthropic_actor
+
+ - `email_address: optional string or null`
+
+ format: email
+
+ - `SystemActor object`
+
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
+
+ - `type: optional "system_actor"`
+
+ default: system_actor
+
+ - `service: optional string or null`
+
+ Name of the automated process that performed the action, when known.
+
+ - `AdminAPIKeyActor object`
+
+ - `type: optional "admin_api_key_actor"`
+
+ default: admin_api_key_actor
+
+ - `admin_api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `ServiceAccountActor object`
+
+ - `type: optional "service_account_actor"`
+
+ default: service_account_actor
+
+ - `ip_address: string`
+
+ - `service_account_id: string`
+
+ - `user_agent: string`
+
+ - `ScimDirectorySyncActor object`
+
+ - `type: optional "scim_directory_sync_actor"`
+
+ default: scim_directory_sync_actor
+
+ - `directory_id: string`
+
+ - `workos_event_id: string`
+
+ - `idp_connection_type: optional string or null`
+
+ - `FederatedIdentityActor object`
+
+ A federated external workload authenticated via a verified OIDC token.
+
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
+
+ - `type: optional "federated_identity_actor"`
+
+ default: federated_identity_actor
+
+ - `issuer: string`
+
+ - `subject: string`
+
+ - `audience: optional array of string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `FederatedActor object`
+
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
+
+ - `type: optional "federated_actor"`
+
+ default: federated_actor
+
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+
+ - `FederatedActorAwsProvider object`
+
+ Asserting party: the AWS account the organization is bound to.
+
+ - `type: optional "aws"`
+
+ default: aws
+
+ - `account_id: string`
+
+ - `signed_principal: string`
+
+ The AWS-signed ARN of the IAM principal that requested the token.
+
+ - `FederatedActorAzureProvider object`
+
+ Asserting party: the Azure subscription the organization is bound to.
+
+ - `type: optional "azure"`
+
+ default: azure
+
+ - `subscription_id: string`
+
+ - `FederatedActorGcpProvider object`
+
+ Asserting party: the GCP project the organization is bound to.
+
+ - `type: optional "gcp"`
+
+ default: gcp
+
+ - `project_number: string`
+
+ - `FederatedActorOidcProvider object`
+
+ Asserting party: a customer-registered OIDC federation issuer.
+
+ - `type: optional "oidc"`
+
+ default: oidc
+
+ - `issuer: optional string or null`
+
+ The federation issuer's URL. Null when the presented credential failed verification.
+
+ - `ip_address: optional string or null`
+
+ - `subject: optional string or null`
+
+ The provider's verified identifier for the caller; its form depends on the provider.
+
+ - `user_agent: optional string or null`
+
+ - `AttestedDeviceActor object`
+
+ An attested mobile device authenticated via Apple App Attest.
+
+ - `type: optional "attested_device_actor"`
+
+ default: attested_device_actor
+
+ - `external_client_id: string`
+
+ - `kid_hash: string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `tunnel_id: string`
+
+ - `tunnel_token_id: string`
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
+
+ - `created_at: optional string`
+
+ When this activity occurred.
+
+ format: date-time
+
+ - `organization_id: optional string or null`
+
+ Organization ID this activity is associated with
+
+ - `organization_uuid: optional string or null`
+
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+
+ - `reason: optional string or null`
+
+ - `UserConsentRecorded object`
+
+ User granted a consent for a specific entity (e.g. consumer health consent for an MCP server).
+
+ - `type: optional "user_consent_recorded"`
+
+ default: user_consent_recorded
+
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+
+ - `APIActor object`
+
+ - `type: optional "api_actor"`
+
+ default: api_actor
+
+ - `api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `UserActor object`
+
+ - `type: optional "user_actor"`
+
+ default: user_actor
+
+ - `email_address: string`
+
+ format: email
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `user_id: string`
+
+ - `UnauthenticatedUserActor object`
+
+ - `type: optional "unauthenticated_user_actor"`
+
+ default: unauthenticated_user_actor
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `unauthenticated_email_address: optional string or null`
+
+ format: email
+
+ - `AnthropicActor object`
+
+ - `type: optional "anthropic_actor"`
+
+ default: anthropic_actor
+
+ - `email_address: optional string or null`
+
+ format: email
+
+ - `SystemActor object`
+
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
+
+ - `type: optional "system_actor"`
+
+ default: system_actor
+
+ - `service: optional string or null`
+
+ Name of the automated process that performed the action, when known.
+
+ - `AdminAPIKeyActor object`
+
+ - `type: optional "admin_api_key_actor"`
+
+ default: admin_api_key_actor
+
+ - `admin_api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `ServiceAccountActor object`
+
+ - `type: optional "service_account_actor"`
+
+ default: service_account_actor
+
+ - `ip_address: string`
+
+ - `service_account_id: string`
+
+ - `user_agent: string`
+
+ - `ScimDirectorySyncActor object`
+
+ - `type: optional "scim_directory_sync_actor"`
+
+ default: scim_directory_sync_actor
+
+ - `directory_id: string`
+
+ - `workos_event_id: string`
+
+ - `idp_connection_type: optional string or null`
+
+ - `FederatedIdentityActor object`
+
+ A federated external workload authenticated via a verified OIDC token.
+
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
+
+ - `type: optional "federated_identity_actor"`
+
+ default: federated_identity_actor
+
+ - `issuer: string`
+
+ - `subject: string`
+
+ - `audience: optional array of string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `FederatedActor object`
+
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
+
+ - `type: optional "federated_actor"`
+
+ default: federated_actor
+
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+
+ - `FederatedActorAwsProvider object`
+
+ Asserting party: the AWS account the organization is bound to.
+
+ - `type: optional "aws"`
+
+ default: aws
+
+ - `account_id: string`
+
+ - `signed_principal: string`
+
+ The AWS-signed ARN of the IAM principal that requested the token.
+
+ - `FederatedActorAzureProvider object`
+
+ Asserting party: the Azure subscription the organization is bound to.
+
+ - `type: optional "azure"`
+
+ default: azure
+
+ - `subscription_id: string`
+
+ - `FederatedActorGcpProvider object`
+
+ Asserting party: the GCP project the organization is bound to.
+
+ - `type: optional "gcp"`
+
+ default: gcp
+
+ - `project_number: string`
+
+ - `FederatedActorOidcProvider object`
+
+ Asserting party: a customer-registered OIDC federation issuer.
+
+ - `type: optional "oidc"`
+
+ default: oidc
+
+ - `issuer: optional string or null`
+
+ The federation issuer's URL. Null when the presented credential failed verification.
+
+ - `ip_address: optional string or null`
+
+ - `subject: optional string or null`
+
+ The provider's verified identifier for the caller; its form depends on the provider.
+
+ - `user_agent: optional string or null`
+
+ - `AttestedDeviceActor object`
+
+ An attested mobile device authenticated via Apple App Attest.
+
+ - `type: optional "attested_device_actor"`
+
+ default: attested_device_actor
+
+ - `external_client_id: string`
+
+ - `kid_hash: string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `consent_type: string`
+
+ - `entity_id: string`
+
+ - `entity_type: string`
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
+
+ - `created_at: optional string`
+
+ When this activity occurred.
+
+ format: date-time
+
+ - `organization_id: optional string or null`
+
+ Organization ID this activity is associated with
+
+ - `organization_uuid: optional string or null`
+
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+
+ - `UserConsentRevoked object`
+
+ User revoked a previously granted consent for a specific entity.
+
+ - `type: optional "user_consent_revoked"`
+
+ default: user_consent_revoked
+
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+
+ - `APIActor object`
+
+ - `type: optional "api_actor"`
+
+ default: api_actor
+
+ - `api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `UserActor object`
+
+ - `type: optional "user_actor"`
+
+ default: user_actor
+
+ - `email_address: string`
+
+ format: email
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `user_id: string`
+
+ - `UnauthenticatedUserActor object`
+
+ - `type: optional "unauthenticated_user_actor"`
+
+ default: unauthenticated_user_actor
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `unauthenticated_email_address: optional string or null`
+
+ format: email
+
+ - `AnthropicActor object`
+
+ - `type: optional "anthropic_actor"`
+
+ default: anthropic_actor
+
+ - `email_address: optional string or null`
+
+ format: email
+
+ - `SystemActor object`
+
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
+
+ - `type: optional "system_actor"`
+
+ default: system_actor
+
+ - `service: optional string or null`
+
+ Name of the automated process that performed the action, when known.
+
+ - `AdminAPIKeyActor object`
+
+ - `type: optional "admin_api_key_actor"`
+
+ default: admin_api_key_actor
+
+ - `admin_api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `ServiceAccountActor object`
+
+ - `type: optional "service_account_actor"`
+
+ default: service_account_actor
+
+ - `ip_address: string`
+
+ - `service_account_id: string`
+
+ - `user_agent: string`
+
+ - `ScimDirectorySyncActor object`
+
+ - `type: optional "scim_directory_sync_actor"`
+
+ default: scim_directory_sync_actor
+
+ - `directory_id: string`
+
+ - `workos_event_id: string`
+
+ - `idp_connection_type: optional string or null`
+
+ - `FederatedIdentityActor object`
+
+ A federated external workload authenticated via a verified OIDC token.
+
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
+
+ - `type: optional "federated_identity_actor"`
+
+ default: federated_identity_actor
+
+ - `issuer: string`
+
+ - `subject: string`
+
+ - `audience: optional array of string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `FederatedActor object`
+
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
+
+ - `type: optional "federated_actor"`
+
+ default: federated_actor
+
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+
+ - `FederatedActorAwsProvider object`
+
+ Asserting party: the AWS account the organization is bound to.
+
+ - `type: optional "aws"`
+
+ default: aws
+
+ - `account_id: string`
+
+ - `signed_principal: string`
+
+ The AWS-signed ARN of the IAM principal that requested the token.
+
+ - `FederatedActorAzureProvider object`
+
+ Asserting party: the Azure subscription the organization is bound to.
+
+ - `type: optional "azure"`
+
+ default: azure
+
+ - `subscription_id: string`
+
+ - `FederatedActorGcpProvider object`
+
+ Asserting party: the GCP project the organization is bound to.
+
+ - `type: optional "gcp"`
+
+ default: gcp
+
+ - `project_number: string`
+
+ - `FederatedActorOidcProvider object`
+
+ Asserting party: a customer-registered OIDC federation issuer.
+
+ - `type: optional "oidc"`
+
+ default: oidc
+
+ - `issuer: optional string or null`
+
+ The federation issuer's URL. Null when the presented credential failed verification.
+
+ - `ip_address: optional string or null`
+
+ - `subject: optional string or null`
+
+ The provider's verified identifier for the caller; its form depends on the provider.
+
+ - `user_agent: optional string or null`
+
+ - `AttestedDeviceActor object`
+
+ An attested mobile device authenticated via Apple App Attest.
+
+ - `type: optional "attested_device_actor"`
+
+ default: attested_device_actor
+
+ - `external_client_id: string`
+
+ - `kid_hash: string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `consent_id: optional string or null`
+
+ - `consent_type: optional string or null`
+
- `created_at: optional string`
When this activity occurred.
format: date-time
+ - `entity_id: optional string or null`
+
+ - `entity_type: optional string or null`
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -125520,13 +126985,13 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `TunnelTokenRevoked object`
+ - `ClaudeUserRoleUpdated object`
- An OAuth bearer token for the tunnel management API was revoked.
+ A user's role within the organization was changed, or the user was added to or removed from the organization.
- - `type: optional "tunnel_token_revoked"`
+ - `type: optional "claude_user_role_updated"`
- default: tunnel_token_revoked
+ default: claude_user_role_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -125734,7 +127199,13 @@ compliance activities that can be filtered by various criteria.
- `user_agent: optional string or null`
- - `token_id: string`
+ - `user_email: string`
+
+ Email of the user whose role was changed
+
+ - `user_id: string`
+
+ ID of the user whose role was changed
- `id: optional string`
@@ -125746,6 +127217,10 @@ compliance activities that can be filtered by various criteria.
format: date-time
+ - `current_role: optional string or null`
+
+ If null, then user was removed from the Organization
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -125754,20 +127229,17 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `token_name: optional string or null`
-
- Name the administrator gave the token when it was created, if any
+ - `previous_role: optional string or null`
- - `TunnelTokenRotated object`
+ If null, then user was added to the Organization
- The Cloudflare connector secret for a tunnel was rotated.
+ - `ClaudeUserSettingsUpdated object`
- `tunnel_token_id` is the id of the *newly-issued* token. The previous
- token is invalidated by the rotation and its id is not recorded here.
+ User updated their personal settings.
- - `type: optional "tunnel_token_rotated"`
+ - `type: optional "claude_user_settings_updated"`
- default: tunnel_token_rotated
+ default: claude_user_settings_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -125975,249 +127447,359 @@ compliance activities that can be filtered by various criteria.
- `user_agent: optional string or null`
- - `tunnel_id: string`
+ - `updates: array of FullName or DisplayName or ArtifactsEnabled or 19 more`
- - `tunnel_token_id: string`
+ - `FullName object`
- - `id: optional string`
+ The full name setting was changed.
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `type: optional "full_name"`
- - `created_at: optional string`
+ default: full_name
- When this activity occurred.
+ - `current_value: optional string or null`
- format: date-time
+ Setting value immediately after this change
- - `organization_id: optional string or null`
+ - `previous_value: optional string or null`
- Organization ID this activity is associated with
+ Setting value immediately before this change
- - `organization_uuid: optional string or null`
+ - `DisplayName object`
- Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+ The display name setting was changed.
- - `reason: optional string or null`
+ - `type: optional "display_name"`
- - `UserConsentRecorded object`
+ default: display_name
- User granted a consent for a specific entity (e.g. consumer health consent for an MCP server).
+ - `current_value: optional string or null`
- - `type: optional "user_consent_recorded"`
+ Setting value immediately after this change
- default: user_consent_recorded
+ - `previous_value: optional string or null`
- - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+ Setting value immediately before this change
- - `APIActor object`
+ - `ArtifactsEnabled object`
- - `type: optional "api_actor"`
+ The artifacts setting was changed.
- default: api_actor
+ - `type: optional "artifacts_enabled"`
- - `api_key_id: string`
+ default: artifacts_enabled
- - `ip_address: string`
+ - `current_value: optional boolean or null`
- - `user_agent: string`
+ Setting value immediately after this change
- - `UserActor object`
+ - `previous_value: optional boolean or null`
- - `type: optional "user_actor"`
+ Setting value immediately before this change
- default: user_actor
+ - `LatexEnabled object`
- - `email_address: string`
+ The LaTeX setting was changed.
- format: email
+ - `type: optional "latex_enabled"`
- - `ip_address: string`
+ default: latex_enabled
- - `user_agent: string`
+ - `current_value: optional boolean or null`
- - `user_id: string`
+ Setting value immediately after this change
- - `UnauthenticatedUserActor object`
+ - `previous_value: optional boolean or null`
- - `type: optional "unauthenticated_user_actor"`
+ Setting value immediately before this change
- default: unauthenticated_user_actor
+ - `AnalysisToolEnabled object`
- - `ip_address: string`
+ The analysis tool setting was changed.
- - `user_agent: string`
+ - `type: optional "analysis_tool_enabled"`
- - `unauthenticated_email_address: optional string or null`
+ default: analysis_tool_enabled
- format: email
+ - `current_value: optional boolean or null`
- - `AnthropicActor object`
+ Setting value immediately after this change
- - `type: optional "anthropic_actor"`
+ - `previous_value: optional boolean or null`
- default: anthropic_actor
+ Setting value immediately before this change
- - `email_address: optional string or null`
+ - `ChatSuggestionsEnabled object`
- format: email
+ The chat suggestions setting was changed.
- - `SystemActor object`
+ - `type: optional "chat_suggestions_enabled"`
- Automated background processing performed by Anthropic systems, acting
- without a user or customer credential.
+ default: chat_suggestions_enabled
- - `type: optional "system_actor"`
+ - `current_value: optional boolean or null`
- default: system_actor
+ Setting value immediately after this change
- - `service: optional string or null`
+ - `previous_value: optional boolean or null`
- Name of the automated process that performed the action, when known.
+ Setting value immediately before this change
- - `AdminAPIKeyActor object`
+ - `MultimodalPdfsEnabled object`
- - `type: optional "admin_api_key_actor"`
+ The multimodal PDFs setting was changed.
- default: admin_api_key_actor
+ - `type: optional "multimodal_pdfs_enabled"`
- - `admin_api_key_id: string`
+ default: multimodal_pdfs_enabled
- - `ip_address: string`
+ - `current_value: optional boolean or null`
- - `user_agent: string`
+ Setting value immediately after this change
- - `ServiceAccountActor object`
+ - `previous_value: optional boolean or null`
- - `type: optional "service_account_actor"`
+ Setting value immediately before this change
- default: service_account_actor
+ - `GdriveEnabled object`
- - `ip_address: string`
+ The Google Drive setting was changed.
- - `service_account_id: string`
+ - `type: optional "gdrive_enabled"`
- - `user_agent: string`
+ default: gdrive_enabled
- - `ScimDirectorySyncActor object`
+ - `current_value: optional boolean or null`
- - `type: optional "scim_directory_sync_actor"`
+ Setting value immediately after this change
- default: scim_directory_sync_actor
+ - `previous_value: optional boolean or null`
- - `directory_id: string`
+ Setting value immediately before this change
- - `workos_event_id: string`
+ - `WebSearchEnabled object`
- - `idp_connection_type: optional string or null`
+ The web search setting was changed.
- - `FederatedIdentityActor object`
+ - `type: optional "web_search_enabled"`
- A federated external workload authenticated via a verified OIDC token.
+ default: web_search_enabled
- Carries the verified issuer, subject, and audience claims from the
- presented JWT.
+ - `current_value: optional boolean or null`
- - `type: optional "federated_identity_actor"`
+ Setting value immediately after this change
- default: federated_identity_actor
+ - `previous_value: optional boolean or null`
- - `issuer: string`
+ Setting value immediately before this change
- - `subject: string`
+ - `GeolocationEnabled object`
- - `audience: optional array of string`
+ The geolocation setting was changed.
- - `ip_address: optional string or null`
+ - `type: optional "geolocation_enabled"`
- - `user_agent: optional string or null`
+ default: geolocation_enabled
- - `FederatedActor object`
+ - `current_value: optional boolean or null`
- An external identity asserted by a trusted provider — a cloud-provider
- gateway or a customer-registered federation issuer — acting without an
- Anthropic-provisioned account or service account.
+ Setting value immediately after this change
- - `type: optional "federated_actor"`
+ - `previous_value: optional boolean or null`
- default: federated_actor
+ Setting value immediately before this change
- - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+ - `EnabledSaffron object`
- - `FederatedActorAwsProvider object`
+ The memory setting was changed for the user.
- Asserting party: the AWS account the organization is bound to.
+ - `type: optional "enabled_saffron"`
- - `type: optional "aws"`
+ default: enabled_saffron
- default: aws
+ - `current_value: optional boolean or null`
- - `account_id: string`
+ Setting value immediately after this change
- - `signed_principal: string`
+ - `previous_value: optional boolean or null`
- The AWS-signed ARN of the IAM principal that requested the token.
+ Setting value immediately before this change
- - `FederatedActorAzureProvider object`
+ - `McpToolsEnabled object`
- Asserting party: the Azure subscription the organization is bound to.
+ The MCP tools setting was changed.
- - `type: optional "azure"`
+ - `type: optional "mcp_tools_enabled"`
- default: azure
+ default: mcp_tools_enabled
- - `subscription_id: string`
+ - `current_value: optional map[boolean] or null`
- - `FederatedActorGcpProvider object`
+ Setting value immediately after this change
- Asserting party: the GCP project the organization is bound to.
+ - `previous_value: optional map[boolean] or null`
- - `type: optional "gcp"`
+ Setting value immediately before this change
- default: gcp
+ - `CliOpPermissionsEnabled object`
- - `project_number: string`
+ The CLI operation permissions setting was changed.
- - `FederatedActorOidcProvider object`
+ - `type: optional "cli_op_permissions_enabled"`
- Asserting party: a customer-registered OIDC federation issuer.
+ default: cli_op_permissions_enabled
- - `type: optional "oidc"`
+ - `current_value: optional map[string] or null`
- default: oidc
+ Setting value immediately after this change
- - `issuer: optional string or null`
+ - `previous_value: optional map[string] or null`
- The federation issuer's URL. Null when the presented credential failed verification.
+ Setting value immediately before this change
- - `ip_address: optional string or null`
+ - `GoogleDriveSearchEnabled object`
- - `subject: optional string or null`
+ The Google Drive search setting was changed.
- The provider's verified identifier for the caller; its form depends on the provider.
+ - `type: optional "google_drive_search_enabled"`
- - `user_agent: optional string or null`
+ default: google_drive_search_enabled
- - `AttestedDeviceActor object`
+ - `current_value: optional boolean or null`
- An attested mobile device authenticated via Apple App Attest.
+ Setting value immediately after this change
- - `type: optional "attested_device_actor"`
+ - `previous_value: optional boolean or null`
- default: attested_device_actor
+ Setting value immediately before this change
- - `external_client_id: string`
+ - `GmailIntegrationEnabled object`
- - `kid_hash: string`
+ The Gmail integration setting was changed.
- - `ip_address: optional string or null`
+ - `type: optional "gmail_integration_enabled"`
- - `user_agent: optional string or null`
+ default: gmail_integration_enabled
- - `consent_type: string`
+ - `current_value: optional boolean or null`
- - `entity_id: string`
+ Setting value immediately after this change
- - `entity_type: string`
+ - `previous_value: optional boolean or null`
+
+ Setting value immediately before this change
+
+ - `GoogleCalendarIntegrationEnabled object`
+
+ The Google Calendar integration setting was changed.
+
+ - `type: optional "google_calendar_integration_enabled"`
+
+ default: google_calendar_integration_enabled
+
+ - `current_value: optional boolean or null`
+
+ Setting value immediately after this change
+
+ - `previous_value: optional boolean or null`
+
+ Setting value immediately before this change
+
+ - `ThinkingModeEnabled object`
+
+ The thinking mode setting was changed.
+
+ - `type: optional "thinking_mode_enabled"`
+
+ default: thinking_mode_enabled
+
+ - `current_value: optional "adaptive" or "extended" or "off" or "unspecified" or null`
+
+ Setting value immediately after this change
+
+ - `"adaptive"`
+
+ - `"extended"`
+
+ - `"off"`
+
+ - `"unspecified"`
+
+ - `previous_value: optional "adaptive" or "extended" or "off" or "unspecified" or null`
+
+ Setting value immediately before this change
+
+ - `"adaptive"`
+
+ - `"extended"`
+
+ - `"off"`
+
+ - `"unspecified"`
+
+ - `ResearchModeEnabled object`
+
+ The research mode setting was changed.
+
+ - `type: optional "research_mode_enabled"`
+
+ default: research_mode_enabled
+
+ - `current_value: optional boolean or null`
+
+ Setting value immediately after this change
+
+ - `previous_value: optional boolean or null`
+
+ Setting value immediately before this change
+
+ - `ComputerUseEnabled object`
+
+ The computer use setting was changed.
+
+ - `type: optional "computer_use_enabled"`
+
+ default: computer_use_enabled
+
+ - `current_value: optional boolean or null`
+
+ Setting value immediately after this change
+
+ - `previous_value: optional boolean or null`
+
+ Setting value immediately before this change
+
+ - `ClaudeAPIInArtifactsEnabled object`
+
+ The Claude API in Artifacts setting was changed.
+
+ - `type: optional "claude_api_in_artifacts_enabled"`
+
+ default: claude_api_in_artifacts_enabled
+
+ - `current_value: optional boolean or null`
+
+ Setting value immediately after this change
+
+ - `previous_value: optional boolean or null`
+
+ Setting value immediately before this change
+
+ - `ConversationPreferences object`
+
+ The 'conversation_preferences' for the user were updated. Values omitted.
+
+ - `type: optional "conversation_preferences"`
+
+ default: conversation_preferences
+
+ - `CoworkGlobalInstructions object`
+
+ The Cowork global instructions were updated. Values omitted.
+
+ - `type: optional "cowork_global_instructions"`
+
+ default: cowork_global_instructions
- `id: optional string`
@@ -126237,13 +127819,13 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `UserConsentRevoked object`
+ - `VerificationEvidenceSubmitted object`
- User revoked a previously granted consent for a specific entity.
+ Verification evidence was submitted for an organization's verification.
- - `type: optional "user_consent_revoked"`
+ - `type: optional "verification_evidence_submitted"`
- default: user_consent_revoked
+ default: verification_evidence_submitted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -126451,13 +128033,17 @@ compliance activities that can be filtered by various criteria.
- `user_agent: optional string or null`
- - `id: optional string`
+ - `verification_id: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ Tagged ID of the verification the evidence was submitted for.
- - `consent_id: optional string or null`
+ - `verification_type: string`
- - `consent_type: optional string or null`
+ The type of verification the evidence was submitted for.
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -126465,10 +128051,6 @@ compliance activities that can be filtered by various criteria.
format: date-time
- - `entity_id: optional string or null`
-
- - `entity_type: optional string or null`
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -126477,13 +128059,13 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeUserRoleUpdated object`
+ - `VerificationProgramApplicationCreated object`
- A user's role within the organization was changed, or the user was added to or removed from the organization.
+ An organization applied to a verification program.
- - `type: optional "claude_user_role_updated"`
+ - `type: optional "verification_program_application_created"`
- default: claude_user_role_updated
+ default: verification_program_application_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -126691,13 +128273,9 @@ compliance activities that can be filtered by various criteria.
- `user_agent: optional string or null`
- - `user_email: string`
-
- Email of the user whose role was changed
-
- - `user_id: string`
+ - `program_slug: string`
- ID of the user whose role was changed
+ The verification program the organization applied to.
- `id: optional string`
@@ -126709,10 +128287,6 @@ compliance activities that can be filtered by various criteria.
format: date-time
- - `current_role: optional string or null`
-
- If null, then user was removed from the Organization
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -126721,17 +128295,13 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_role: optional string or null`
-
- If null, then user was added to the Organization
-
- - `ClaudeUserSettingsUpdated object`
+ - `WorkspaceMemberSpendLimitCreated object`
- User updated their personal settings.
+ A per-member or workspace-default Claude Code spend limit was created.
- - `type: optional "claude_user_settings_updated"`
+ - `type: optional "workspace_member_spend_limit_created"`
- default: claude_user_settings_updated
+ default: workspace_member_spend_limit_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -126939,364 +128509,262 @@ compliance activities that can be filtered by various criteria.
- `user_agent: optional string or null`
- - `updates: array of FullName or DisplayName or ArtifactsEnabled or 19 more`
-
- - `FullName object`
-
- The full name setting was changed.
-
- - `type: optional "full_name"`
-
- default: full_name
-
- - `current_value: optional string or null`
-
- Setting value immediately after this change
-
- - `previous_value: optional string or null`
-
- Setting value immediately before this change
-
- - `DisplayName object`
-
- The display name setting was changed.
-
- - `type: optional "display_name"`
-
- default: display_name
-
- - `current_value: optional string or null`
-
- Setting value immediately after this change
-
- - `previous_value: optional string or null`
-
- Setting value immediately before this change
-
- - `ArtifactsEnabled object`
-
- The artifacts setting was changed.
-
- - `type: optional "artifacts_enabled"`
-
- default: artifacts_enabled
-
- - `current_value: optional boolean or null`
-
- Setting value immediately after this change
-
- - `previous_value: optional boolean or null`
-
- Setting value immediately before this change
-
- - `LatexEnabled object`
-
- The LaTeX setting was changed.
-
- - `type: optional "latex_enabled"`
-
- default: latex_enabled
-
- - `current_value: optional boolean or null`
-
- Setting value immediately after this change
-
- - `previous_value: optional boolean or null`
-
- Setting value immediately before this change
-
- - `AnalysisToolEnabled object`
-
- The analysis tool setting was changed.
-
- - `type: optional "analysis_tool_enabled"`
-
- default: analysis_tool_enabled
-
- - `current_value: optional boolean or null`
-
- Setting value immediately after this change
-
- - `previous_value: optional boolean or null`
-
- Setting value immediately before this change
-
- - `ChatSuggestionsEnabled object`
-
- The chat suggestions setting was changed.
-
- - `type: optional "chat_suggestions_enabled"`
-
- default: chat_suggestions_enabled
-
- - `current_value: optional boolean or null`
-
- Setting value immediately after this change
-
- - `previous_value: optional boolean or null`
-
- Setting value immediately before this change
-
- - `MultimodalPdfsEnabled object`
-
- The multimodal PDFs setting was changed.
-
- - `type: optional "multimodal_pdfs_enabled"`
-
- default: multimodal_pdfs_enabled
-
- - `current_value: optional boolean or null`
-
- Setting value immediately after this change
-
- - `previous_value: optional boolean or null`
+ - `id: optional string`
- Setting value immediately before this change
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- - `GdriveEnabled object`
+ - `account_id: optional string or null`
- The Google Drive setting was changed.
+ Tagged ID of the user (null for workspace-wide default).
- - `type: optional "gdrive_enabled"`
+ - `created_at: optional string`
- default: gdrive_enabled
+ When this activity occurred.
- - `current_value: optional boolean or null`
+ format: date-time
- Setting value immediately after this change
+ - `limit_action: optional string or null`
- - `previous_value: optional boolean or null`
+ The action taken when the limit is reached.
- Setting value immediately before this change
+ - `limit_usd: optional number or null`
- - `WebSearchEnabled object`
+ The spend limit threshold in USD cents.
- The web search setting was changed.
+ - `organization_id: optional string or null`
- - `type: optional "web_search_enabled"`
+ Organization ID this activity is associated with
- default: web_search_enabled
+ - `organization_uuid: optional string or null`
- - `current_value: optional boolean or null`
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- Setting value immediately after this change
+ - `workspace_id: optional string or null`
- - `previous_value: optional boolean or null`
+ Tagged ID of the workspace.
- Setting value immediately before this change
+ - `WorkspaceMemberSpendLimitDeleted object`
- - `GeolocationEnabled object`
+ A per-member or workspace-default Claude Code spend limit was deleted.
- The geolocation setting was changed.
+ - `type: optional "workspace_member_spend_limit_deleted"`
- - `type: optional "geolocation_enabled"`
+ default: workspace_member_spend_limit_deleted
- default: geolocation_enabled
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
- - `current_value: optional boolean or null`
+ - `APIActor object`
- Setting value immediately after this change
+ - `type: optional "api_actor"`
- - `previous_value: optional boolean or null`
+ default: api_actor
- Setting value immediately before this change
+ - `api_key_id: string`
- - `EnabledSaffron object`
+ - `ip_address: string`
- The memory setting was changed for the user.
+ - `user_agent: string`
- - `type: optional "enabled_saffron"`
+ - `UserActor object`
- default: enabled_saffron
+ - `type: optional "user_actor"`
- - `current_value: optional boolean or null`
+ default: user_actor
- Setting value immediately after this change
+ - `email_address: string`
- - `previous_value: optional boolean or null`
+ format: email
- Setting value immediately before this change
+ - `ip_address: string`
- - `McpToolsEnabled object`
+ - `user_agent: string`
- The MCP tools setting was changed.
+ - `user_id: string`
- - `type: optional "mcp_tools_enabled"`
+ - `UnauthenticatedUserActor object`
- default: mcp_tools_enabled
+ - `type: optional "unauthenticated_user_actor"`
- - `current_value: optional map[boolean] or null`
+ default: unauthenticated_user_actor
- Setting value immediately after this change
+ - `ip_address: string`
- - `previous_value: optional map[boolean] or null`
+ - `user_agent: string`
- Setting value immediately before this change
+ - `unauthenticated_email_address: optional string or null`
- - `CliOpPermissionsEnabled object`
+ format: email
- The CLI operation permissions setting was changed.
+ - `AnthropicActor object`
- - `type: optional "cli_op_permissions_enabled"`
+ - `type: optional "anthropic_actor"`
- default: cli_op_permissions_enabled
+ default: anthropic_actor
- - `current_value: optional map[string] or null`
+ - `email_address: optional string or null`
- Setting value immediately after this change
+ format: email
- - `previous_value: optional map[string] or null`
+ - `SystemActor object`
- Setting value immediately before this change
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
- - `GoogleDriveSearchEnabled object`
+ - `type: optional "system_actor"`
- The Google Drive search setting was changed.
+ default: system_actor
- - `type: optional "google_drive_search_enabled"`
+ - `service: optional string or null`
- default: google_drive_search_enabled
+ Name of the automated process that performed the action, when known.
- - `current_value: optional boolean or null`
+ - `AdminAPIKeyActor object`
- Setting value immediately after this change
+ - `type: optional "admin_api_key_actor"`
- - `previous_value: optional boolean or null`
+ default: admin_api_key_actor
- Setting value immediately before this change
+ - `admin_api_key_id: string`
- - `GmailIntegrationEnabled object`
+ - `ip_address: string`
- The Gmail integration setting was changed.
+ - `user_agent: string`
- - `type: optional "gmail_integration_enabled"`
+ - `ServiceAccountActor object`
- default: gmail_integration_enabled
+ - `type: optional "service_account_actor"`
- - `current_value: optional boolean or null`
+ default: service_account_actor
- Setting value immediately after this change
+ - `ip_address: string`
- - `previous_value: optional boolean or null`
+ - `service_account_id: string`
- Setting value immediately before this change
+ - `user_agent: string`
- - `GoogleCalendarIntegrationEnabled object`
+ - `ScimDirectorySyncActor object`
- The Google Calendar integration setting was changed.
+ - `type: optional "scim_directory_sync_actor"`
- - `type: optional "google_calendar_integration_enabled"`
+ default: scim_directory_sync_actor
- default: google_calendar_integration_enabled
+ - `directory_id: string`
- - `current_value: optional boolean or null`
+ - `workos_event_id: string`
- Setting value immediately after this change
+ - `idp_connection_type: optional string or null`
- - `previous_value: optional boolean or null`
+ - `FederatedIdentityActor object`
- Setting value immediately before this change
+ A federated external workload authenticated via a verified OIDC token.
- - `ThinkingModeEnabled object`
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
- The thinking mode setting was changed.
+ - `type: optional "federated_identity_actor"`
- - `type: optional "thinking_mode_enabled"`
+ default: federated_identity_actor
- default: thinking_mode_enabled
+ - `issuer: string`
- - `current_value: optional "adaptive" or "extended" or "off" or "unspecified" or null`
+ - `subject: string`
- Setting value immediately after this change
+ - `audience: optional array of string`
- - `"adaptive"`
+ - `ip_address: optional string or null`
- - `"extended"`
+ - `user_agent: optional string or null`
- - `"off"`
+ - `FederatedActor object`
- - `"unspecified"`
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
- - `previous_value: optional "adaptive" or "extended" or "off" or "unspecified" or null`
+ - `type: optional "federated_actor"`
- Setting value immediately before this change
+ default: federated_actor
- - `"adaptive"`
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
- - `"extended"`
+ - `FederatedActorAwsProvider object`
- - `"off"`
+ Asserting party: the AWS account the organization is bound to.
- - `"unspecified"`
+ - `type: optional "aws"`
- - `ResearchModeEnabled object`
+ default: aws
- The research mode setting was changed.
+ - `account_id: string`
- - `type: optional "research_mode_enabled"`
+ - `signed_principal: string`
- default: research_mode_enabled
+ The AWS-signed ARN of the IAM principal that requested the token.
- - `current_value: optional boolean or null`
+ - `FederatedActorAzureProvider object`
- Setting value immediately after this change
+ Asserting party: the Azure subscription the organization is bound to.
- - `previous_value: optional boolean or null`
+ - `type: optional "azure"`
- Setting value immediately before this change
+ default: azure
- - `ComputerUseEnabled object`
+ - `subscription_id: string`
- The computer use setting was changed.
+ - `FederatedActorGcpProvider object`
- - `type: optional "computer_use_enabled"`
+ Asserting party: the GCP project the organization is bound to.
- default: computer_use_enabled
+ - `type: optional "gcp"`
- - `current_value: optional boolean or null`
+ default: gcp
- Setting value immediately after this change
+ - `project_number: string`
- - `previous_value: optional boolean or null`
+ - `FederatedActorOidcProvider object`
- Setting value immediately before this change
+ Asserting party: a customer-registered OIDC federation issuer.
- - `ClaudeAPIInArtifactsEnabled object`
+ - `type: optional "oidc"`
- The Claude API in Artifacts setting was changed.
+ default: oidc
- - `type: optional "claude_api_in_artifacts_enabled"`
+ - `issuer: optional string or null`
- default: claude_api_in_artifacts_enabled
+ The federation issuer's URL. Null when the presented credential failed verification.
- - `current_value: optional boolean or null`
+ - `ip_address: optional string or null`
- Setting value immediately after this change
+ - `subject: optional string or null`
- - `previous_value: optional boolean or null`
+ The provider's verified identifier for the caller; its form depends on the provider.
- Setting value immediately before this change
+ - `user_agent: optional string or null`
- - `ConversationPreferences object`
+ - `AttestedDeviceActor object`
- The 'conversation_preferences' for the user were updated. Values omitted.
+ An attested mobile device authenticated via Apple App Attest.
- - `type: optional "conversation_preferences"`
+ - `type: optional "attested_device_actor"`
- default: conversation_preferences
+ default: attested_device_actor
- - `CoworkGlobalInstructions object`
+ - `external_client_id: string`
- The Cowork global instructions were updated. Values omitted.
+ - `kid_hash: string`
- - `type: optional "cowork_global_instructions"`
+ - `ip_address: optional string or null`
- default: cowork_global_instructions
+ - `user_agent: optional string or null`
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `account_id: optional string or null`
+
+ Tagged ID of the user (null for workspace-wide default).
+
- `created_at: optional string`
When this activity occurred.
@@ -127311,13 +128779,21 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `VerificationEvidenceSubmitted object`
+ - `spend_limit_id: optional string or null`
- Verification evidence was submitted for an organization's verification.
+ UUID of the deleted spend limit.
- - `type: optional "verification_evidence_submitted"`
+ - `workspace_id: optional string or null`
- default: verification_evidence_submitted
+ Tagged ID of the workspace.
+
+ - `WorkspaceMemberSpendLimitUpdated object`
+
+ A per-member Claude Code spend limit amount was updated.
+
+ - `type: optional "workspace_member_spend_limit_updated"`
+
+ default: workspace_member_spend_limit_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -127525,24 +129001,24 @@ compliance activities that can be filtered by various criteria.
- `user_agent: optional string or null`
- - `verification_id: string`
-
- Tagged ID of the verification the evidence was submitted for.
-
- - `verification_type: string`
-
- The type of verification the evidence was submitted for.
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `account_id: optional string or null`
+
+ Tagged ID of the user (null for workspace-wide default).
+
- `created_at: optional string`
When this activity occurred.
format: date-time
+ - `new_limit_usd: optional number or null`
+
+ The new spend limit threshold in USD cents.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -127551,13 +129027,21 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `VerificationProgramApplicationCreated object`
+ - `spend_limit_id: optional string or null`
- An organization applied to a verification program.
+ UUID of the spend limit.
- - `type: optional "verification_program_application_created"`
+ - `workspace_id: optional string or null`
- default: verification_program_application_created
+ Tagged ID of the workspace.
+
+ - `WorkspaceSpendLimitAlertEmailsUpdated object`
+
+ Spend limit alert email recipients were updated for a workspace.
+
+ - `type: optional "workspace_spend_limit_alert_emails_updated"`
+
+ default: workspace_spend_limit_alert_emails_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -127765,14 +129249,14 @@ compliance activities that can be filtered by various criteria.
- `user_agent: optional string or null`
- - `program_slug: string`
-
- The verification program the organization applied to.
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `alert_emails: optional array of string or null`
+
+ Updated list of alert email addresses.
+
- `created_at: optional string`
When this activity occurred.
@@ -127787,13 +129271,17 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `WorkspaceMemberSpendLimitCreated object`
+ - `workspace_id: optional string or null`
- A per-member or workspace-default Claude Code spend limit was created.
+ Tagged ID of the workspace.
- - `type: optional "workspace_member_spend_limit_created"`
+ - `WorkspaceSpendLimitCreated object`
- default: workspace_member_spend_limit_created
+ A workspace-level API spend limit was created.
+
+ - `type: optional "workspace_spend_limit_created"`
+
+ default: workspace_spend_limit_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -128005,10 +129493,6 @@ compliance activities that can be filtered by various criteria.
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `account_id: optional string or null`
-
- Tagged ID of the user (null for workspace-wide default).
-
- `created_at: optional string`
When this activity occurred.
@@ -128017,7 +129501,7 @@ compliance activities that can be filtered by various criteria.
- `limit_action: optional string or null`
- The action taken when the limit is reached.
+ The action taken when the limit is reached (notify_only or notify_and_pause).
- `limit_usd: optional number or null`
@@ -128035,13 +129519,302 @@ compliance activities that can be filtered by various criteria.
Tagged ID of the workspace.
- - `WorkspaceMemberSpendLimitDeleted object`
+ - `WorkspaceSpendLimitDeleted object`
- A per-member or workspace-default Claude Code spend limit was deleted.
+ A workspace-level API spend limit was deleted.
- - `type: optional "workspace_member_spend_limit_deleted"`
+ - `type: optional "workspace_spend_limit_deleted"`
- default: workspace_member_spend_limit_deleted
+ default: workspace_spend_limit_deleted
+
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+
+ - `APIActor object`
+
+ - `type: optional "api_actor"`
+
+ default: api_actor
+
+ - `api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `UserActor object`
+
+ - `type: optional "user_actor"`
+
+ default: user_actor
+
+ - `email_address: string`
+
+ format: email
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `user_id: string`
+
+ - `UnauthenticatedUserActor object`
+
+ - `type: optional "unauthenticated_user_actor"`
+
+ default: unauthenticated_user_actor
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `unauthenticated_email_address: optional string or null`
+
+ format: email
+
+ - `AnthropicActor object`
+
+ - `type: optional "anthropic_actor"`
+
+ default: anthropic_actor
+
+ - `email_address: optional string or null`
+
+ format: email
+
+ - `SystemActor object`
+
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
+
+ - `type: optional "system_actor"`
+
+ default: system_actor
+
+ - `service: optional string or null`
+
+ Name of the automated process that performed the action, when known.
+
+ - `AdminAPIKeyActor object`
+
+ - `type: optional "admin_api_key_actor"`
+
+ default: admin_api_key_actor
+
+ - `admin_api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `ServiceAccountActor object`
+
+ - `type: optional "service_account_actor"`
+
+ default: service_account_actor
+
+ - `ip_address: string`
+
+ - `service_account_id: string`
+
+ - `user_agent: string`
+
+ - `ScimDirectorySyncActor object`
+
+ - `type: optional "scim_directory_sync_actor"`
+
+ default: scim_directory_sync_actor
+
+ - `directory_id: string`
+
+ - `workos_event_id: string`
+
+ - `idp_connection_type: optional string or null`
+
+ - `FederatedIdentityActor object`
+
+ A federated external workload authenticated via a verified OIDC token.
+
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
+
+ - `type: optional "federated_identity_actor"`
+
+ default: federated_identity_actor
+
+ - `issuer: string`
+
+ - `subject: string`
+
+ - `audience: optional array of string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `FederatedActor object`
+
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
+
+ - `type: optional "federated_actor"`
+
+ default: federated_actor
+
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+
+ - `FederatedActorAwsProvider object`
+
+ Asserting party: the AWS account the organization is bound to.
+
+ - `type: optional "aws"`
+
+ default: aws
+
+ - `account_id: string`
+
+ - `signed_principal: string`
+
+ The AWS-signed ARN of the IAM principal that requested the token.
+
+ - `FederatedActorAzureProvider object`
+
+ Asserting party: the Azure subscription the organization is bound to.
+
+ - `type: optional "azure"`
+
+ default: azure
+
+ - `subscription_id: string`
+
+ - `FederatedActorGcpProvider object`
+
+ Asserting party: the GCP project the organization is bound to.
+
+ - `type: optional "gcp"`
+
+ default: gcp
+
+ - `project_number: string`
+
+ - `FederatedActorOidcProvider object`
+
+ Asserting party: a customer-registered OIDC federation issuer.
+
+ - `type: optional "oidc"`
+
+ default: oidc
+
+ - `issuer: optional string or null`
+
+ The federation issuer's URL. Null when the presented credential failed verification.
+
+ - `ip_address: optional string or null`
+
+ - `subject: optional string or null`
+
+ The provider's verified identifier for the caller; its form depends on the provider.
+
+ - `user_agent: optional string or null`
+
+ - `AttestedDeviceActor object`
+
+ An attested mobile device authenticated via Apple App Attest.
+
+ - `type: optional "attested_device_actor"`
+
+ default: attested_device_actor
+
+ - `external_client_id: string`
+
+ - `kid_hash: string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
+
+ - `created_at: optional string`
+
+ When this activity occurred.
+
+ format: date-time
+
+ - `organization_id: optional string or null`
+
+ Organization ID this activity is associated with
+
+ - `organization_uuid: optional string or null`
+
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+
+ - `spend_limit_id: optional string or null`
+
+ UUID of the deleted spend limit.
+
+ - `workspace_id: optional string or null`
+
+ Tagged ID of the workspace.
+
+- `first_id: optional string or null`
+
+- `has_more: optional boolean`
+
+ default: false
+
+- `last_id: optional string or null`
+
+### Example
+
+```bash
+curl https://api.anthropic.com/v1/compliance/activities \
+ -H 'anthropic-version: 2023-06-01' \
+ -H "Authorization: Bearer $ANTHROPIC_COMPLIANCE_API_KEY"
+```
+
+#### Response (200)
+
+```json
+{
+ "data": [
+ {
+ "actor": {
+ "api_key_id": "api_key_id",
+ "ip_address": "ip_address",
+ "user_agent": "user_agent",
+ "type": "api_actor"
+ },
+ "decision": "blocked",
+ "id": "id",
+ "abuse_session_id": "abuse_session_id",
+ "created_at": "2019-12-27T18:11:19.117Z",
+ "organization_id": "organization_id",
+ "organization_uuid": "organization_uuid",
+ "type": "abuse_decision_received"
+ }
+ ],
+ "first_id": "first_id",
+ "has_more": true,
+ "last_id": "last_id"
+}
+```
+
+## Domain types
+
+### Activity List Response
+
+- `ActivityListResponse = AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 503 more`
+
+ - `AbuseDecisionReceived object`
+
+ An external anti-abuse service reported a consequential decision about a sign-in or sign-up attempt.
+
+ - `type: optional "abuse_decision_received"`
+
+ default: abuse_decision_received
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -128249,257 +130022,21 @@ compliance activities that can be filtered by various criteria.
- `user_agent: optional string or null`
- - `id: optional string`
-
- Unique identifier for the activity e.g. 'activity_abcd1234'
-
- - `account_id: optional string or null`
-
- Tagged ID of the user (null for workspace-wide default).
-
- - `created_at: optional string`
-
- When this activity occurred.
-
- format: date-time
-
- - `organization_id: optional string or null`
-
- Organization ID this activity is associated with
-
- - `organization_uuid: optional string or null`
-
- Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
-
- - `spend_limit_id: optional string or null`
-
- UUID of the deleted spend limit.
-
- - `workspace_id: optional string or null`
-
- Tagged ID of the workspace.
-
- - `WorkspaceMemberSpendLimitUpdated object`
-
- A per-member Claude Code spend limit amount was updated.
-
- - `type: optional "workspace_member_spend_limit_updated"`
-
- default: workspace_member_spend_limit_updated
-
- - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
-
- - `APIActor object`
-
- - `type: optional "api_actor"`
-
- default: api_actor
-
- - `api_key_id: string`
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `UserActor object`
-
- - `type: optional "user_actor"`
-
- default: user_actor
-
- - `email_address: string`
-
- format: email
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `user_id: string`
-
- - `UnauthenticatedUserActor object`
-
- - `type: optional "unauthenticated_user_actor"`
-
- default: unauthenticated_user_actor
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `unauthenticated_email_address: optional string or null`
-
- format: email
-
- - `AnthropicActor object`
-
- - `type: optional "anthropic_actor"`
-
- default: anthropic_actor
-
- - `email_address: optional string or null`
-
- format: email
-
- - `SystemActor object`
-
- Automated background processing performed by Anthropic systems, acting
- without a user or customer credential.
-
- - `type: optional "system_actor"`
-
- default: system_actor
-
- - `service: optional string or null`
-
- Name of the automated process that performed the action, when known.
-
- - `AdminAPIKeyActor object`
-
- - `type: optional "admin_api_key_actor"`
-
- default: admin_api_key_actor
-
- - `admin_api_key_id: string`
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `ServiceAccountActor object`
-
- - `type: optional "service_account_actor"`
-
- default: service_account_actor
-
- - `ip_address: string`
-
- - `service_account_id: string`
-
- - `user_agent: string`
-
- - `ScimDirectorySyncActor object`
-
- - `type: optional "scim_directory_sync_actor"`
-
- default: scim_directory_sync_actor
-
- - `directory_id: string`
-
- - `workos_event_id: string`
-
- - `idp_connection_type: optional string or null`
-
- - `FederatedIdentityActor object`
-
- A federated external workload authenticated via a verified OIDC token.
-
- Carries the verified issuer, subject, and audience claims from the
- presented JWT.
-
- - `type: optional "federated_identity_actor"`
-
- default: federated_identity_actor
-
- - `issuer: string`
-
- - `subject: string`
-
- - `audience: optional array of string`
-
- - `ip_address: optional string or null`
-
- - `user_agent: optional string or null`
-
- - `FederatedActor object`
-
- An external identity asserted by a trusted provider — a cloud-provider
- gateway or a customer-registered federation issuer — acting without an
- Anthropic-provisioned account or service account.
-
- - `type: optional "federated_actor"`
-
- default: federated_actor
-
- - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
-
- - `FederatedActorAwsProvider object`
-
- Asserting party: the AWS account the organization is bound to.
-
- - `type: optional "aws"`
-
- default: aws
-
- - `account_id: string`
-
- - `signed_principal: string`
-
- The AWS-signed ARN of the IAM principal that requested the token.
-
- - `FederatedActorAzureProvider object`
-
- Asserting party: the Azure subscription the organization is bound to.
-
- - `type: optional "azure"`
-
- default: azure
-
- - `subscription_id: string`
-
- - `FederatedActorGcpProvider object`
-
- Asserting party: the GCP project the organization is bound to.
-
- - `type: optional "gcp"`
-
- default: gcp
-
- - `project_number: string`
-
- - `FederatedActorOidcProvider object`
-
- Asserting party: a customer-registered OIDC federation issuer.
-
- - `type: optional "oidc"`
-
- default: oidc
-
- - `issuer: optional string or null`
-
- The federation issuer's URL. Null when the presented credential failed verification.
-
- - `ip_address: optional string or null`
-
- - `subject: optional string or null`
-
- The provider's verified identifier for the caller; its form depends on the provider.
-
- - `user_agent: optional string or null`
-
- - `AttestedDeviceActor object`
-
- An attested mobile device authenticated via Apple App Attest.
-
- - `type: optional "attested_device_actor"`
-
- default: attested_device_actor
-
- - `external_client_id: string`
+ - `decision: "blocked" or "unspecified"`
- - `kid_hash: string`
+ The decision applied to the session.
- - `ip_address: optional string or null`
+ - `"blocked"`
- - `user_agent: optional string or null`
+ - `"unspecified"`
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `account_id: optional string or null`
+ - `abuse_session_id: optional string or null`
- Tagged ID of the user (null for workspace-wide default).
+ The anti-abuse service's opaque session identifier for correlation.
- `created_at: optional string`
@@ -128507,10 +130044,6 @@ compliance activities that can be filtered by various criteria.
format: date-time
- - `new_limit_usd: optional number or null`
-
- The new spend limit threshold in USD cents.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -128519,21 +130052,13 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `spend_limit_id: optional string or null`
-
- UUID of the spend limit.
-
- - `workspace_id: optional string or null`
-
- Tagged ID of the workspace.
-
- - `WorkspaceSpendLimitAlertEmailsUpdated object`
+ - `AccountDeleted object`
- Spend limit alert email recipients were updated for a workspace.
+ User-initiated self-service account deletion.
- - `type: optional "workspace_spend_limit_alert_emails_updated"`
+ - `type: optional "account_deleted"`
- default: workspace_spend_limit_alert_emails_updated
+ default: account_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -128745,10 +130270,6 @@ compliance activities that can be filtered by various criteria.
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `alert_emails: optional array of string or null`
-
- Updated list of alert email addresses.
-
- `created_at: optional string`
When this activity occurred.
@@ -128763,17 +130284,13 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `workspace_id: optional string or null`
-
- Tagged ID of the workspace.
-
- - `WorkspaceSpendLimitCreated object`
+ - `AdminAPIKeyCreated object`
- A workspace-level API spend limit was created.
+ An admin API key was created.
- - `type: optional "workspace_spend_limit_created"`
+ - `type: optional "admin_api_key_created"`
- default: workspace_spend_limit_created
+ default: admin_api_key_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -128981,6 +130498,10 @@ compliance activities that can be filtered by various criteria.
- `user_agent: optional string or null`
+ - `admin_api_key_id: string`
+
+ Tagged ID of the created admin API key
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -128991,14 +130512,6 @@ compliance activities that can be filtered by various criteria.
format: date-time
- - `limit_action: optional string or null`
-
- The action taken when the limit is reached (notify_only or notify_and_pause).
-
- - `limit_usd: optional number or null`
-
- The spend limit threshold in USD cents.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -129007,17 +130520,17 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `workspace_id: optional string or null`
+ - `scopes: optional array of string`
- Tagged ID of the workspace.
+ Scopes granted to the key (empty for legacy non-scoped admin keys)
- - `WorkspaceSpendLimitDeleted object`
+ - `AdminAPIKeyDeleted object`
- A workspace-level API spend limit was deleted.
+ An admin API key was deleted.
- - `type: optional "workspace_spend_limit_deleted"`
+ - `type: optional "admin_api_key_deleted"`
- default: workspace_spend_limit_deleted
+ default: admin_api_key_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -129225,6 +130738,10 @@ compliance activities that can be filtered by various criteria.
- `user_agent: optional string or null`
+ - `admin_api_key_id: string`
+
+ Tagged ID of the deleted admin API key
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -129243,70 +130760,13 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `spend_limit_id: optional string or null`
-
- UUID of the deleted spend limit.
-
- - `workspace_id: optional string or null`
-
- Tagged ID of the workspace.
-
-- `first_id: optional string or null`
-
-- `has_more: optional boolean`
-
- default: false
-
-- `last_id: optional string or null`
-
-### Example
-
-```bash
-curl https://api.anthropic.com/v1/compliance/activities \
- -H 'anthropic-version: 2023-06-01' \
- -H "Authorization: Bearer $ANTHROPIC_COMPLIANCE_API_KEY"
-```
-
-#### Response (200)
-
-```json
-{
- "data": [
- {
- "actor": {
- "api_key_id": "api_key_id",
- "ip_address": "ip_address",
- "user_agent": "user_agent",
- "type": "api_actor"
- },
- "decision": "blocked",
- "id": "id",
- "abuse_session_id": "abuse_session_id",
- "created_at": "2019-12-27T18:11:19.117Z",
- "organization_id": "organization_id",
- "organization_uuid": "organization_uuid",
- "type": "abuse_decision_received"
- }
- ],
- "first_id": "first_id",
- "has_more": true,
- "last_id": "last_id"
-}
-```
-
-## Domain types
-
-### Activity List Response
-
-- `ActivityListResponse = AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 501 more`
-
- - `AbuseDecisionReceived object`
+ - `AdminAPIKeyUpdated object`
- An external anti-abuse service reported a consequential decision about a sign-in or sign-up attempt.
+ An admin API key was updated (renamed or activated/deactivated).
- - `type: optional "abuse_decision_received"`
+ - `type: optional "admin_api_key_updated"`
- default: abuse_decision_received
+ default: admin_api_key_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -129514,22 +130974,14 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `decision: "blocked" or "unspecified"`
-
- The decision applied to the session.
-
- - `"blocked"`
+ - `admin_api_key_id: string`
- - `"unspecified"`
+ Tagged ID of the updated admin API key
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `abuse_session_id: optional string or null`
-
- The anti-abuse service's opaque session identifier for correlation.
-
- `created_at: optional string`
When this activity occurred.
@@ -129544,13 +130996,35 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `AccountDeleted object`
+ - `updates: optional array of object`
- User-initiated self-service account deletion.
+ The field-level changes applied in this update
- - `type: optional "account_deleted"`
+ - `type: "name" or "status" or "unspecified"`
- default: account_deleted
+ The admin API key field that changed
+
+ - `"name"`
+
+ - `"status"`
+
+ - `"unspecified"`
+
+ - `current_value: string`
+
+ Field value immediately after this change
+
+ - `previous_value: string`
+
+ Field value immediately before this change
+
+ - `AdminConnectorRequestResolved object`
+
+ Admin approved or dismissed pending member requests to enable an MCP connector.
+
+ - `type: optional "admin_connector_request_resolved"`
+
+ default: admin_connector_request_resolved
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -129758,6 +131232,18 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `decision: "approved" or "dismissed" or "unspecified"`
+
+ - `"approved"`
+
+ - `"dismissed"`
+
+ - `"unspecified"`
+
+ - `mcp_server_id: string`
+
+ - `resolved_count: number`
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -129776,13 +131262,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `AdminAPIKeyCreated object`
+ - `AdminRequestCreated object`
- An admin API key was created.
+ Admin request created by an org member (seat upgrade, limit increase, join org, end-user invite).
- - `type: optional "admin_api_key_created"`
+ - `type: optional "admin_request_created"`
- default: admin_api_key_created
+ default: admin_request_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -129990,9 +131476,7 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `admin_api_key_id: string`
-
- Tagged ID of the created admin API key
+ - `request_type: string`
- `id: optional string`
@@ -130012,17 +131496,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `scopes: optional array of string`
-
- Scopes granted to the key (empty for legacy non-scoped admin keys)
-
- - `AdminAPIKeyDeleted object`
+ - `AdminSetupChecklistStepDelegated object`
- An admin API key was deleted.
+ A step of the Claude Enterprise admin setup checklist was delegated to a teammate — an organization member, or an email address that has not joined the organization yet — replacing any earlier delegation of that step.
- - `type: optional "admin_api_key_deleted"`
+ - `type: optional "admin_setup_checklist_step_delegated"`
- default: admin_api_key_deleted
+ default: admin_setup_checklist_step_delegated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -130230,9 +131710,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `admin_api_key_id: string`
+ - `step: string`
- Tagged ID of the deleted admin API key
+ The checklist step that was delegated, for example `enable_sso` or `verify_domain`.
- `id: optional string`
@@ -130244,6 +131724,14 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `delegate_email: optional string or null`
+
+ Email address the step was delegated to; present only when the delegate is not yet an organization member.
+
+ - `delegate_user_id: optional string or null`
+
+ Tagged ID of the organization member the step was delegated to; absent when the step was delegated to an email address that has not joined the organization.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -130252,13 +131740,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `AdminAPIKeyUpdated object`
+ - `AdminSetupChecklistStepDelegationCancelled object`
- An admin API key was updated (renamed or activated/deactivated).
+ The delegation of a Claude Enterprise admin setup checklist step was cancelled.
- - `type: optional "admin_api_key_updated"`
+ - `type: optional "admin_setup_checklist_step_delegation_cancelled"`
- default: admin_api_key_updated
+ default: admin_setup_checklist_step_delegation_cancelled
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -130466,9 +131954,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `admin_api_key_id: string`
+ - `step: string`
- Tagged ID of the updated admin API key
+ The checklist step whose delegation was cancelled.
- `id: optional string`
@@ -130488,35 +131976,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `updates: optional array of object`
-
- The field-level changes applied in this update
-
- - `type: "name" or "status" or "unspecified"`
-
- The admin API key field that changed
-
- - `"name"`
-
- - `"status"`
-
- - `"unspecified"`
-
- - `current_value: string`
-
- Field value immediately after this change
-
- - `previous_value: string`
-
- Field value immediately before this change
-
- - `AdminConnectorRequestResolved object`
+ - `AgeVerified object`
- Admin approved or dismissed pending member requests to enable an MCP connector.
+ User age was verified.
- - `type: optional "admin_connector_request_resolved"`
+ - `type: optional "age_verified"`
- default: admin_connector_request_resolved
+ default: age_verified
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -130724,18 +132190,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `decision: "approved" or "dismissed" or "unspecified"`
-
- - `"approved"`
-
- - `"dismissed"`
-
- - `"unspecified"`
-
- - `mcp_server_id: string`
-
- - `resolved_count: number`
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -130754,13 +132208,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `AdminRequestCreated object`
+ - `AnonymousMobileLoginAttempted object`
- Admin request created by an org member (seat upgrade, limit increase, join org, end-user invite).
+ Anonymous mobile login was attempted.
- - `type: optional "admin_request_created"`
+ - `type: optional "anonymous_mobile_login_attempted"`
- default: admin_request_created
+ default: anonymous_mobile_login_attempted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -130968,8 +132422,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `request_type: string`
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -130988,13 +132440,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `AdminSetupChecklistStepDelegated object`
+ - `APIKeyCreated object`
- A step of the Claude Enterprise admin setup checklist was delegated to a teammate — an organization member, or an email address that has not joined the organization yet — replacing any earlier delegation of that step.
+ Activity logged when a new API key is created.
- - `type: optional "admin_setup_checklist_step_delegated"`
+ - `type: optional "api_key_created"`
- default: admin_setup_checklist_step_delegated
+ default: api_key_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -131202,9 +132654,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `step: string`
+ - `api_key_id: string`
- The checklist step that was delegated, for example `enable_sso` or `verify_domain`.
+ The tagged ID of the created API key
- `id: optional string`
@@ -131216,14 +132668,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `delegate_email: optional string or null`
-
- Email address the step was delegated to; present only when the delegate is not yet an organization member.
-
- - `delegate_user_id: optional string or null`
-
- Tagged ID of the organization member the step was delegated to; absent when the step was delegated to an email address that has not joined the organization.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -131232,13 +132676,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `AdminSetupChecklistStepDelegationCancelled object`
+ - `restricted_to_organization: optional boolean or null`
- The delegation of a Claude Enterprise admin setup checklist step was cancelled.
+ Whether the key was restricted to the creating organization, rather than granted access across the whole parent organization
- - `type: optional "admin_setup_checklist_step_delegation_cancelled"`
+ - `scopes: optional array of string`
- default: admin_setup_checklist_step_delegation_cancelled
+ The scopes for this API key
+
+ - `ClaudeArtifactAccessFailed object`
+
+ An attempt to access an artifact failed.
+
+ - `type: optional "claude_artifact_access_failed"`
+
+ default: claude_artifact_access_failed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -131446,14 +132898,18 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `step: string`
-
- The checklist step whose delegation was cancelled.
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `claude_artifact_id: optional string or null`
+
+ The artifact's identifier, when known.
+
+ - `claude_artifact_version_id: optional string or null`
+
+ The version of the artifact the user attempted to access, when known.
+
- `created_at: optional string`
When this activity occurred.
@@ -131468,13 +132924,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `AgeVerified object`
+ - `reason: optional string or null`
- User age was verified.
+ The reason access was denied, when recorded.
- - `type: optional "age_verified"`
+ - `ClaudeArtifactCommented object`
- default: age_verified
+ Comment activity on a published artifact: a comment was added, a thread's resolved state was changed, or a thread was deleted. The actor is the user who performed the action; the comment text itself is stored with the artifact and is not part of this record.
+
+ - `type: optional "claude_artifact_commented"`
+
+ default: claude_artifact_commented
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -131682,10 +133142,56 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `claude_artifact_id: string`
+
+ The artifact's identifier.
+
+ - `comment_action: "activate_thread" or "create_thread" or "deactivate_thread" or 10 more`
+
+ The action recorded: for example a new comment thread, a reply to an existing thread, a thread resolved, reopened, or deleted, a thread's Claude activation granted or revoked, a comment's text rewritten by its author, an existing comment sent to Claude or withdrawn from Claude, or a thread resolved by a Claude session.
+
+ - `"activate_thread"`
+
+ - `"create_thread"`
+
+ - `"deactivate_thread"`
+
+ - `"delete_thread"`
+
+ - `"edit_comment"`
+
+ - `"move_thread"`
+
+ - `"reopen"`
+
+ - `"reply"`
+
+ - `"resolve"`
+
+ - `"send_to_claude"`
+
+ - `"session_resolve"`
+
+ - `"unsend_to_claude"`
+
+ - `"unspecified"`
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `claude_artifact_comment_id: optional string or null`
+
+ The comment's identifier. Present when the activity relates to a specific comment, for example a new comment, an author's edit of one, or an existing comment sent to Claude or withdrawn from Claude; absent for thread-level actions performed without a comment, such as resolve, reopen, deletion, an activation change, or a resolve by a Claude session.
+
+ - `claude_artifact_comment_thread_id: optional string or null`
+
+ The comment thread's identifier.
+
+ - `claude_artifact_version_id: optional string or null`
+
+ The artifact version the comment activity applied to, when known.
+
- `created_at: optional string`
When this activity occurred.
@@ -131700,13 +133206,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `AnonymousMobileLoginAttempted object`
+ - `ClaudeArtifactCommentsViewed object`
- Anonymous mobile login was attempted.
+ An artifact's comments were viewed.
- - `type: optional "anonymous_mobile_login_attempted"`
+ - `type: optional "claude_artifact_comments_viewed"`
- default: anonymous_mobile_login_attempted
+ default: claude_artifact_comments_viewed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -131914,10 +133420,18 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `claude_artifact_id: string`
+
+ The artifact's identifier.
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `claude_artifact_version_id: optional string or null`
+
+ The version of the artifact whose comments were served, when known.
+
- `created_at: optional string`
When this activity occurred.
@@ -131932,13 +133446,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `APIKeyCreated object`
+ - `ClaudeArtifactCreated object`
- Activity logged when a new API key is created.
+ An artifact was created.
- - `type: optional "api_key_created"`
+ - `type: optional "claude_artifact_created"`
- default: api_key_created
+ default: claude_artifact_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -132146,9 +133660,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `api_key_id: string`
+ - `claude_artifact_id: string`
- The tagged ID of the created API key
+ Tagged ID of the artifact that was created, e.g. "claude_artifact_01HX...".
- `id: optional string`
@@ -132168,21 +133682,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `restricted_to_organization: optional boolean or null`
-
- Whether the key was restricted to the creating organization, rather than granted access across the whole parent organization
-
- - `scopes: optional array of string`
-
- The scopes for this API key
-
- - `ClaudeArtifactAccessFailed object`
+ - `ClaudePublishedArtifactDeleted object`
- An attempt to access an artifact failed.
+ A published artifact was deleted or unpublished — by its creator, by an organization admin, or by Anthropic (for example, when it was removed for a policy violation).
- - `type: optional "claude_artifact_access_failed"`
+ - `type: optional "claude_published_artifact_deleted"`
- default: claude_artifact_access_failed
+ default: claude_published_artifact_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -132390,17 +133896,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `id: optional string`
-
- Unique identifier for the activity e.g. 'activity_abcd1234'
-
- - `claude_artifact_id: optional string or null`
+ - `claude_published_artifact_id: string`
- The artifact's identifier, when known.
+ The published artifact's identifier.
- - `claude_artifact_version_id: optional string or null`
+ - `id: optional string`
- The version of the artifact the user attempted to access, when known.
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -132416,17 +133918,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `reason: optional string or null`
-
- The reason access was denied, when recorded.
-
- - `ClaudeArtifactCommented object`
+ - `ClaudeArtifactPublished object`
- Comment activity on a published artifact: a comment was added, a thread's resolved state was changed, or a thread was deleted. The actor is the user who performed the action; the comment text itself is stored with the artifact and is not part of this record.
+ A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded on every save, including saves of private artifacts, and changes to who can access the artifact are recorded separately as claude_artifact_sharing_updated.
- - `type: optional "claude_artifact_commented"`
+ - `type: optional "claude_artifact_published"`
- default: claude_artifact_commented
+ default: claude_artifact_published
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -132634,55 +134132,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_artifact_id: string`
-
- The artifact's identifier.
-
- - `comment_action: "activate_thread" or "create_thread" or "deactivate_thread" or 10 more`
-
- The action recorded: for example a new comment thread, a reply to an existing thread, a thread resolved, reopened, or deleted, a thread's Claude activation granted or revoked, a comment's text rewritten by its author, an existing comment sent to Claude or withdrawn from Claude, or a thread resolved by a Claude session.
-
- - `"activate_thread"`
-
- - `"create_thread"`
-
- - `"deactivate_thread"`
-
- - `"delete_thread"`
-
- - `"edit_comment"`
-
- - `"move_thread"`
-
- - `"reopen"`
-
- - `"reply"`
+ - `artifact_type: string`
- - `"resolve"`
+ Artifact type (code, html, react, etc.)
- - `"send_to_claude"`
+ - `claude_published_artifact_id: string`
- - `"session_resolve"`
+ The published artifact's identifier.
- - `"unsend_to_claude"`
+ - `title: string`
- - `"unspecified"`
+ Title of the published artifact
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `claude_artifact_comment_id: optional string or null`
-
- The comment's identifier. Present when the activity relates to a specific comment, for example a new comment, an author's edit of one, or an existing comment sent to Claude or withdrawn from Claude; absent for thread-level actions performed without a comment, such as resolve, reopen, deletion, an activation change, or a resolve by a Claude session.
-
- - `claude_artifact_comment_thread_id: optional string or null`
-
- The comment thread's identifier.
-
- `claude_artifact_version_id: optional string or null`
- The artifact version the comment activity applied to, when known.
+ The version identifier recorded as live by this publish.
- `created_at: optional string`
@@ -132690,6 +134158,14 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `description: optional string or null`
+
+ No longer populated: the gallery-card description supplied at publish time is intentionally omitted from this feed.
+
+ - `is_redeploy: optional boolean or null`
+
+ True when the publish updated an existing artifact; false when the publish created the artifact.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -132698,13 +134174,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeArtifactCommentsViewed object`
+ - `ClaudeArtifactSharingUpdated object`
- An artifact's comments were viewed.
+ An artifact's sharing settings were updated.
- - `type: optional "claude_artifact_comments_viewed"`
+ - `type: optional "claude_artifact_sharing_updated"`
- default: claude_artifact_comments_viewed
+ default: claude_artifact_sharing_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -132912,17 +134388,45 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `audience: array of Organization or Users or AnyoneWithLink`
+
+ The artifact's sharing audience after the change. If empty, the artifact is visible only to its owner.
+
+ - `Organization object`
+
+ Sharing audience: visible to the owning organization.
+
+ - `type: optional "organization"`
+
+ default: organization
+
+ - `Users object`
+
+ Sharing audience: visible to an explicit allowlist of users.
+
+ - `type: optional "users"`
+
+ default: users
+
+ - `AnyoneWithLink object`
+
+ Sharing audience: anyone with the link, including anonymous viewers (an artifact shared to the open internet).
+
+ - `type: optional "anyone_with_link"`
+
+ default: anyone_with_link
+
- `claude_artifact_id: string`
The artifact's identifier.
- - `id: optional string`
+ - `claude_artifact_version_id: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ The artifact version's identifier.
- - `claude_artifact_version_id: optional string or null`
+ - `id: optional string`
- The version of the artifact whose comments were served, when known.
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -132930,6 +134434,22 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `new_mode: optional string or null`
+
+ The read-axis sharing mode after the change: `owner`, `users`, `org`, or `public` (anyone on the internet).
+
+ - `new_user_count: optional number or null`
+
+ The number of accounts on the explicit read allowlist after the change. Only meaningful when `new_mode` is `users`.
+
+ - `new_write_mode: optional string or null`
+
+ The write-axis sharing mode after the change: `owner`, `users`, or `org`.
+
+ - `new_write_user_count: optional number or null`
+
+ The number of accounts on the explicit write allowlist after the change. Only meaningful when `new_write_mode` is `users`.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -132938,13 +134458,29 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeArtifactCreated object`
+ - `previous_mode: optional string or null`
- An artifact was created.
+ The read-axis sharing mode before the change: `owner`, `users`, `org`, or `public` (anyone on the internet).
- - `type: optional "claude_artifact_created"`
+ - `previous_user_count: optional number or null`
- default: claude_artifact_created
+ The number of accounts on the explicit read allowlist before the change. Only meaningful when `previous_mode` is `users`.
+
+ - `previous_write_mode: optional string or null`
+
+ The write-axis sharing mode before the change: `owner`, `users`, or `org`.
+
+ - `previous_write_user_count: optional number or null`
+
+ The number of accounts on the explicit write allowlist before the change. Only meaningful when `previous_write_mode` is `users`.
+
+ - `ClaudeArtifactViewed object`
+
+ An artifact was viewed.
+
+ - `type: optional "claude_artifact_viewed"`
+
+ default: claude_artifact_viewed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -133154,12 +134690,16 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `claude_artifact_id: string`
- Tagged ID of the artifact that was created, e.g. "claude_artifact_01HX...".
+ The artifact's identifier.
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `claude_artifact_version_id: optional string or null`
+
+ The version of the artifact the user was served, when known.
+
- `created_at: optional string`
When this activity occurred.
@@ -133174,13 +134714,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudePublishedArtifactDeleted object`
+ - `AuditLogExportAccessed object`
- A published artifact was deleted or unpublished — by its creator, by an organization admin, or by Anthropic (for example, when it was removed for a policy violation).
+ Audit log export file was accessed/downloaded via signed URL.
- - `type: optional "claude_published_artifact_deleted"`
+ - `type: optional "audit_log_export_accessed"`
- default: claude_published_artifact_deleted
+ default: audit_log_export_accessed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -133388,10 +134928,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_published_artifact_id: string`
-
- The published artifact's identifier.
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -133410,13 +134946,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeArtifactPublished object`
+ - `AuditLogExportStarted object`
- A new version of an artifact was published — for an artifact created in a chat this is the action that made it publicly viewable; for an artifact created outside a chat it is recorded on every save, including saves of private artifacts, and changes to who can access the artifact are recorded separately as claude_artifact_sharing_updated.
+ Audit log export was initiated.
- - `type: optional "claude_artifact_published"`
+ - `type: optional "audit_log_export_started"`
- default: claude_artifact_published
+ default: audit_log_export_started
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -133624,25 +135160,253 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `artifact_type: string`
+ - `id: optional string`
- Artifact type (code, html, react, etc.)
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- - `claude_published_artifact_id: string`
+ - `created_at: optional string`
- The published artifact's identifier.
+ When this activity occurred.
- - `title: string`
+ format: date-time
- Title of the published artifact
+ - `from_date: optional string or null`
+
+ Start date of the export range
+
+ - `organization_id: optional string or null`
+
+ Organization ID this activity is associated with
+
+ - `organization_uuid: optional string or null`
+
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+
+ - `to_date: optional string or null`
+
+ End date of the export range
+
+ - `BillingEmailsUpdated object`
+
+ The organization's billing email recipients were updated.
+
+ - `type: optional "billing_emails_updated"`
+
+ default: billing_emails_updated
+
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+
+ - `APIActor object`
+
+ - `type: optional "api_actor"`
+
+ default: api_actor
+
+ - `api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `UserActor object`
+
+ - `type: optional "user_actor"`
+
+ default: user_actor
+
+ - `email_address: string`
+
+ format: email
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `user_id: string`
+
+ - `UnauthenticatedUserActor object`
+
+ - `type: optional "unauthenticated_user_actor"`
+
+ default: unauthenticated_user_actor
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `unauthenticated_email_address: optional string or null`
+
+ format: email
+
+ - `AnthropicActor object`
+
+ - `type: optional "anthropic_actor"`
+
+ default: anthropic_actor
+
+ - `email_address: optional string or null`
+
+ format: email
+
+ - `SystemActor object`
+
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
+
+ - `type: optional "system_actor"`
+
+ default: system_actor
+
+ - `service: optional string or null`
+
+ Name of the automated process that performed the action, when known.
+
+ - `AdminAPIKeyActor object`
+
+ - `type: optional "admin_api_key_actor"`
+
+ default: admin_api_key_actor
+
+ - `admin_api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `ServiceAccountActor object`
+
+ - `type: optional "service_account_actor"`
+
+ default: service_account_actor
+
+ - `ip_address: string`
+
+ - `service_account_id: string`
+
+ - `user_agent: string`
+
+ - `ScimDirectorySyncActor object`
+
+ - `type: optional "scim_directory_sync_actor"`
+
+ default: scim_directory_sync_actor
+
+ - `directory_id: string`
+
+ - `workos_event_id: string`
+
+ - `idp_connection_type: optional string or null`
+
+ - `FederatedIdentityActor object`
+
+ A federated external workload authenticated via a verified OIDC token.
+
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
+
+ - `type: optional "federated_identity_actor"`
+
+ default: federated_identity_actor
+
+ - `issuer: string`
+
+ - `subject: string`
+
+ - `audience: optional array of string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `FederatedActor object`
+
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
+
+ - `type: optional "federated_actor"`
+
+ default: federated_actor
+
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+
+ - `FederatedActorAwsProvider object`
+
+ Asserting party: the AWS account the organization is bound to.
+
+ - `type: optional "aws"`
+
+ default: aws
+
+ - `account_id: string`
+
+ - `signed_principal: string`
+
+ The AWS-signed ARN of the IAM principal that requested the token.
+
+ - `FederatedActorAzureProvider object`
+
+ Asserting party: the Azure subscription the organization is bound to.
+
+ - `type: optional "azure"`
+
+ default: azure
+
+ - `subscription_id: string`
+
+ - `FederatedActorGcpProvider object`
+
+ Asserting party: the GCP project the organization is bound to.
+
+ - `type: optional "gcp"`
+
+ default: gcp
+
+ - `project_number: string`
+
+ - `FederatedActorOidcProvider object`
+
+ Asserting party: a customer-registered OIDC federation issuer.
+
+ - `type: optional "oidc"`
+
+ default: oidc
+
+ - `issuer: optional string or null`
+
+ The federation issuer's URL. Null when the presented credential failed verification.
+
+ - `ip_address: optional string or null`
+
+ - `subject: optional string or null`
+
+ The provider's verified identifier for the caller; its form depends on the provider.
+
+ - `user_agent: optional string or null`
+
+ - `AttestedDeviceActor object`
+
+ An attested mobile device authenticated via Apple App Attest.
+
+ - `type: optional "attested_device_actor"`
+
+ default: attested_device_actor
+
+ - `external_client_id: string`
+
+ - `kid_hash: string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `claude_artifact_version_id: optional string or null`
+ - `cc_email_count: optional number or null`
- The version identifier recorded as live by this publish.
+ Number of 'cc' email recipients.
- `created_at: optional string`
@@ -133650,14 +135414,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `description: optional string or null`
-
- No longer populated: the gallery-card description supplied at publish time is intentionally omitted from this feed.
-
- - `is_redeploy: optional boolean or null`
-
- True when the publish updated an existing artifact; false when the publish created the artifact.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -133666,13 +135422,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeArtifactSharingUpdated object`
+ - `primary_email_set: optional boolean or null`
- An artifact's sharing settings were updated.
+ Whether a primary billing email is configured.
- - `type: optional "claude_artifact_sharing_updated"`
+ - `to_email_count: optional number or null`
- default: claude_artifact_sharing_updated
+ Number of 'to' email recipients.
+
+ - `CcrAgentCreated object`
+
+ A Claude Code agent was created.
+
+ - `type: optional "ccr_agent_created"`
+
+ default: ccr_agent_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -133880,41 +135644,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `audience: array of Organization or Users or AnyoneWithLink`
-
- The artifact's sharing audience after the change. If empty, the artifact is visible only to its owner.
-
- - `Organization object`
-
- Sharing audience: visible to the owning organization.
-
- - `type: optional "organization"`
-
- default: organization
-
- - `Users object`
-
- Sharing audience: visible to an explicit allowlist of users.
-
- - `type: optional "users"`
+ - `agent_id: string`
- default: users
+ The agent that was created, e.g. "cagt_01HX...".
- - `AnyoneWithLink object`
+ - `default_source_urls_truncated: boolean`
- Sharing audience: anyone with the link, including anonymous viewers (an artifact shared to the open internet).
+ Whether default_source_urls was capped and omits some of the granted repositories.
- - `type: optional "anyone_with_link"`
+ - `display_name: string`
- default: anyone_with_link
+ The agent's display name at creation time.
- - `claude_artifact_id: string`
+ - `omitted_source_url_count: number`
- The artifact's identifier.
+ Number of default repository entries that could not be safely rendered as a credential-free URL and were omitted from default_source_urls. A non-zero value with an empty list means repositories were granted but could not be displayed — not that all repositories were removed.
- - `claude_artifact_version_id: string`
+ - `slug: string`
- The artifact version's identifier.
+ The agent's URL-safe identifier, unique within the organization.
- `id: optional string`
@@ -133926,21 +135674,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `new_mode: optional string or null`
-
- The read-axis sharing mode after the change: `owner`, `users`, `org`, or `public` (anyone on the internet).
-
- - `new_user_count: optional number or null`
-
- The number of accounts on the explicit read allowlist after the change. Only meaningful when `new_mode` is `users`.
-
- - `new_write_mode: optional string or null`
+ - `default_source_urls: optional array of string`
- The write-axis sharing mode after the change: `owner`, `users`, or `org`.
+ The repository URLs the agent works on by default, reduced to scheme, host, and path — credentials and query parameters are never included. Empty with a zero omitted_source_url_count means the agent was created without any default repositories; empty with a non-zero count means repositories were granted but could not be safely rendered. At most 100 entries are included; default_source_urls_truncated indicates when more were granted.
- - `new_write_user_count: optional number or null`
+ - `guest_policy: optional string or null`
- The number of accounts on the explicit write allowlist after the change. Only meaningful when `new_write_mode` is `users`.
+ Whether the agent responds in Slack channels that include guest users, and in Slack Connect channels shared with other organizations: "allow", "restrict", or "channel" (the agent responds, using only that channel's own content and configuration). In Slack Connect channels "allow" gives at most "channel" access. Omitted when the agent inherits the default policy.
- `organization_id: optional string or null`
@@ -133950,29 +135690,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_mode: optional string or null`
-
- The read-axis sharing mode before the change: `owner`, `users`, `org`, or `public` (anyone on the internet).
-
- - `previous_user_count: optional number or null`
-
- The number of accounts on the explicit read allowlist before the change. Only meaningful when `previous_mode` is `users`.
-
- - `previous_write_mode: optional string or null`
-
- The write-axis sharing mode before the change: `owner`, `users`, or `org`.
-
- - `previous_write_user_count: optional number or null`
+ - `slack_alias: optional string or null`
- The number of accounts on the explicit write allowlist before the change. Only meaningful when `previous_write_mode` is `users`.
+ The Slack trigger word that routes mentions to this agent. An empty value means the agent responds to bare "@Claude" mentions. Omitted when the agent is not addressable from Slack.
- - `ClaudeArtifactViewed object`
+ - `CcrAgentDeleted object`
- An artifact was viewed.
+ A Claude Code agent was deleted.
- - `type: optional "claude_artifact_viewed"`
+ - `type: optional "ccr_agent_deleted"`
- default: claude_artifact_viewed
+ default: ccr_agent_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -134180,17 +135908,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_artifact_id: string`
+ - `agent_id: string`
- The artifact's identifier.
+ The agent that was deleted, e.g. "cagt_01HX...".
+
+ - `cascaded_agent_ids_truncated: boolean`
+
+ True when more agents were deleted in this cascade than are individually recorded. On a cascade parent event (cascaded_from_agent_id unset), cascaded_agent_ids is capped at 100. On a cascade child event (cascaded_from_agent_id set, emitted when the parent deletion failed after committing child deletions), one event is emitted per deleted child up to 100, and this field indicates additional children were deleted in the same cascade.
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `claude_artifact_version_id: optional string or null`
+ - `cascaded_agent_ids: optional array of string`
- The version of the artifact the user was served, when known.
+ Agents assigned to individual Slack channels that were also deleted because agent_id was the agent assigned to their entire Slack workspace. Empty when no such agents were deleted, and always empty on a cascade child event (cascaded_from_agent_id set) — the child's siblings are recorded as their own events, not listed here. Capped at 100 entries; cascaded_agent_ids_truncated is set when the actual count exceeded the cap.
+
+ - `cascaded_from_agent_id: optional string or null`
+
+ When set, the Slack workspace's dedicated agent whose deletion attempt caused this agent to be deleted. The parent's own deletion may have failed after the cascade committed — check for a separate event with agent_id = cascaded_from_agent_id to confirm. Unset on a direct deletion.
- `created_at: optional string`
@@ -134206,13 +135942,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `AuditLogExportAccessed object`
+ - `CcrAgentProxyAnthropicOidcTokenExchanged object`
- Audit log export file was accessed/downloaded via signed URL.
+ The Claude Code agent proxy exchanged a minted identity token for short-lived credentials in the organization's own cloud. Recorded for exchange targets only (such as "aws" and "gcp"; the "direct" target has no exchange step). One event is recorded per exchange call; a request served from the proxy's exchanged-credential cache does not exchange again and is not recorded here. Per-request detail for traffic the credentials were injected into is available in the agent proxy network events.
- - `type: optional "audit_log_export_accessed"`
+ - `type: optional "ccr_agent_proxy_anthropic_oidc_token_exchanged"`
- default: audit_log_export_accessed
+ default: ccr_agent_proxy_anthropic_oidc_token_exchanged
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -134420,6 +136156,38 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `agent_id: string`
+
+ The Claude Code agent that owns the session, e.g. "cagt_01HX...". Empty when the session is not owned by an agent.
+
+ - `credential_id: string`
+
+ The credential row the exchange ran for, e.g. "apc_01HX...".
+
+ - `profile_id: string`
+
+ The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
+
+ - `role_arn: string`
+
+ The IAM role the token was exchanged for ("aws" target), e.g. "arn:aws:iam::123456789012:role/example-role". Empty for other targets.
+
+ - `role_session_name: string`
+
+ The role session name the temporary credentials were issued under ("aws" target), matching the session name recorded in the organization's own AWS CloudTrail log. Empty for other targets.
+
+ - `service_account: string`
+
+ The Google Cloud service account the federated token was exchanged into ("gcp" target), e.g. "example@example-project.iam.gserviceaccount.com". Empty when the federated token was used directly, and for other targets.
+
+ - `session_id: string`
+
+ The Claude Code session whose request triggered the exchange, e.g. "cse_01HX..." or "session_01HX..." (the session's ID is carried in whichever tagged form the session's credential presented).
+
+ - `target: string`
+
+ The credential's configured target, e.g. "aws" or "gcp".
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -134430,6 +136198,12 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `credentials_expire_at: optional string or null`
+
+ When the exchanged cloud credentials expire. Unset when the cloud provider did not return a lifetime; such credentials were used for the single triggering request and not cached.
+
+ format: date-time
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -134438,13 +136212,33 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `AuditLogExportStarted object`
+ - `slack_threads: optional array of object`
- Audit log export was initiated.
+ The Slack threads in the session's provenance, when the session originated from Slack. At most 64 entries are included.
- - `type: optional "audit_log_export_started"`
+ - `channel_id: string`
- default: audit_log_export_started
+ The Slack channel ID, e.g. "C0123ABCDE".
+
+ - `enterprise_id: string`
+
+ The Slack Enterprise Grid organization ID, e.g. "E0123ABCDE". Empty for workspaces that are not part of an Enterprise Grid.
+
+ - `team_id: string`
+
+ The Slack workspace (team) ID, e.g. "T0123ABCDE".
+
+ - `thread_ts: string`
+
+ The Slack thread timestamp within the channel, e.g. "1714000000.123456". Empty for a session bound to a whole channel rather than to one thread.
+
+ - `CcrAgentProxyAnthropicOidcTokenMinted object`
+
+ The Claude Code agent proxy minted a short-lived identity token for an anthropic_oidc credential. One event is recorded per fresh token issuance; a request served from the proxy's short-lived token cache does not mint a new token and is not recorded here. Per-request detail for traffic the credential was injected into is available in the agent proxy network events.
+
+ - `type: optional "ccr_agent_proxy_anthropic_oidc_token_minted"`
+
+ default: ccr_agent_proxy_anthropic_oidc_token_minted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -134652,6 +136446,54 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `agent_id: string`
+
+ The Claude Code agent that owns the session, e.g. "cagt_01HX...". Empty when the session is not owned by an agent.
+
+ - `audience: string`
+
+ The minted token's audience: the fixed token-exchange audience for the "aws" target, the credential row's Google workload identity pool provider URL for the "gcp" target, or the row's configured audience for the "direct" target.
+
+ - `credential_id: string`
+
+ The credential row the token was minted for, e.g. "apc_01HX...".
+
+ - `issuance_path: "broker_report" or "direct" or "proxy_record" or "unspecified"`
+
+ Which record of the issuance this event is. Unspecified on events published before this field existed.
+
+ - `"broker_report"`
+
+ - `"direct"`
+
+ - `"proxy_record"`
+
+ - `"unspecified"`
+
+ - `mint_jti: string`
+
+ The identifier of the mint attempt, a bare UUID. One mint through the Claude Tag mint broker produces two minted events that carry the same value, the broker's own report and the agent proxy's record. A reader counts issuances from the broker's reports by distinct report_id, and several distinct reports that share one mint_jti are the accepted mints of a replayed token. Empty on events for mints that did not travel through the broker.
+
+ - `profile_id: string`
+
+ The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
+
+ - `report_id: string`
+
+ The identity of the mint broker's report itself, a bare UUID. The broker mints it once per report and delivery retries repeat it, so several events carrying one report_id are duplicates of one report and collapse to one issuance. Present on broker_report events only.
+
+ - `session_id: string`
+
+ The Claude Code session whose request triggered the mint, e.g. "cse_01HX..." or "session_01HX..." (the session's ID is carried in whichever tagged form the session's credential presented).
+
+ - `target: string`
+
+ The credential's configured target, e.g. "aws", "gcp", or "direct".
+
+ - `test_mint: string`
+
+ Set when the token was minted by the gateway verification test that runs while an admin registers a custom-gateway audience: "wrong_subject" for the probe token the gateway must reject, "right_subject" for the control token it must accept. Empty for tokens minted for live sessions.
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -134662,10 +136504,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `from_date: optional string or null`
-
- Start date of the export range
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -134674,17 +136512,39 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `to_date: optional string or null`
+ - `slack_threads: optional array of object`
- End date of the export range
+ The Slack threads in the session's provenance, when the session originated from Slack. At most 64 entries are included.
- - `BillingEmailsUpdated object`
+ - `channel_id: string`
- The organization's billing email recipients were updated.
+ The Slack channel ID, e.g. "C0123ABCDE".
- - `type: optional "billing_emails_updated"`
+ - `enterprise_id: string`
- default: billing_emails_updated
+ The Slack Enterprise Grid organization ID, e.g. "E0123ABCDE". Empty for workspaces that are not part of an Enterprise Grid.
+
+ - `team_id: string`
+
+ The Slack workspace (team) ID, e.g. "T0123ABCDE".
+
+ - `thread_ts: string`
+
+ The Slack thread timestamp within the channel, e.g. "1714000000.123456". Empty for a session bound to a whole channel rather than to one thread.
+
+ - `token_expires_at: optional string or null`
+
+ When the minted token expires.
+
+ format: date-time
+
+ - `CcrAgentProxyCredentialCreated object`
+
+ A Claude Code agent proxy credential was created. Credentials hold the secrets the agent proxy injects into requests Claude Code sessions send to approved external services; each credential belongs to an agent proxy profile. Audit events carry only credential names and settings, never the secret material itself.
+
+ - `type: optional "ccr_agent_proxy_credential_created"`
+
+ default: ccr_agent_proxy_credential_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -134892,13 +136752,61 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `credential_id: string`
+
+ The credential that was created, e.g. "apc_01HX...".
+
+ - `credential_type: string`
+
+ The kind of credential, e.g. "bearer", "basic", "github_app", "mtls".
+
+ - `display_name: string`
+
+ The credential's display name.
+
+ - `host_constraint_truncated: boolean`
+
+ Whether host_constraint was capped and omits some of the configured host name patterns.
+
+ - `profile_id: string`
+
+ The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `cc_email_count: optional number or null`
+ - `authorization_basis: optional object or null`
- Number of 'cc' email recipients.
+ CcrAgentProxyCredentialAuthorizationBasis records how the actor was authorized to perform a Claude Code agent proxy credential operation. Populated only when the operation was authorized against a specific actor's permissions; absent on system-initiated operations (for example, an automatic token rotation) and on operations authorized by a provisioning link rather than the actor's own permissions.
+
+ - `slack_channel_id: string`
+
+ The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".
+
+ - `slack_enterprise_id: string`
+
+ The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.
+
+ - `slack_team_id: string`
+
+ The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".
+
+ - `via_entitlement_leg: boolean`
+
+ True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.
+
+ - `via_full_manage: boolean`
+
+ True when the actor held the organization-wide Claude Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel `claude_tag_channel:manage` permission or, when `via_account_assignment` is true, via a direct channel-manager assignment.
+
+ - `granting_role_ids: optional array of string`
+
+ The tagged IDs of the custom roles that granted the actor the per-channel `claude_tag_channel:manage` permission, e.g. "rbac_role_01HX...". Empty when `via_full_manage` is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when `via_account_assignment` is true (no role stands behind a direct assignment).
+
+ - `via_account_assignment: optional boolean or null`
+
+ True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, `via_full_manage` and `via_entitlement_leg` are false and `granting_role_ids` is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.
- `created_at: optional string`
@@ -134906,6 +136814,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `host_constraint: optional array of string`
+
+ The host name patterns the credential may be sent to, e.g. "api.example.com" or "*.example.com". At most 100 entries are included; host_constraint_truncated indicates when the configured set is larger.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -134914,21 +136826,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `primary_email_set: optional boolean or null`
-
- Whether a primary billing email is configured.
-
- - `to_email_count: optional number or null`
-
- Number of 'to' email recipients.
-
- - `CcrAgentCreated object`
+ - `CcrAgentProxyCredentialDeleted object`
- A Claude Code agent was created.
+ A Claude Code agent proxy credential was deleted. Its secret material was removed and can no longer be sent to any host.
- - `type: optional "ccr_agent_created"`
+ - `type: optional "ccr_agent_proxy_credential_deleted"`
- default: ccr_agent_created
+ default: ccr_agent_proxy_credential_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -135136,43 +137040,55 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `agent_id: string`
+ - `credential_id: string`
- The agent that was created, e.g. "cagt_01HX...".
+ The credential that was deleted, e.g. "apc_01HX...".
- - `default_source_urls_truncated: boolean`
+ - `profile_id: string`
- Whether default_source_urls was capped and omits some of the granted repositories.
+ The agent proxy profile the credential belonged to, e.g. "capp_01HX...". Carried so the deletion can be correlated with the profile's other audit events after the credential row no longer exists.
- - `display_name: string`
+ - `id: optional string`
- The agent's display name at creation time.
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- - `omitted_source_url_count: number`
+ - `authorization_basis: optional object or null`
- Number of default repository entries that could not be safely rendered as a credential-free URL and were omitted from default_source_urls. A non-zero value with an empty list means repositories were granted but could not be displayed — not that all repositories were removed.
+ CcrAgentProxyCredentialAuthorizationBasis records how the actor was authorized to perform a Claude Code agent proxy credential operation. Populated only when the operation was authorized against a specific actor's permissions; absent on system-initiated operations (for example, an automatic token rotation) and on operations authorized by a provisioning link rather than the actor's own permissions.
- - `slug: string`
+ - `slack_channel_id: string`
- The agent's URL-safe identifier, unique within the organization.
+ The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".
- - `id: optional string`
+ - `slack_enterprise_id: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.
- - `created_at: optional string`
+ - `slack_team_id: string`
- When this activity occurred.
+ The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".
- format: date-time
+ - `via_entitlement_leg: boolean`
- - `default_source_urls: optional array of string`
+ True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.
- The repository URLs the agent works on by default, reduced to scheme, host, and path — credentials and query parameters are never included. Empty with a zero omitted_source_url_count means the agent was created without any default repositories; empty with a non-zero count means repositories were granted but could not be safely rendered. At most 100 entries are included; default_source_urls_truncated indicates when more were granted.
+ - `via_full_manage: boolean`
- - `guest_policy: optional string or null`
+ True when the actor held the organization-wide Claude Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel `claude_tag_channel:manage` permission or, when `via_account_assignment` is true, via a direct channel-manager assignment.
- Whether the agent responds in Slack channels that include guest users, and in Slack Connect channels shared with other organizations: "allow", "restrict", or "channel" (the agent responds, using only that channel's own content and configuration). In Slack Connect channels "allow" gives at most "channel" access. Omitted when the agent inherits the default policy.
+ - `granting_role_ids: optional array of string`
+
+ The tagged IDs of the custom roles that granted the actor the per-channel `claude_tag_channel:manage` permission, e.g. "rbac_role_01HX...". Empty when `via_full_manage` is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when `via_account_assignment` is true (no role stands behind a direct assignment).
+
+ - `via_account_assignment: optional boolean or null`
+
+ True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, `via_full_manage` and `via_entitlement_leg` are false and `granting_role_ids` is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.
+
+ - `created_at: optional string`
+
+ When this activity occurred.
+
+ format: date-time
- `organization_id: optional string or null`
@@ -135182,17 +137098,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `slack_alias: optional string or null`
-
- The Slack trigger word that routes mentions to this agent. An empty value means the agent responds to bare "@Claude" mentions. Omitted when the agent is not addressable from Slack.
-
- - `CcrAgentDeleted object`
+ - `CcrAgentProxyCredentialRotated object`
- A Claude Code agent was deleted.
+ A Claude Code agent proxy credential's secret material was replaced. The replacement keeps the same name, profile, and allowed hosts under a new credential identifier, and everything that referenced the old credential now uses the replacement.
- - `type: optional "ccr_agent_deleted"`
+ - `type: optional "ccr_agent_proxy_credential_rotated"`
- default: ccr_agent_deleted
+ default: ccr_agent_proxy_credential_rotated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -135400,25 +137312,69 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `agent_id: string`
+ - `credential_id: string`
- The agent that was deleted, e.g. "cagt_01HX...".
+ The replacement credential, e.g. "apc_01HX...".
- - `cascaded_agent_ids_truncated: boolean`
+ - `credential_type: string`
- True when more agents were deleted in this cascade than are individually recorded. On a cascade parent event (cascaded_from_agent_id unset), cascaded_agent_ids is capped at 100. On a cascade child event (cascaded_from_agent_id set, emitted when the parent deletion failed after committing child deletions), one event is emitted per deleted child up to 100, and this field indicates additional children were deleted in the same cascade.
+ The kind of credential, e.g. "bearer", "basic", "github_app", "mtls".
+
+ - `destinations_repointed: number`
+
+ The number of agent proxy destinations that referenced the old credential and now reference the replacement.
+
+ - `display_name: string`
+
+ The credential's display name.
+
+ - `previous_credential_id: string`
+
+ The credential that was replaced, e.g. "apc_01HX...".
+
+ - `profile_id: string`
+
+ The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
+
+ - `rules_repointed: number`
+
+ The number of agent proxy rules that referenced the old credential and now reference the replacement.
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `cascaded_agent_ids: optional array of string`
+ - `authorization_basis: optional object or null`
- Agents assigned to individual Slack channels that were also deleted because agent_id was the agent assigned to their entire Slack workspace. Empty when no such agents were deleted, and always empty on a cascade child event (cascaded_from_agent_id set) — the child's siblings are recorded as their own events, not listed here. Capped at 100 entries; cascaded_agent_ids_truncated is set when the actual count exceeded the cap.
+ CcrAgentProxyCredentialAuthorizationBasis records how the actor was authorized to perform a Claude Code agent proxy credential operation. Populated only when the operation was authorized against a specific actor's permissions; absent on system-initiated operations (for example, an automatic token rotation) and on operations authorized by a provisioning link rather than the actor's own permissions.
- - `cascaded_from_agent_id: optional string or null`
+ - `slack_channel_id: string`
- When set, the Slack workspace's dedicated agent whose deletion attempt caused this agent to be deleted. The parent's own deletion may have failed after the cascade committed — check for a separate event with agent_id = cascaded_from_agent_id to confirm. Unset on a direct deletion.
+ The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".
+
+ - `slack_enterprise_id: string`
+
+ The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.
+
+ - `slack_team_id: string`
+
+ The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".
+
+ - `via_entitlement_leg: boolean`
+
+ True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.
+
+ - `via_full_manage: boolean`
+
+ True when the actor held the organization-wide Claude Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel `claude_tag_channel:manage` permission or, when `via_account_assignment` is true, via a direct channel-manager assignment.
+
+ - `granting_role_ids: optional array of string`
+
+ The tagged IDs of the custom roles that granted the actor the per-channel `claude_tag_channel:manage` permission, e.g. "rbac_role_01HX...". Empty when `via_full_manage` is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when `via_account_assignment` is true (no role stands behind a direct assignment).
+
+ - `via_account_assignment: optional boolean or null`
+
+ True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, `via_full_manage` and `via_entitlement_leg` are false and `granting_role_ids` is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.
- `created_at: optional string`
@@ -135434,13 +137390,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyAnthropicOidcTokenExchanged object`
+ - `CcrAgentProxyCredentialUpdated object`
- The Claude Code agent proxy exchanged a minted identity token for short-lived credentials in the organization's own cloud. Recorded for exchange targets only (such as "aws" and "gcp"; the "direct" target has no exchange step). One event is recorded per exchange call; a request served from the proxy's exchanged-credential cache does not exchange again and is not recorded here. Per-request detail for traffic the credentials were injected into is available in the agent proxy network events.
+ A Claude Code agent proxy credential's settings were updated. Only the display name and the allowed host patterns can be updated; the secret material can only be replaced through a rotation.
- - `type: optional "ccr_agent_proxy_anthropic_oidc_token_exchanged"`
+ - `type: optional "ccr_agent_proxy_credential_updated"`
- default: ccr_agent_proxy_anthropic_oidc_token_exchanged
+ default: ccr_agent_proxy_credential_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -135648,41 +137604,57 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `agent_id: string`
+ - `credential_id: string`
- The Claude Code agent that owns the session, e.g. "cagt_01HX...". Empty when the session is not owned by an agent.
+ The credential that was updated, e.g. "apc_01HX...".
- - `credential_id: string`
+ - `display_name: string`
- The credential row the exchange ran for, e.g. "apc_01HX...".
+ The credential's display name after the update.
+
+ - `host_constraint_truncated: boolean`
+
+ Whether host_constraint was capped and omits some of the configured host name patterns.
- `profile_id: string`
The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
- - `role_arn: string`
+ - `id: optional string`
- The IAM role the token was exchanged for ("aws" target), e.g. "arn:aws:iam::123456789012:role/example-role". Empty for other targets.
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- - `role_session_name: string`
+ - `authorization_basis: optional object or null`
- The role session name the temporary credentials were issued under ("aws" target), matching the session name recorded in the organization's own AWS CloudTrail log. Empty for other targets.
+ CcrAgentProxyCredentialAuthorizationBasis records how the actor was authorized to perform a Claude Code agent proxy credential operation. Populated only when the operation was authorized against a specific actor's permissions; absent on system-initiated operations (for example, an automatic token rotation) and on operations authorized by a provisioning link rather than the actor's own permissions.
- - `service_account: string`
+ - `slack_channel_id: string`
- The Google Cloud service account the federated token was exchanged into ("gcp" target), e.g. "example@example-project.iam.gserviceaccount.com". Empty when the federated token was used directly, and for other targets.
+ The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".
- - `session_id: string`
+ - `slack_enterprise_id: string`
- The Claude Code session whose request triggered the exchange, e.g. "cse_01HX..." or "session_01HX..." (the session's ID is carried in whichever tagged form the session's credential presented).
+ The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.
- - `target: string`
+ - `slack_team_id: string`
- The credential's configured target, e.g. "aws" or "gcp".
+ The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".
- - `id: optional string`
+ - `via_entitlement_leg: boolean`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.
+
+ - `via_full_manage: boolean`
+
+ True when the actor held the organization-wide Claude Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel `claude_tag_channel:manage` permission or, when `via_account_assignment` is true, via a direct channel-manager assignment.
+
+ - `granting_role_ids: optional array of string`
+
+ The tagged IDs of the custom roles that granted the actor the per-channel `claude_tag_channel:manage` permission, e.g. "rbac_role_01HX...". Empty when `via_full_manage` is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when `via_account_assignment` is true (no role stands behind a direct assignment).
+
+ - `via_account_assignment: optional boolean or null`
+
+ True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, `via_full_manage` and `via_entitlement_leg` are false and `granting_role_ids` is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.
- `created_at: optional string`
@@ -135690,11 +137662,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `credentials_expire_at: optional string or null`
-
- When the exchanged cloud credentials expire. Unset when the cloud provider did not return a lifetime; such credentials were used for the single triggering request and not cached.
+ - `host_constraint: optional array of string`
- format: date-time
+ The host name patterns the credential may be sent to after the update, e.g. "api.example.com" or "*.example.com". Populated only when the update changed them. At most 100 entries are included; host_constraint_truncated indicates when the configured set is larger.
- `organization_id: optional string or null`
@@ -135704,33 +137674,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `slack_threads: optional array of object`
-
- The Slack threads in the session's provenance, when the session originated from Slack. At most 64 entries are included.
-
- - `channel_id: string`
-
- The Slack channel ID, e.g. "C0123ABCDE".
-
- - `enterprise_id: string`
-
- The Slack Enterprise Grid organization ID, e.g. "E0123ABCDE". Empty for workspaces that are not part of an Enterprise Grid.
-
- - `team_id: string`
-
- The Slack workspace (team) ID, e.g. "T0123ABCDE".
-
- - `thread_ts: string`
+ - `updated_fields: optional array of string`
- The Slack thread timestamp within the channel, e.g. "1714000000.123456". Empty for a session bound to a whole channel rather than to one thread.
+ Names of the settings included in the update: "display_name", "host_constraint".
- - `CcrAgentProxyAnthropicOidcTokenMinted object`
+ - `CcrAgentProxyDestinationDeleted object`
- The Claude Code agent proxy minted a short-lived identity token for an anthropic_oidc credential. One event is recorded per fresh token issuance; a request served from the proxy's short-lived token cache does not mint a new token and is not recorded here. Per-request detail for traffic the credential was injected into is available in the agent proxy network events.
+ An agent proxy destination was deleted.
- - `type: optional "ccr_agent_proxy_anthropic_oidc_token_minted"`
+ - `type: optional "ccr_agent_proxy_destination_deleted"`
- default: ccr_agent_proxy_anthropic_oidc_token_minted
+ default: ccr_agent_proxy_destination_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -135938,58 +137892,26 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `agent_id: string`
-
- The Claude Code agent that owns the session, e.g. "cagt_01HX...". Empty when the session is not owned by an agent.
-
- - `audience: string`
-
- The minted token's audience: the fixed token-exchange audience for the "aws" target, the credential row's Google workload identity pool provider URL for the "gcp" target, or the row's configured audience for the "direct" target.
-
- - `credential_id: string`
-
- The credential row the token was minted for, e.g. "apc_01HX...".
-
- - `issuance_path: "broker_report" or "direct" or "proxy_record" or "unspecified"`
-
- Which record of the issuance this event is. Unspecified on events published before this field existed.
-
- - `"broker_report"`
-
- - `"direct"`
-
- - `"proxy_record"`
+ - `deleted_with_profile: boolean`
- - `"unspecified"`
+ True when this deletion happened as part of deleting the whole profile (profile_id names the deleted profile). At most one of deleted_with_profile / cascade_trigger_credential_id is set; both unset means a direct DeleteAgentProxyDestination call.
- - `mint_jti: string`
+ - `destination_id: string`
- The identifier of the mint attempt, a bare UUID. One mint through the Claude Tag mint broker produces two minted events that carry the same value, the broker's own report and the agent proxy's record. A reader counts issuances from the broker's reports by distinct report_id, and several distinct reports that share one mint_jti are the accepted mints of a replayed token. Empty on events for mints that did not travel through the broker.
+ The destination that was deleted, e.g. "apd_01HX...".
- `profile_id: string`
- The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
-
- - `report_id: string`
-
- The identity of the mint broker's report itself, a bare UUID. The broker mints it once per report and delivery retries repeat it, so several events carrying one report_id are duplicates of one report and collapse to one issuance. Present on broker_report events only.
-
- - `session_id: string`
-
- The Claude Code session whose request triggered the mint, e.g. "cse_01HX..." or "session_01HX..." (the session's ID is carried in whichever tagged form the session's credential presented).
-
- - `target: string`
-
- The credential's configured target, e.g. "aws", "gcp", or "direct".
-
- - `test_mint: string`
-
- Set when the token was minted by the gateway verification test that runs while an admin registers a custom-gateway audience: "wrong_subject" for the probe token the gateway must reject, "right_subject" for the control token it must accept. Empty for tokens minted for live sessions.
+ The agent proxy profile the destination belonged to, e.g. "capp_01HX...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `cascade_trigger_credential_id: optional string or null`
+
+ Set when this deletion was triggered by a cascading DeleteAgentProxyCredential (the destination's client_tls_credential was the deleted credential). Unset for a direct DeleteAgentProxyDestination call and for the profile-delete cascade (see deleted_with_profile).
+
- `created_at: optional string`
When this activity occurred.
@@ -136004,39 +137926,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `slack_threads: optional array of object`
-
- The Slack threads in the session's provenance, when the session originated from Slack. At most 64 entries are included.
-
- - `channel_id: string`
-
- The Slack channel ID, e.g. "C0123ABCDE".
-
- - `enterprise_id: string`
-
- The Slack Enterprise Grid organization ID, e.g. "E0123ABCDE". Empty for workspaces that are not part of an Enterprise Grid.
-
- - `team_id: string`
-
- The Slack workspace (team) ID, e.g. "T0123ABCDE".
-
- - `thread_ts: string`
-
- The Slack thread timestamp within the channel, e.g. "1714000000.123456". Empty for a session bound to a whole channel rather than to one thread.
-
- - `token_expires_at: optional string or null`
-
- When the minted token expires.
-
- format: date-time
-
- - `CcrAgentProxyCredentialCreated object`
+ - `CcrAgentProxyNetworkEventsListed object`
- A Claude Code agent proxy credential was created. Credentials hold the secrets the agent proxy injects into requests Claude Code sessions send to approved external services; each credential belongs to an agent proxy profile. Audit events carry only credential names and settings, never the secret material itself.
+ A Claude Code network activity export was accessed for the given hour.
- - `type: optional "ccr_agent_proxy_credential_created"`
+ - `type: optional "ccr_agent_proxy_network_events_listed"`
- default: ccr_agent_proxy_credential_created
+ default: ccr_agent_proxy_network_events_listed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -136244,71 +138140,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `credential_id: string`
-
- The credential that was created, e.g. "apc_01HX...".
-
- - `credential_type: string`
-
- The kind of credential, e.g. "bearer", "basic", "github_app", "mtls".
-
- - `display_name: string`
-
- The credential's display name.
-
- - `host_constraint_truncated: boolean`
-
- Whether host_constraint was capped and omits some of the configured host name patterns.
-
- - `profile_id: string`
+ - `failed: boolean`
- The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
+ True when the export request did not complete successfully.
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `authorization_basis: optional object or null`
-
- CcrAgentProxyCredentialAuthorizationBasis records how the actor was authorized to perform a Claude Code agent proxy credential operation. Populated only when the operation was authorized against a specific actor's permissions; absent on system-initiated operations (for example, an automatic token rotation) and on operations authorized by a provisioning link rather than the actor's own permissions.
-
- - `slack_channel_id: string`
-
- The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".
-
- - `slack_enterprise_id: string`
-
- The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.
-
- - `slack_team_id: string`
-
- The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".
-
- - `via_entitlement_leg: boolean`
-
- True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.
-
- - `via_full_manage: boolean`
-
- True when the actor held the organization-wide Claude Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel `claude_tag_channel:manage` permission or, when `via_account_assignment` is true, via a direct channel-manager assignment.
-
- - `granting_role_ids: optional array of string`
-
- The tagged IDs of the custom roles that granted the actor the per-channel `claude_tag_channel:manage` permission, e.g. "rbac_role_01HX...". Empty when `via_full_manage` is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when `via_account_assignment` is true (no role stands behind a direct assignment).
-
- - `via_account_assignment: optional boolean or null`
-
- True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, `via_full_manage` and `via_entitlement_leg` are false and `granting_role_ids` is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.
-
- `created_at: optional string`
When this activity occurred.
format: date-time
- - `host_constraint: optional array of string`
+ - `hour: optional string or null`
- The host name patterns the credential may be sent to, e.g. "api.example.com" or "*.example.com". At most 100 entries are included; host_constraint_truncated indicates when the configured set is larger.
+ The UTC hour that was exported.
+
+ format: date-time
- `organization_id: optional string or null`
@@ -136318,13 +138168,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyCredentialDeleted object`
+ - `CcrAgentProxyProfileBound object`
- A Claude Code agent proxy credential was deleted. Its secret material was removed and can no longer be sent to any host.
+ A Claude Code agent proxy profile was bound to a scope, applying its policy to Claude Code sessions in that scope.
- - `type: optional "ccr_agent_proxy_credential_deleted"`
+ - `type: optional "ccr_agent_proxy_profile_bound"`
- default: ccr_agent_proxy_credential_deleted
+ default: ccr_agent_proxy_profile_bound
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -136532,49 +138382,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `credential_id: string`
-
- The credential that was deleted, e.g. "apc_01HX...".
-
- `profile_id: string`
- The agent proxy profile the credential belonged to, e.g. "capp_01HX...". Carried so the deletion can be correlated with the profile's other audit events after the credential row no longer exists.
-
- - `id: optional string`
-
- Unique identifier for the activity e.g. 'activity_abcd1234'
-
- - `authorization_basis: optional object or null`
-
- CcrAgentProxyCredentialAuthorizationBasis records how the actor was authorized to perform a Claude Code agent proxy credential operation. Populated only when the operation was authorized against a specific actor's permissions; absent on system-initiated operations (for example, an automatic token rotation) and on operations authorized by a provisioning link rather than the actor's own permissions.
-
- - `slack_channel_id: string`
-
- The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".
-
- - `slack_enterprise_id: string`
-
- The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.
-
- - `slack_team_id: string`
-
- The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".
-
- - `via_entitlement_leg: boolean`
-
- True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.
+ The profile that was bound, e.g. "capp_01HX...".
- - `via_full_manage: boolean`
+ - `scope_id: string`
- True when the actor held the organization-wide Claude Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel `claude_tag_channel:manage` permission or, when `via_account_assignment` is true, via a direct channel-manager assignment.
+ The identifier of the scope the profile was bound to.
- - `granting_role_ids: optional array of string`
+ - `scope_kind: string`
- The tagged IDs of the custom roles that granted the actor the per-channel `claude_tag_channel:manage` permission, e.g. "rbac_role_01HX...". Empty when `via_full_manage` is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when `via_account_assignment` is true (no role stands behind a direct assignment).
+ The kind of scope the profile was bound to: "organization", "environment", "account", or "agent".
- - `via_account_assignment: optional boolean or null`
+ - `id: optional string`
- True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, `via_full_manage` and `via_entitlement_leg` are false and `granting_role_ids` is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -136590,13 +138412,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyCredentialRotated object`
+ - `CcrAgentProxyProfileCreated object`
- A Claude Code agent proxy credential's secret material was replaced. The replacement keeps the same name, profile, and allowed hosts under a new credential identifier, and everything that referenced the old credential now uses the replacement.
+ A Claude Code agent proxy profile was created. Agent proxy profiles are named, reusable bundles of access policy that administrators bind to parts of the organization.
- - `type: optional "ccr_agent_proxy_credential_rotated"`
+ - `type: optional "ccr_agent_proxy_profile_created"`
- default: ccr_agent_proxy_credential_rotated
+ default: ccr_agent_proxy_profile_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -136804,75 +138626,59 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `credential_id: string`
-
- The replacement credential, e.g. "apc_01HX...".
-
- - `credential_type: string`
-
- The kind of credential, e.g. "bearer", "basic", "github_app", "mtls".
-
- - `destinations_repointed: number`
-
- The number of agent proxy destinations that referenced the old credential and now reference the replacement.
-
- `display_name: string`
- The credential's display name.
-
- - `previous_credential_id: string`
-
- The credential that was replaced, e.g. "apc_01HX...".
+ The profile's display name at creation time.
- `profile_id: string`
- The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
+ The profile that was created, e.g. "capp_01HX...".
- - `rules_repointed: number`
+ - `slug: string`
- The number of agent proxy rules that referenced the old credential and now reference the replacement.
+ The profile's URL-safe identifier, unique within the organization.
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `authorization_basis: optional object or null`
+ - `created_at: optional string`
- CcrAgentProxyCredentialAuthorizationBasis records how the actor was authorized to perform a Claude Code agent proxy credential operation. Populated only when the operation was authorized against a specific actor's permissions; absent on system-initiated operations (for example, an automatic token rotation) and on operations authorized by a provisioning link rather than the actor's own permissions.
+ When this activity occurred.
- - `slack_channel_id: string`
+ format: date-time
- The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".
+ - `github_access: optional array of object`
- - `slack_enterprise_id: string`
+ The GitHub repository access the profile grants, one entry per GitHub App installation. Empty when the profile grants no GitHub access.
- The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.
+ - `access_mode: string`
- - `slack_team_id: string`
+ How repository access is granted: "none" (no access), "list" (exactly the repositories in repos), or "all" — a legacy value for policies created before per-repository grants were required; it can no longer be assigned.
- The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".
+ - `github_installation_id: number`
- - `via_entitlement_leg: boolean`
+ The GitHub App installation the access applies to.
- True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.
+ - `repo_count: number`
- - `via_full_manage: boolean`
+ The total number of repositories granted, including any omitted from repos.
- True when the actor held the organization-wide Claude Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel `claude_tag_channel:manage` permission or, when `via_account_assignment` is true, via a direct channel-manager assignment.
+ - `repos_truncated: boolean`
- - `granting_role_ids: optional array of string`
+ Whether repos was capped and omits some of the granted repositories.
- The tagged IDs of the custom roles that granted the actor the per-channel `claude_tag_channel:manage` permission, e.g. "rbac_role_01HX...". Empty when `via_full_manage` is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when `via_account_assignment` is true (no role stands behind a direct assignment).
+ - `ghe_configuration_id: optional number or null`
- - `via_account_assignment: optional boolean or null`
+ The GitHub host configuration this installation belongs to. Distinguishes installations with the same numeric installation ID across github.com and GitHub Enterprise Server hosts. Absent for github.com installations.
- True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, `via_full_manage` and `via_entitlement_leg` are false and `granting_role_ids` is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.
+ - `repo_ids: optional array of number`
- - `created_at: optional string`
+ The numeric GitHub repository IDs the profile grants access to, in the same order as repos (and subject to the same 100-entry cap). These IDs are the authoritative identity of the granted repositories — access is enforced against them, not against the display names in repos.
- When this activity occurred.
+ - `repos: optional array of string`
- format: date-time
+ Repository names (owner/name) the profile grants access to, populated when access_mode is "list". Names are display-only labels resolved when the event was recorded and may lag a repository rename; the entries in repo_ids are the authoritative identity of the granted repositories. A repository whose name is unavailable is listed as its numeric GitHub repository ID instead. At most 100 entries are included; repos_truncated indicates when the granted set is larger.
- `organization_id: optional string or null`
@@ -136882,13 +138688,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyCredentialUpdated object`
+ - `CcrAgentProxyProfileDeleted object`
- A Claude Code agent proxy credential's settings were updated. Only the display name and the allowed host patterns can be updated; the secret material can only be replaced through a rotation.
+ A Claude Code agent proxy profile was deleted, removing its policy from everything it was bound to.
- - `type: optional "ccr_agent_proxy_credential_updated"`
+ - `type: optional "ccr_agent_proxy_profile_deleted"`
- default: ccr_agent_proxy_credential_updated
+ default: ccr_agent_proxy_profile_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -137096,57 +138902,37 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `credential_id: string`
-
- The credential that was updated, e.g. "apc_01HX...".
-
- - `display_name: string`
-
- The credential's display name after the update.
-
- - `host_constraint_truncated: boolean`
-
- Whether host_constraint was capped and omits some of the configured host name patterns.
-
- - `profile_id: string`
-
- The agent proxy profile the credential belongs to, e.g. "capp_01HX...".
-
- - `id: optional string`
-
- Unique identifier for the activity e.g. 'activity_abcd1234'
-
- - `authorization_basis: optional object or null`
+ - `deleted_credential_count: number`
- CcrAgentProxyCredentialAuthorizationBasis records how the actor was authorized to perform a Claude Code agent proxy credential operation. Populated only when the operation was authorized against a specific actor's permissions; absent on system-initiated operations (for example, an automatic token rotation) and on operations authorized by a provisioning link rather than the actor's own permissions.
+ Number of credentials deleted together with the profile — deleting a profile also deletes the credentials attached to it. Each deleted credential additionally emits its own ccr_agent_proxy_credential_deleted activity, at most 100 per profile deletion. Best-effort: when deleted_credentials_unknown is true the count could not be determined and 0 here does not mean the profile had no credentials.
- - `slack_channel_id: string`
+ - `deleted_credentials_unknown: boolean`
- The Slack channel the credential's agent proxy profile is bound to, e.g. "C01ABC...".
+ Whether the number of credentials deleted with the profile could not be determined. When true, deleted_credential_count is 0 and no per-credential deletion activities were emitted, even though the deletion may have destroyed credentials.
- - `slack_enterprise_id: string`
+ - `deleted_destination_count: number`
- The Slack Enterprise Grid organization containing the workspace, e.g. "E01ABC...". Empty when the workspace does not belong to an Enterprise Grid organization.
+ Number of destinations deleted together with the profile. Each deleted destination additionally emits its own ccr_agent_proxy_destination_deleted activity with deleted_with_profile set, at most 100 per profile deletion. Best-effort: when deleted_destinations_unknown is true the count could not be determined and 0 here does not mean the profile had no destinations.
- - `slack_team_id: string`
+ - `deleted_destinations_unknown: boolean`
- The Slack workspace the credential's agent proxy profile is bound to, e.g. "T01ABC...".
+ Whether the number of destinations deleted with the profile could not be determined. Same semantics as deleted_credentials_unknown.
- - `via_entitlement_leg: boolean`
+ - `deleted_rule_count: number`
- True when the actor's permission came from a custom role assigned in Roles & permissions. False when it came from a built-in Owner or Admin role.
+ Number of rules deleted together with the profile. Each deleted rule additionally emits its own ccr_agent_proxy_rule_deleted activity with deleted_with_profile set, at most 100 per profile deletion. Best-effort: when deleted_rules_unknown is true the count could not be determined and 0 here does not mean the profile had no rules.
- - `via_full_manage: boolean`
+ - `deleted_rules_unknown: boolean`
- True when the actor held the organization-wide Claude Tag management permission. False when the actor was instead authorized for the Slack channel identified below, either via the per-channel `claude_tag_channel:manage` permission or, when `via_account_assignment` is true, via a direct channel-manager assignment.
+ Whether the number of rules deleted with the profile could not be determined. Same semantics as deleted_credentials_unknown.
- - `granting_role_ids: optional array of string`
+ - `profile_id: string`
- The tagged IDs of the custom roles that granted the actor the per-channel `claude_tag_channel:manage` permission, e.g. "rbac_role_01HX...". Empty when `via_full_manage` is true (the actor was authorized by the organization-wide permission, so no per-channel role grant was evaluated) and when `via_account_assignment` is true (no role stands behind a direct assignment).
+ The profile that was deleted, e.g. "capp_01HX...".
- - `via_account_assignment: optional boolean or null`
+ - `id: optional string`
- True when the actor was authorized because an owner or admin assigned them directly as a manager of the Slack channel identified below (see ccr_channel_manager_added), rather than through a permission held via a role. When true, `via_full_manage` and `via_entitlement_leg` are false and `granting_role_ids` is empty. Absent on events recorded before direct channel-manager assignments existed; treat absence as false.
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -137154,10 +138940,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `host_constraint: optional array of string`
-
- The host name patterns the credential may be sent to after the update, e.g. "api.example.com" or "*.example.com". Populated only when the update changed them. At most 100 entries are included; host_constraint_truncated indicates when the configured set is larger.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -137166,17 +138948,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `updated_fields: optional array of string`
-
- Names of the settings included in the update: "display_name", "host_constraint".
-
- - `CcrAgentProxyDestinationDeleted object`
+ - `CcrAgentProxyProfileUnbound object`
- An agent proxy destination was deleted.
+ A Claude Code agent proxy profile was unbound from a scope, removing its policy from Claude Code sessions in that scope.
- - `type: optional "ccr_agent_proxy_destination_deleted"`
+ - `type: optional "ccr_agent_proxy_profile_unbound"`
- default: ccr_agent_proxy_destination_deleted
+ default: ccr_agent_proxy_profile_unbound
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -137384,26 +139162,22 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `deleted_with_profile: boolean`
+ - `profile_id: string`
- True when this deletion happened as part of deleting the whole profile (profile_id names the deleted profile). At most one of deleted_with_profile / cascade_trigger_credential_id is set; both unset means a direct DeleteAgentProxyDestination call.
+ The profile that was unbound, e.g. "capp_01HX...".
- - `destination_id: string`
+ - `scope_id: string`
- The destination that was deleted, e.g. "apd_01HX...".
+ The identifier of the scope the profile was unbound from.
- - `profile_id: string`
+ - `scope_kind: string`
- The agent proxy profile the destination belonged to, e.g. "capp_01HX...".
+ The kind of scope the profile was unbound from: "organization", "environment", "account", or "agent".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `cascade_trigger_credential_id: optional string or null`
-
- Set when this deletion was triggered by a cascading DeleteAgentProxyCredential (the destination's client_tls_credential was the deleted credential). Unset for a direct DeleteAgentProxyDestination call and for the profile-delete cascade (see deleted_with_profile).
-
- `created_at: optional string`
When this activity occurred.
@@ -137418,13 +139192,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyNetworkEventsListed object`
+ - `CcrAgentProxyProfileUpdated object`
- A Claude Code network activity export was accessed for the given hour.
+ A Claude Code agent proxy profile's configuration was updated.
- - `type: optional "ccr_agent_proxy_network_events_listed"`
+ - `type: optional "ccr_agent_proxy_profile_updated"`
- default: ccr_agent_proxy_network_events_listed
+ default: ccr_agent_proxy_profile_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -137632,9 +139406,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `failed: boolean`
+ - `profile_id: string`
- True when the export request did not complete successfully.
+ The profile that was updated, e.g. "capp_01HX...".
- `id: optional string`
@@ -137646,11 +139420,49 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `hour: optional string or null`
+ - `github_access_changes: optional array of object`
- The UTC hour that was exported.
+ How the profile's GitHub repository access changed, one entry per GitHub App installation whose access changed. Empty when the update did not change GitHub access.
- format: date-time
+ - `access_mode: string`
+
+ How repository access is granted after the change: "none" (no access), "list" (access is restricted to an explicit repository list — repos_added/repos_removed carry this change's delta and repo_count the post-change total), or "all" — a legacy value for policies created before per-repository grants were required; it can no longer be assigned.
+
+ - `github_installation_id: number`
+
+ The GitHub App installation the change applies to.
+
+ - `repo_count: number`
+
+ The total number of repositories granted after the change.
+
+ - `repos_truncated: boolean`
+
+ Whether repos_added or repos_removed was capped and omits some of the changed repositories.
+
+ - `ghe_configuration_id: optional number or null`
+
+ The GitHub host configuration this installation belongs to. Distinguishes installations with the same numeric installation ID across github.com and GitHub Enterprise Server hosts. Absent for github.com installations.
+
+ - `previous_access_mode: optional string or null`
+
+ How repository access was granted before the change. Present only when the access mode changed.
+
+ - `repo_ids_added: optional array of number`
+
+ The numeric GitHub repository IDs added to the granted set, in the same order as repos_added (and subject to the same 100-entry cap). These IDs are the authoritative identity of the added repositories — access is enforced against them, not against the display names in repos_added.
+
+ - `repo_ids_removed: optional array of number`
+
+ The numeric GitHub repository IDs removed from the granted set, in the same order as repos_removed (and subject to the same 100-entry cap). These IDs are the authoritative identity of the removed repositories.
+
+ - `repos_added: optional array of string`
+
+ Repository names (owner/name) added to the granted set. Names are display-only labels resolved when the event was recorded and may lag a repository rename; the entries in repo_ids_added are the authoritative identity of the added repositories. A repository whose name is unavailable is listed as its numeric GitHub repository ID instead. At most 100 entries are included; repos_truncated indicates when more were added. Empty when the change involves "all" access, which grants every repository regardless of any explicit list.
+
+ - `repos_removed: optional array of string`
+
+ Repository names (owner/name) removed from the granted set. Same rendering, cap, and "all" handling as repos_added; repo_ids_removed carries the authoritative identity of the removed repositories.
- `organization_id: optional string or null`
@@ -137660,13 +139472,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyProfileBound object`
+ - `updated_fields: optional array of string`
- A Claude Code agent proxy profile was bound to a scope, applying its policy to Claude Code sessions in that scope.
+ Names of the configuration fields included in the update, e.g. "display_name", "github_installation_permissions".
- - `type: optional "ccr_agent_proxy_profile_bound"`
+ - `CcrAgentProxyProvisioningCredentialRejected object`
- default: ccr_agent_proxy_profile_bound
+ An organization owner rejected a credential that a teammate submitted via an agent proxy provisioning link: the credential and its disabled rule were deleted and the link was revoked. The actor is the owner; the submitter is recorded for attribution.
+
+ - `type: optional "ccr_agent_proxy_provisioning_credential_rejected"`
+
+ default: ccr_agent_proxy_provisioning_credential_rejected
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -137874,17 +139690,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `credential_id: string`
+
+ The credential the member submitted, e.g. "apc_01HX...".
+
+ - `link_id: string`
+
+ The provisioning link's identifier.
+
- `profile_id: string`
- The profile that was bound, e.g. "capp_01HX...".
+ The agent proxy profile the credential lived in, e.g. "capp_01HX...".
- - `scope_id: string`
+ - `rule_id: string`
- The identifier of the scope the profile was bound to.
+ The disabled rule that was deleted alongside the credential, e.g. "apr_01HX...".
- - `scope_kind: string`
+ - `submitted_by_user_id: string`
- The kind of scope the profile was bound to: "organization", "environment", "account", or "agent".
+ The tagged account ID of the user who originally submitted the credential, e.g. "user_01HX...".
- `id: optional string`
@@ -137904,13 +139728,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyProfileCreated object`
+ - `CcrAgentProxyProvisioningLinkEnabled object`
- A Claude Code agent proxy profile was created. Agent proxy profiles are named, reusable bundles of access policy that administrators bind to parts of the organization.
+ An organization owner enabled a credential that a teammate submitted via an agent proxy provisioning link: the disabled rule created at submission was switched to enforce, so the credential now takes traffic. The actor is the owner; the submitter is the actor on the prior ccr_agent_proxy_provisioning_link_submitted event.
- - `type: optional "ccr_agent_proxy_profile_created"`
+ - `type: optional "ccr_agent_proxy_provisioning_link_enabled"`
- default: ccr_agent_proxy_profile_created
+ default: ccr_agent_proxy_provisioning_link_enabled
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -138118,17 +139942,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `display_name: string`
+ - `credential_id: string`
- The profile's display name at creation time.
+ The credential the member submitted, e.g. "apc_01HX...".
+
+ - `link_id: string`
+
+ The provisioning link's identifier.
- `profile_id: string`
- The profile that was created, e.g. "capp_01HX...".
+ The agent proxy profile the credential lives in, e.g. "capp_01HX...".
- - `slug: string`
+ - `rule_id: string`
- The profile's URL-safe identifier, unique within the organization.
+ The rule that was flipped to enforce, e.g. "apr_01HX...".
- `id: optional string`
@@ -138140,38 +139968,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `github_access: optional array of object`
-
- The GitHub repository access the profile grants, one entry per GitHub App installation. Empty when the profile grants no GitHub access.
-
- - `access_mode: string`
-
- How repository access is granted: "none" (no access), "list" (exactly the repositories in repos), or "all" — a legacy value for policies created before per-repository grants were required; it can no longer be assigned.
-
- - `github_installation_id: number`
-
- The GitHub App installation the access applies to.
-
- - `repo_count: number`
-
- The total number of repositories granted, including any omitted from repos.
-
- - `repos_truncated: boolean`
-
- Whether repos was capped and omits some of the granted repositories.
-
- - `ghe_configuration_id: optional number or null`
-
- The GitHub host configuration this installation belongs to. Distinguishes installations with the same numeric installation ID across github.com and GitHub Enterprise Server hosts. Absent for github.com installations.
-
- - `repo_ids: optional array of number`
-
- The numeric GitHub repository IDs the profile grants access to, in the same order as repos (and subject to the same 100-entry cap). These IDs are the authoritative identity of the granted repositories — access is enforced against them, not against the display names in repos.
-
- - `repos: optional array of string`
-
- Repository names (owner/name) the profile grants access to, populated when access_mode is "list". Names are display-only labels resolved when the event was recorded and may lag a repository rename; the entries in repo_ids are the authoritative identity of the granted repositories. A repository whose name is unavailable is listed as its numeric GitHub repository ID instead. At most 100 entries are included; repos_truncated indicates when the granted set is larger.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -138180,13 +139976,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyProfileDeleted object`
+ - `CcrAgentProxyProvisioningLinkGenerated object`
- A Claude Code agent proxy profile was deleted, removing its policy from everything it was bound to.
+ An organization owner generated a one-time agent proxy credential provisioning link so a teammate can submit a credential into the target agent proxy profile without holding the owner role.
- - `type: optional "ccr_agent_proxy_profile_deleted"`
+ - `type: optional "ccr_agent_proxy_provisioning_link_generated"`
- default: ccr_agent_proxy_profile_deleted
+ default: ccr_agent_proxy_provisioning_link_generated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -138394,33 +140190,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `deleted_credential_count: number`
-
- Number of credentials deleted together with the profile — deleting a profile also deletes the credentials attached to it. Each deleted credential additionally emits its own ccr_agent_proxy_credential_deleted activity, at most 100 per profile deletion. Best-effort: when deleted_credentials_unknown is true the count could not be determined and 0 here does not mean the profile had no credentials.
-
- - `deleted_credentials_unknown: boolean`
-
- Whether the number of credentials deleted with the profile could not be determined. When true, deleted_credential_count is 0 and no per-credential deletion activities were emitted, even though the deletion may have destroyed credentials.
-
- - `deleted_destination_count: number`
-
- Number of destinations deleted together with the profile. Each deleted destination additionally emits its own ccr_agent_proxy_destination_deleted activity with deleted_with_profile set, at most 100 per profile deletion. Best-effort: when deleted_destinations_unknown is true the count could not be determined and 0 here does not mean the profile had no destinations.
-
- - `deleted_destinations_unknown: boolean`
-
- Whether the number of destinations deleted with the profile could not be determined. Same semantics as deleted_credentials_unknown.
-
- - `deleted_rule_count: number`
-
- Number of rules deleted together with the profile. Each deleted rule additionally emits its own ccr_agent_proxy_rule_deleted activity with deleted_with_profile set, at most 100 per profile deletion. Best-effort: when deleted_rules_unknown is true the count could not be determined and 0 here does not mean the profile had no rules.
-
- - `deleted_rules_unknown: boolean`
+ - `link_id: string`
- Whether the number of rules deleted with the profile could not be determined. Same semantics as deleted_credentials_unknown.
+ The provisioning link's identifier. Correlation only; redemption requires an org-member session, so this is not a bearer credential.
- `profile_id: string`
- The profile that was deleted, e.g. "capp_01HX...".
+ The agent proxy profile the submitted credential will be created in, e.g. "capp_01HX...".
- `id: optional string`
@@ -138440,13 +140216,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyProfileUnbound object`
+ - `CcrAgentProxyProvisioningLinkRevoked object`
- A Claude Code agent proxy profile was unbound from a scope, removing its policy from Claude Code sessions in that scope.
+ An organization owner revoked an unfilled agent proxy provisioning link.
- - `type: optional "ccr_agent_proxy_profile_unbound"`
+ - `type: optional "ccr_agent_proxy_provisioning_link_revoked"`
- default: ccr_agent_proxy_profile_unbound
+ default: ccr_agent_proxy_provisioning_link_revoked
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -138654,17 +140430,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `profile_id: string`
-
- The profile that was unbound, e.g. "capp_01HX...".
-
- - `scope_id: string`
+ - `link_id: string`
- The identifier of the scope the profile was unbound from.
+ The provisioning link's identifier.
- - `scope_kind: string`
+ - `profile_id: string`
- The kind of scope the profile was unbound from: "organization", "environment", "account", or "agent".
+ The agent proxy profile the link targeted, e.g. "capp_01HX...".
- `id: optional string`
@@ -138684,13 +140456,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyProfileUpdated object`
+ - `CcrAgentProxyProvisioningLinkSubmitted object`
- A Claude Code agent proxy profile's configuration was updated.
+ A teammate submitted a credential via an agent proxy provisioning link. The credential and a disabled rule are created; the credential takes traffic only after an organization owner enables the submitted credential. This event records the link-mediated lifecycle; the credential itself additionally emits ccr_agent_proxy_credential_created.
- - `type: optional "ccr_agent_proxy_profile_updated"`
+ - `type: optional "ccr_agent_proxy_provisioning_link_submitted"`
- default: ccr_agent_proxy_profile_updated
+ default: ccr_agent_proxy_provisioning_link_submitted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -138898,63 +140670,35 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `profile_id: string`
-
- The profile that was updated, e.g. "capp_01HX...".
-
- - `id: optional string`
-
- Unique identifier for the activity e.g. 'activity_abcd1234'
-
- - `created_at: optional string`
-
- When this activity occurred.
-
- format: date-time
-
- - `github_access_changes: optional array of object`
-
- How the profile's GitHub repository access changed, one entry per GitHub App installation whose access changed. Empty when the update did not change GitHub access.
-
- - `access_mode: string`
-
- How repository access is granted after the change: "none" (no access), "list" (access is restricted to an explicit repository list — repos_added/repos_removed carry this change's delta and repo_count the post-change total), or "all" — a legacy value for policies created before per-repository grants were required; it can no longer be assigned.
-
- - `github_installation_id: number`
-
- The GitHub App installation the change applies to.
-
- - `repo_count: number`
-
- The total number of repositories granted after the change.
+ - `credential_id: string`
- - `repos_truncated: boolean`
+ The credential that was created, e.g. "apc_01HX...".
- Whether repos_added or repos_removed was capped and omits some of the changed repositories.
+ - `credential_type: string`
- - `ghe_configuration_id: optional number or null`
+ The kind of credential, e.g. "bearer" or "basic".
- The GitHub host configuration this installation belongs to. Distinguishes installations with the same numeric installation ID across github.com and GitHub Enterprise Server hosts. Absent for github.com installations.
+ - `link_id: string`
- - `previous_access_mode: optional string or null`
+ The provisioning link's identifier.
- How repository access was granted before the change. Present only when the access mode changed.
+ - `profile_id: string`
- - `repo_ids_added: optional array of number`
+ The agent proxy profile the credential was created in, e.g. "capp_01HX...".
- The numeric GitHub repository IDs added to the granted set, in the same order as repos_added (and subject to the same 100-entry cap). These IDs are the authoritative identity of the added repositories — access is enforced against them, not against the display names in repos_added.
+ - `id: optional string`
- - `repo_ids_removed: optional array of number`
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- The numeric GitHub repository IDs removed from the granted set, in the same order as repos_removed (and subject to the same 100-entry cap). These IDs are the authoritative identity of the removed repositories.
+ - `created_at: optional string`
- - `repos_added: optional array of string`
+ When this activity occurred.
- Repository names (owner/name) added to the granted set. Names are display-only labels resolved when the event was recorded and may lag a repository rename; the entries in repo_ids_added are the authoritative identity of the added repositories. A repository whose name is unavailable is listed as its numeric GitHub repository ID instead. At most 100 entries are included; repos_truncated indicates when more were added. Empty when the change involves "all" access, which grants every repository regardless of any explicit list.
+ format: date-time
- - `repos_removed: optional array of string`
+ - `host_constraint: optional array of string`
- Repository names (owner/name) removed from the granted set. Same rendering, cap, and "all" handling as repos_added; repo_ids_removed carries the authoritative identity of the removed repositories.
+ The host name patterns the credential may be sent to.
- `organization_id: optional string or null`
@@ -138964,17 +140708,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `updated_fields: optional array of string`
+ - `CcrAgentProxyRuleCreated object`
- Names of the configuration fields included in the update, e.g. "display_name", "github_installation_permissions".
+ An agent proxy rule was created. A rule decides what happens to a session's outbound requests that match it.
- - `CcrAgentProxyProvisioningCredentialRejected object`
+ - `type: optional "ccr_agent_proxy_rule_created"`
- An organization owner rejected a credential that a teammate submitted via an agent proxy provisioning link: the credential and its disabled rule were deleted and the link was revoked. The actor is the owner; the submitter is recorded for attribution.
+ default: ccr_agent_proxy_rule_created
- - `type: optional "ccr_agent_proxy_provisioning_credential_rejected"`
+ - `action: "allow" or "deny" or "require_approval" or "unspecified"`
- default: ccr_agent_proxy_provisioning_credential_rejected
+ What the rule does with a matching request.
+
+ - `"allow"`
+
+ - `"deny"`
+
+ - `"require_approval"`
+
+ - `"unspecified"`
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -139182,25 +140934,65 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `credential_id: string`
+ - `has_condition: boolean`
- The credential the member submitted, e.g. "apc_01HX...".
+ Whether the rule carries a custom condition expression that further narrows the requests it matches beyond the host name patterns, ports, methods and paths.
- - `link_id: string`
+ - `hosts_truncated: boolean`
- The provisioning link's identifier.
+ Whether hosts was capped and omits some of the configured host name patterns.
+
+ - `injects_credential: boolean`
+
+ Whether the rule adds a managed credential to the requests it allows.
+
+ - `mode: "disabled" or "enforce" or "shadow" or "unspecified"`
+
+ Whether the rule is enforced, only observed, or switched off.
+
+ - `"disabled"`
+
+ - `"enforce"`
+
+ - `"shadow"`
+
+ - `"unspecified"`
+
+ - `path_pattern_count: number`
+
+ How many request path patterns (prefixes or regular expressions) narrow the requests the rule matches; 0 when the rule matches every path.
+
+ - `ports_truncated: boolean`
+
+ Whether ports was capped and omits some of the configured ports.
+
+ - `priority: number`
+
+ Where the rule is evaluated among the profile's rules: a lower number is evaluated first, and the first matching rule decides the request.
- `profile_id: string`
- The agent proxy profile the credential lived in, e.g. "capp_01HX...".
+ The agent proxy profile the rule belongs to, e.g. "capp_01HX...".
- - `rule_id: string`
+ - `protocol: "http" or "mysql" or "postgres" or 3 more`
- The disabled rule that was deleted alongside the credential, e.g. "apr_01HX...".
+ The kind of connection the rule applies to.
- - `submitted_by_user_id: string`
+ - `"http"`
- The tagged account ID of the user who originally submitted the credential, e.g. "user_01HX...".
+ - `"mysql"`
+
+ - `"postgres"`
+
+ - `"ssh"`
+
+ - `"tcp"`
+
+ - `"unspecified"`
+
+ - `rule_id: string`
+
+ The rule that was created, e.g. "apr_01HX...".
- `id: optional string`
@@ -139212,6 +141004,32 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `hosts: optional array of string`
+
+ The host name patterns the rule matches, in canonical form (lowercase, internationalized names in their ASCII encoding), e.g. "api.example.com" or "*.example.com". At most 100 entries are included; hosts_truncated indicates when the configured set is larger.
+
+ - `injected_credential_id: optional string or null`
+
+ The managed credential the rule adds to the requests it allows, e.g. "apc_01HX...". Unset when the rule adds none.
+
+ - `methods: optional array of string`
+
+ The HTTP methods the rule matches, e.g. `GET`. Empty when the rule matches every method.
+
+ - `mutation_kinds: optional array of "inject_credential" or "route_to" or "set_header" or 2 more`
+
+ The kinds of change the rule makes to the requests it allows, each listed once.
+
+ - `"inject_credential"`
+
+ - `"route_to"`
+
+ - `"set_header"`
+
+ - `"strip_header"`
+
+ - `"unspecified"`
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -139220,13 +141038,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyProvisioningLinkEnabled object`
+ - `ports: optional array of number`
- An organization owner enabled a credential that a teammate submitted via an agent proxy provisioning link: the disabled rule created at submission was switched to enforce, so the credential now takes traffic. The actor is the owner; the submitter is the actor on the prior ccr_agent_proxy_provisioning_link_submitted event.
+ The TCP ports the rule matches, e.g. 443. At most 100 entries are included; ports_truncated indicates when the configured set is larger.
- - `type: optional "ccr_agent_proxy_provisioning_link_enabled"`
+ - `route_to_destination_id: optional string or null`
- default: ccr_agent_proxy_provisioning_link_enabled
+ The configured destination the rule sends allowed requests to instead of the host they name, e.g. "apd_01HX...". Unset when the rule reroutes nothing.
+
+ - `CcrAgentProxyRuleDeleted object`
+
+ An agent proxy rule was deleted.
+
+ - `type: optional "ccr_agent_proxy_rule_deleted"`
+
+ default: ccr_agent_proxy_rule_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -139434,26 +141260,26 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `credential_id: string`
-
- The credential the member submitted, e.g. "apc_01HX...".
-
- - `link_id: string`
+ - `deleted_with_profile: boolean`
- The provisioning link's identifier.
+ True when this deletion happened as part of deleting the whole profile (profile_id names the deleted profile). At most one of deleted_with_profile / cascade_trigger_credential_id is set; both unset means a direct DeleteAgentProxyRule call or a provisioning-link reject (RejectAgentProxyProvisionedCredential) — the reject case also emits CcrAgentProxyProvisioningCredentialRejected with the same rule_id in the same batch.
- `profile_id: string`
- The agent proxy profile the credential lives in, e.g. "capp_01HX...".
+ The agent proxy profile the rule belonged to, e.g. "capp_01HX...".
- `rule_id: string`
- The rule that was flipped to enforce, e.g. "apr_01HX...".
+ The rule that was deleted, e.g. "apr_01HX...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `cascade_trigger_credential_id: optional string or null`
+
+ Set when this deletion was triggered by a cascading DeleteAgentProxyCredential (the rule inject_credential-referenced the deleted credential). Unset for a direct DeleteAgentProxyRule call, for the profile-delete cascade (see deleted_with_profile), and for a provisioning-link reject that removed the provisioned rule.
+
- `created_at: optional string`
When this activity occurred.
@@ -139468,13 +141294,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyProvisioningLinkGenerated object`
+ - `CcrAgentProxyRuleUpdated object`
- An organization owner generated a one-time agent proxy credential provisioning link so a teammate can submit a credential into the target agent proxy profile without holding the owner role.
+ An agent proxy rule was updated. An update replaces everything the rule matches and does, so the host name patterns here are the rule's complete set after the update.
- - `type: optional "ccr_agent_proxy_provisioning_link_generated"`
+ - `type: optional "ccr_agent_proxy_rule_updated"`
- default: ccr_agent_proxy_provisioning_link_generated
+ default: ccr_agent_proxy_rule_updated
+
+ - `action: "allow" or "deny" or "require_approval" or "unspecified"`
+
+ What the rule does with a matching request.
+
+ - `"allow"`
+
+ - `"deny"`
+
+ - `"require_approval"`
+
+ - `"unspecified"`
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -139682,13 +141520,69 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `link_id: string`
+ - `has_condition: boolean`
- The provisioning link's identifier. Correlation only; redemption requires an org-member session, so this is not a bearer credential.
+ Whether the rule carries a custom condition expression that further narrows the requests it matches beyond the host name patterns, ports, methods and paths.
+
+ - `hosts_truncated: boolean`
+
+ Whether hosts was capped and omits some of the configured host name patterns.
+
+ - `injects_credential: boolean`
+
+ Whether the rule adds a managed credential to the requests it allows.
+
+ - `mode: "disabled" or "enforce" or "shadow" or "unspecified"`
+
+ Whether the rule is enforced, only observed, or switched off.
+
+ - `"disabled"`
+
+ - `"enforce"`
+
+ - `"shadow"`
+
+ - `"unspecified"`
+
+ - `path_pattern_count: number`
+
+ How many request path patterns (prefixes or regular expressions) narrow the requests the rule matches after the update; 0 when the rule matches every path.
+
+ - `ports_truncated: boolean`
+
+ Whether ports was capped and omits some of the configured ports.
+
+ - `priority: number`
+
+ Where the rule is evaluated among the profile's rules: a lower number is evaluated first, and the first matching rule decides the request.
- `profile_id: string`
- The agent proxy profile the submitted credential will be created in, e.g. "capp_01HX...".
+ The agent proxy profile the rule belongs to, e.g. "capp_01HX...".
+
+ - `protocol: "http" or "mysql" or "postgres" or 3 more`
+
+ The kind of connection the rule applies to.
+
+ - `"http"`
+
+ - `"mysql"`
+
+ - `"postgres"`
+
+ - `"ssh"`
+
+ - `"tcp"`
+
+ - `"unspecified"`
+
+ - `rule_id: string`
+
+ The rule that was updated, e.g. "apr_01HX...".
+
+ - `version: number`
+
+ The rule's version after the update; it increases by one on every update.
- `id: optional string`
@@ -139700,6 +141594,32 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `hosts: optional array of string`
+
+ The host name patterns the rule matches after the update, in canonical form (lowercase, internationalized names in their ASCII encoding). At most 100 entries are included; hosts_truncated indicates when the configured set is larger.
+
+ - `injected_credential_id: optional string or null`
+
+ The managed credential the rule adds to the requests it allows, e.g. "apc_01HX...". Unset when the rule adds none.
+
+ - `methods: optional array of string`
+
+ The HTTP methods the rule matches after the update, e.g. `GET`. Empty when the rule matches every method.
+
+ - `mutation_kinds: optional array of "inject_credential" or "route_to" or "set_header" or 2 more`
+
+ The kinds of change the rule makes to the requests it allows after the update, each listed once.
+
+ - `"inject_credential"`
+
+ - `"route_to"`
+
+ - `"set_header"`
+
+ - `"strip_header"`
+
+ - `"unspecified"`
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -139708,13 +141628,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyProvisioningLinkRevoked object`
+ - `ports: optional array of number`
- An organization owner revoked an unfilled agent proxy provisioning link.
+ The TCP ports the rule matches, e.g. 443. At most 100 entries are included; ports_truncated indicates when the configured set is larger.
- - `type: optional "ccr_agent_proxy_provisioning_link_revoked"`
+ - `route_to_destination_id: optional string or null`
- default: ccr_agent_proxy_provisioning_link_revoked
+ The configured destination the rule sends allowed requests to instead of the host they name, e.g. "apd_01HX...". Unset when the rule reroutes nothing.
+
+ - `CcrAgentSlackAccessScopeCreated object`
+
+ A Claude Code agent was granted access to read or write in an additional Slack channel beyond the one it is assigned to.
+
+ - `type: optional "ccr_agent_slack_access_scope_created"`
+
+ default: ccr_agent_slack_access_scope_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -139922,13 +141850,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `link_id: string`
+ - `agent_id: string`
- The provisioning link's identifier.
+ The agent that was granted access, e.g. "cagt_01HX...".
- - `profile_id: string`
+ - `can_write: boolean`
- The agent proxy profile the link targeted, e.g. "capp_01HX...".
+ Whether the grant includes permission to post messages in the channel, in addition to reading it.
+
+ - `slack_channel_id: string`
+
+ The Slack channel the agent was granted access to, e.g. "C01ABC...". Empty when the grant covers the entire workspace.
+
+ - `slack_team_id: string`
+
+ The Slack workspace containing the channel, e.g. "T01ABC...".
- `id: optional string`
@@ -139948,13 +141884,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyProvisioningLinkSubmitted object`
+ - `CcrAgentSlackAccessScopeDeleted object`
- A teammate submitted a credential via an agent proxy provisioning link. The credential and a disabled rule are created; the credential takes traffic only after an organization owner enables the submitted credential. This event records the link-mediated lifecycle; the credential itself additionally emits ccr_agent_proxy_credential_created.
+ A Claude Code agent's access to an additional Slack channel was revoked.
- - `type: optional "ccr_agent_proxy_provisioning_link_submitted"`
+ - `type: optional "ccr_agent_slack_access_scope_deleted"`
- default: ccr_agent_proxy_provisioning_link_submitted
+ default: ccr_agent_slack_access_scope_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -140162,21 +142098,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `credential_id: string`
-
- The credential that was created, e.g. "apc_01HX...".
-
- - `credential_type: string`
+ - `agent_id: string`
- The kind of credential, e.g. "bearer" or "basic".
+ The agent whose access was revoked, e.g. "cagt_01HX...".
- - `link_id: string`
+ - `slack_channel_id: string`
- The provisioning link's identifier.
+ The Slack channel the agent's access was revoked from, e.g. "C01ABC...". Empty when the revoked grant covered the entire workspace.
- - `profile_id: string`
+ - `slack_team_id: string`
- The agent proxy profile the credential was created in, e.g. "capp_01HX...".
+ The Slack workspace containing the channel, e.g. "T01ABC...".
- `id: optional string`
@@ -140188,10 +142120,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `host_constraint: optional array of string`
-
- The host name patterns the credential may be sent to.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -140200,25 +142128,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyRuleCreated object`
-
- An agent proxy rule was created. A rule decides what happens to a session's outbound requests that match it.
-
- - `type: optional "ccr_agent_proxy_rule_created"`
-
- default: ccr_agent_proxy_rule_created
-
- - `action: "allow" or "deny" or "require_approval" or "unspecified"`
-
- What the rule does with a matching request.
-
- - `"allow"`
+ - `CcrAgentSlackBindingCreated object`
- - `"deny"`
+ A Claude Code agent was assigned to a Slack channel or workspace as its dedicated agent.
- - `"require_approval"`
+ - `type: optional "ccr_agent_slack_binding_created"`
- - `"unspecified"`
+ default: ccr_agent_slack_binding_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -140426,65 +142342,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `has_condition: boolean`
-
- Whether the rule carries a custom condition expression that further narrows the requests it matches beyond the host name patterns, ports, methods and paths.
-
- - `hosts_truncated: boolean`
-
- Whether hosts was capped and omits some of the configured host name patterns.
-
- - `injects_credential: boolean`
-
- Whether the rule adds a managed credential to the requests it allows.
-
- - `mode: "disabled" or "enforce" or "shadow" or "unspecified"`
-
- Whether the rule is enforced, only observed, or switched off.
-
- - `"disabled"`
-
- - `"enforce"`
-
- - `"shadow"`
-
- - `"unspecified"`
-
- - `path_pattern_count: number`
-
- How many request path patterns (prefixes or regular expressions) narrow the requests the rule matches; 0 when the rule matches every path.
-
- - `ports_truncated: boolean`
-
- Whether ports was capped and omits some of the configured ports.
-
- - `priority: number`
-
- Where the rule is evaluated among the profile's rules: a lower number is evaluated first, and the first matching rule decides the request.
-
- - `profile_id: string`
-
- The agent proxy profile the rule belongs to, e.g. "capp_01HX...".
-
- - `protocol: "http" or "mysql" or "postgres" or 3 more`
-
- The kind of connection the rule applies to.
-
- - `"http"`
-
- - `"mysql"`
-
- - `"postgres"`
+ - `agent_id: string`
- - `"ssh"`
+ The agent the binding was created for, e.g. "cagt_01HX...".
- - `"tcp"`
+ - `slack_channel_id: string`
- - `"unspecified"`
+ The Slack channel the agent was assigned to, e.g. "C01ABC...". Empty when the agent was assigned to the entire workspace.
- - `rule_id: string`
+ - `slack_team_id: string`
- The rule that was created, e.g. "apr_01HX...".
+ The Slack workspace the agent was assigned to, e.g. "T01ABC...".
- `id: optional string`
@@ -140496,32 +142364,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `hosts: optional array of string`
-
- The host name patterns the rule matches, in canonical form (lowercase, internationalized names in their ASCII encoding), e.g. "api.example.com" or "*.example.com". At most 100 entries are included; hosts_truncated indicates when the configured set is larger.
-
- - `injected_credential_id: optional string or null`
-
- The managed credential the rule adds to the requests it allows, e.g. "apc_01HX...". Unset when the rule adds none.
-
- - `methods: optional array of string`
-
- The HTTP methods the rule matches, e.g. `GET`. Empty when the rule matches every method.
-
- - `mutation_kinds: optional array of "inject_credential" or "route_to" or "set_header" or 2 more`
-
- The kinds of change the rule makes to the requests it allows, each listed once.
-
- - `"inject_credential"`
-
- - `"route_to"`
-
- - `"set_header"`
-
- - `"strip_header"`
-
- - `"unspecified"`
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -140530,21 +142372,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ports: optional array of number`
-
- The TCP ports the rule matches, e.g. 443. At most 100 entries are included; ports_truncated indicates when the configured set is larger.
-
- - `route_to_destination_id: optional string or null`
-
- The configured destination the rule sends allowed requests to instead of the host they name, e.g. "apd_01HX...". Unset when the rule reroutes nothing.
-
- - `CcrAgentProxyRuleDeleted object`
+ - `CcrAgentSlackBindingDeleted object`
- An agent proxy rule was deleted.
+ A Claude Code agent's assignment to a Slack channel or workspace was removed.
- - `type: optional "ccr_agent_proxy_rule_deleted"`
+ - `type: optional "ccr_agent_slack_binding_deleted"`
- default: ccr_agent_proxy_rule_deleted
+ default: ccr_agent_slack_binding_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -140752,26 +142586,22 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `deleted_with_profile: boolean`
+ - `agent_id: string`
- True when this deletion happened as part of deleting the whole profile (profile_id names the deleted profile). At most one of deleted_with_profile / cascade_trigger_credential_id is set; both unset means a direct DeleteAgentProxyRule call or a provisioning-link reject (RejectAgentProxyProvisionedCredential) — the reject case also emits CcrAgentProxyProvisioningCredentialRejected with the same rule_id in the same batch.
+ The agent the binding was removed from, e.g. "cagt_01HX...".
- - `profile_id: string`
+ - `slack_channel_id: string`
- The agent proxy profile the rule belonged to, e.g. "capp_01HX...".
+ The Slack channel the agent was unassigned from, e.g. "C01ABC...". Empty when the assignment covered the entire workspace.
- - `rule_id: string`
+ - `slack_team_id: string`
- The rule that was deleted, e.g. "apr_01HX...".
+ The Slack workspace the agent was unassigned from, e.g. "T01ABC...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `cascade_trigger_credential_id: optional string or null`
-
- Set when this deletion was triggered by a cascading DeleteAgentProxyCredential (the rule inject_credential-referenced the deleted credential). Unset for a direct DeleteAgentProxyRule call, for the profile-delete cascade (see deleted_with_profile), and for a provisioning-link reject that removed the provisioned rule.
-
- `created_at: optional string`
When this activity occurred.
@@ -140786,25 +142616,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentProxyRuleUpdated object`
-
- An agent proxy rule was updated. An update replaces everything the rule matches and does, so the host name patterns here are the rule's complete set after the update.
-
- - `type: optional "ccr_agent_proxy_rule_updated"`
-
- default: ccr_agent_proxy_rule_updated
-
- - `action: "allow" or "deny" or "require_approval" or "unspecified"`
-
- What the rule does with a matching request.
-
- - `"allow"`
+ - `CcrAgentUpdated object`
- - `"deny"`
+ A Claude Code agent's configuration was updated. Also emitted with updated_fields ["is_virtual"] alone when an auto-provisioned agent is promoted to a configured one, whether by an update request targeting it or by binding an agent proxy profile to it.
- - `"require_approval"`
+ - `type: optional "ccr_agent_updated"`
- - `"unspecified"`
+ default: ccr_agent_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -141012,69 +142830,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `has_condition: boolean`
-
- Whether the rule carries a custom condition expression that further narrows the requests it matches beyond the host name patterns, ports, methods and paths.
-
- - `hosts_truncated: boolean`
-
- Whether hosts was capped and omits some of the configured host name patterns.
-
- - `injects_credential: boolean`
-
- Whether the rule adds a managed credential to the requests it allows.
-
- - `mode: "disabled" or "enforce" or "shadow" or "unspecified"`
-
- Whether the rule is enforced, only observed, or switched off.
-
- - `"disabled"`
-
- - `"enforce"`
-
- - `"shadow"`
-
- - `"unspecified"`
-
- - `path_pattern_count: number`
-
- How many request path patterns (prefixes or regular expressions) narrow the requests the rule matches after the update; 0 when the rule matches every path.
-
- - `ports_truncated: boolean`
-
- Whether ports was capped and omits some of the configured ports.
-
- - `priority: number`
-
- Where the rule is evaluated among the profile's rules: a lower number is evaluated first, and the first matching rule decides the request.
-
- - `profile_id: string`
-
- The agent proxy profile the rule belongs to, e.g. "capp_01HX...".
-
- - `protocol: "http" or "mysql" or "postgres" or 3 more`
-
- The kind of connection the rule applies to.
-
- - `"http"`
-
- - `"mysql"`
-
- - `"postgres"`
-
- - `"ssh"`
-
- - `"tcp"`
+ - `agent_id: string`
- - `"unspecified"`
+ The agent that was updated, e.g. "cagt_01HX...".
- - `rule_id: string`
+ - `default_source_urls_truncated: boolean`
- The rule that was updated, e.g. "apr_01HX...".
+ Whether default_source_urls was capped and omits some of the granted repositories.
- - `version: number`
+ - `omitted_source_url_count: number`
- The rule's version after the update; it increases by one on every update.
+ Number of default repository entries that could not be safely rendered as a credential-free URL and were omitted from default_source_urls. A non-zero value with an empty list means repositories were granted but could not be displayed — not that all repositories were removed.
- `id: optional string`
@@ -141086,31 +142852,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `hosts: optional array of string`
-
- The host name patterns the rule matches after the update, in canonical form (lowercase, internationalized names in their ASCII encoding). At most 100 entries are included; hosts_truncated indicates when the configured set is larger.
-
- - `injected_credential_id: optional string or null`
-
- The managed credential the rule adds to the requests it allows, e.g. "apc_01HX...". Unset when the rule adds none.
-
- - `methods: optional array of string`
-
- The HTTP methods the rule matches after the update, e.g. `GET`. Empty when the rule matches every method.
-
- - `mutation_kinds: optional array of "inject_credential" or "route_to" or "set_header" or 2 more`
-
- The kinds of change the rule makes to the requests it allows after the update, each listed once.
-
- - `"inject_credential"`
-
- - `"route_to"`
+ - `default_source_urls: optional array of string`
- - `"set_header"`
+ The agent's default repository URLs after the update, reduced to scheme, host, and path — credentials and query parameters are never included. Populated only when the update changed them — "default_source_urls" appears in updated_fields. Empty while listed in updated_fields AND omitted_source_url_count is 0 means all default repositories were removed. At most 100 entries are included; default_source_urls_truncated indicates when more were granted.
- - `"strip_header"`
+ - `guest_policy: optional string or null`
- - `"unspecified"`
+ The agent's response policy for Slack channels that include guest users and Slack Connect channels shared with other organizations, after the update: "allow", "restrict", "channel" (the agent responds, using only that channel's own content and configuration), or "default" when the update removed the agent-specific policy so the agent inherits the surrounding default. In Slack Connect channels "allow" gives at most "channel" access. Present only when the update changed it.
- `organization_id: optional string or null`
@@ -141120,21 +142868,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ports: optional array of number`
+ - `slack_alias: optional string or null`
- The TCP ports the rule matches, e.g. 443. At most 100 entries are included; ports_truncated indicates when the configured set is larger.
+ The agent's Slack trigger word after the update. Present only when the update changed it. An empty value means the agent responds to bare "@Claude" mentions.
- - `route_to_destination_id: optional string or null`
+ - `updated_fields: optional array of string`
- The configured destination the rule sends allowed requests to instead of the host they name, e.g. "apd_01HX...". Unset when the rule reroutes nothing.
+ Names of the configuration fields included in the update, e.g. "display_name", "system_prompt_addendum", "guest_policy". Includes "is_virtual" when this update was the first administrator action on an auto-provisioned agent — a durable state change even when no other field was supplied.
- - `CcrAgentSlackAccessScopeCreated object`
+ - `CcrChannelManagerAdded object`
- A Claude Code agent was granted access to read or write in an additional Slack channel beyond the one it is assigned to.
+ An org owner/admin assigned an organization member to manage the Claude-in-Slack configuration of one Slack channel.
- - `type: optional "ccr_agent_slack_access_scope_created"`
+ - `type: optional "ccr_channel_manager_added"`
- default: ccr_agent_slack_access_scope_created
+ default: ccr_channel_manager_added
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -141344,20 +143092,20 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `agent_id: string`
- The agent that was granted access, e.g. "cagt_01HX...".
-
- - `can_write: boolean`
-
- Whether the grant includes permission to post messages in the channel, in addition to reading it.
+ The channel's Claude agent (cagt_...) the assignment is recorded against.
- `slack_channel_id: string`
- The Slack channel the agent was granted access to, e.g. "C01ABC...". Empty when the grant covers the entire workspace.
+ The Slack channel the member may now manage, e.g. "C01ABC...".
- `slack_team_id: string`
The Slack workspace containing the channel, e.g. "T01ABC...".
+ - `user_id: string`
+
+ Tagged ID of the member who was assigned.
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -141376,13 +143124,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentSlackAccessScopeDeleted object`
+ - `CcrChannelManagerRemoved object`
- A Claude Code agent's access to an additional Slack channel was revoked.
+ An org owner/admin removed an organization member's assignment to manage the Claude-in-Slack configuration of one Slack channel.
- - `type: optional "ccr_agent_slack_access_scope_deleted"`
+ - `type: optional "ccr_channel_manager_removed"`
- default: ccr_agent_slack_access_scope_deleted
+ default: ccr_channel_manager_removed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -141592,259 +143340,19 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `agent_id: string`
- The agent whose access was revoked, e.g. "cagt_01HX...".
+ The channel's Claude agent (cagt_...) the assignment was recorded against.
- `slack_channel_id: string`
- The Slack channel the agent's access was revoked from, e.g. "C01ABC...". Empty when the revoked grant covered the entire workspace.
+ The Slack channel the member managed, e.g. "C01ABC...".
- `slack_team_id: string`
The Slack workspace containing the channel, e.g. "T01ABC...".
- - `id: optional string`
-
- Unique identifier for the activity e.g. 'activity_abcd1234'
-
- - `created_at: optional string`
-
- When this activity occurred.
-
- format: date-time
-
- - `organization_id: optional string or null`
-
- Organization ID this activity is associated with
-
- - `organization_uuid: optional string or null`
-
- Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
-
- - `CcrAgentSlackBindingCreated object`
-
- A Claude Code agent was assigned to a Slack channel or workspace as its dedicated agent.
-
- - `type: optional "ccr_agent_slack_binding_created"`
-
- default: ccr_agent_slack_binding_created
-
- - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
-
- - `APIActor object`
-
- - `type: optional "api_actor"`
-
- default: api_actor
-
- - `api_key_id: string`
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `UserActor object`
-
- - `type: optional "user_actor"`
-
- default: user_actor
-
- - `email_address: string`
-
- format: email
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `user_id: string`
-
- - `UnauthenticatedUserActor object`
-
- - `type: optional "unauthenticated_user_actor"`
-
- default: unauthenticated_user_actor
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `unauthenticated_email_address: optional string or null`
-
- format: email
-
- - `AnthropicActor object`
-
- - `type: optional "anthropic_actor"`
-
- default: anthropic_actor
-
- - `email_address: optional string or null`
-
- format: email
-
- - `SystemActor object`
-
- Automated background processing performed by Anthropic systems, acting
- without a user or customer credential.
-
- - `type: optional "system_actor"`
-
- default: system_actor
-
- - `service: optional string or null`
-
- Name of the automated process that performed the action, when known.
-
- - `AdminAPIKeyActor object`
-
- - `type: optional "admin_api_key_actor"`
-
- default: admin_api_key_actor
-
- - `admin_api_key_id: string`
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `ServiceAccountActor object`
-
- - `type: optional "service_account_actor"`
-
- default: service_account_actor
-
- - `ip_address: string`
-
- - `service_account_id: string`
-
- - `user_agent: string`
-
- - `ScimDirectorySyncActor object`
-
- - `type: optional "scim_directory_sync_actor"`
-
- default: scim_directory_sync_actor
-
- - `directory_id: string`
-
- - `workos_event_id: string`
-
- - `idp_connection_type: optional string or null`
-
- - `FederatedIdentityActor object`
-
- A federated external workload authenticated via a verified OIDC token.
-
- Carries the verified issuer, subject, and audience claims from the
- presented JWT.
-
- - `type: optional "federated_identity_actor"`
-
- default: federated_identity_actor
-
- - `issuer: string`
-
- - `subject: string`
-
- - `audience: optional array of string`
-
- - `ip_address: optional string or null`
-
- - `user_agent: optional string or null`
-
- - `FederatedActor object`
-
- An external identity asserted by a trusted provider — a cloud-provider
- gateway or a customer-registered federation issuer — acting without an
- Anthropic-provisioned account or service account.
-
- - `type: optional "federated_actor"`
-
- default: federated_actor
-
- - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
-
- - `FederatedActorAwsProvider object`
-
- Asserting party: the AWS account the organization is bound to.
-
- - `type: optional "aws"`
-
- default: aws
-
- - `account_id: string`
-
- - `signed_principal: string`
-
- The AWS-signed ARN of the IAM principal that requested the token.
-
- - `FederatedActorAzureProvider object`
-
- Asserting party: the Azure subscription the organization is bound to.
-
- - `type: optional "azure"`
-
- default: azure
-
- - `subscription_id: string`
-
- - `FederatedActorGcpProvider object`
-
- Asserting party: the GCP project the organization is bound to.
-
- - `type: optional "gcp"`
-
- default: gcp
-
- - `project_number: string`
-
- - `FederatedActorOidcProvider object`
-
- Asserting party: a customer-registered OIDC federation issuer.
-
- - `type: optional "oidc"`
-
- default: oidc
-
- - `issuer: optional string or null`
-
- The federation issuer's URL. Null when the presented credential failed verification.
-
- - `ip_address: optional string or null`
-
- - `subject: optional string or null`
-
- The provider's verified identifier for the caller; its form depends on the provider.
-
- - `user_agent: optional string or null`
-
- - `AttestedDeviceActor object`
-
- An attested mobile device authenticated via Apple App Attest.
-
- - `type: optional "attested_device_actor"`
-
- default: attested_device_actor
-
- - `external_client_id: string`
-
- - `kid_hash: string`
-
- - `ip_address: optional string or null`
-
- - `user_agent: optional string or null`
-
- - `agent_id: string`
-
- The agent the binding was created for, e.g. "cagt_01HX...".
-
- - `slack_channel_id: string`
-
- The Slack channel the agent was assigned to, e.g. "C01ABC...". Empty when the agent was assigned to the entire workspace.
-
- - `slack_team_id: string`
+ - `user_id: string`
- The Slack workspace the agent was assigned to, e.g. "T01ABC...".
+ Tagged ID of the member whose assignment was removed.
- `id: optional string`
@@ -141864,13 +143372,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentSlackBindingDeleted object`
+ - `CcrRoleChannelAssignmentDeleted object`
- A Claude Code agent's assignment to a Slack channel or workspace was removed.
+ CcrRoleChannelAssignmentDeleted is emitted when an org owner/admin removes an RBAC role's channel assignment row (the role reverts to granting zero channels).
- - `type: optional "ccr_agent_slack_binding_deleted"`
+ - `type: optional "ccr_role_channel_assignment_deleted"`
- default: ccr_agent_slack_binding_deleted
+ default: ccr_role_channel_assignment_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -142078,17 +143586,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `agent_id: string`
-
- The agent the binding was removed from, e.g. "cagt_01HX...".
-
- - `slack_channel_id: string`
+ - `previous_channel_count: number`
- The Slack channel the agent was unassigned from, e.g. "C01ABC...". Empty when the assignment covered the entire workspace.
+ Number of (team, channel) pairs the role was assigned before deletion.
- - `slack_team_id: string`
+ - `role_id: string`
- The Slack workspace the agent was unassigned from, e.g. "T01ABC...".
+ Tagged ID of the role whose channel assignment was removed.
- `id: optional string`
@@ -142108,13 +143612,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrAgentUpdated object`
+ - `CcrRoleChannelAssignmentUpdated object`
- A Claude Code agent's configuration was updated. Also emitted with updated_fields ["is_virtual"] alone when an auto-provisioned agent is promoted to a configured one, whether by an update request targeting it or by binding an agent proxy profile to it.
+ CcrRoleChannelAssignmentUpdated is emitted when an org owner/admin sets or replaces the list of Slack channels an RBAC role's holders may configure via the delegated Claude-in-Slack channel-manage surface.
- - `type: optional "ccr_agent_updated"`
+ - `type: optional "ccr_role_channel_assignment_updated"`
- default: ccr_agent_updated
+ default: ccr_role_channel_assignment_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -142322,36 +143826,32 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `agent_id: string`
+ - `channel_count: number`
- The agent that was updated, e.g. "cagt_01HX...".
+ Number of channels assigned after the write.
- - `default_source_urls_truncated: boolean`
+ - `previous_channel_count: number`
- Whether default_source_urls was capped and omits some of the granted repositories.
+ Number of channels assigned before the write.
- - `omitted_source_url_count: number`
+ - `role_id: string`
- Number of default repository entries that could not be safely rendered as a credential-free URL and were omitted from default_source_urls. A non-zero value with an empty list means repositories were granted but could not be displayed — not that all repositories were removed.
+ Tagged ID of the role whose channel assignment was written.
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `agent_ids: optional array of string`
+
+ The channel-silo agents (cagt_...) assigned after the write. Capped at 100 entries; channel_count carries the uncapped total.
+
- `created_at: optional string`
When this activity occurred.
format: date-time
- - `default_source_urls: optional array of string`
-
- The agent's default repository URLs after the update, reduced to scheme, host, and path — credentials and query parameters are never included. Populated only when the update changed them — "default_source_urls" appears in updated_fields. Empty while listed in updated_fields AND omitted_source_url_count is 0 means all default repositories were removed. At most 100 entries are included; default_source_urls_truncated indicates when more were granted.
-
- - `guest_policy: optional string or null`
-
- The agent's response policy for Slack channels that include guest users and Slack Connect channels shared with other organizations, after the update: "allow", "restrict", "channel" (the agent responds, using only that channel's own content and configuration), or "default" when the update removed the agent-specific policy so the agent inherits the surrounding default. In Slack Connect channels "allow" gives at most "channel" access. Present only when the update changed it.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -142360,21 +143860,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `slack_alias: optional string or null`
-
- The agent's Slack trigger word after the update. Present only when the update changed it. An empty value means the agent responds to bare "@Claude" mentions.
-
- - `updated_fields: optional array of string`
-
- Names of the configuration fields included in the update, e.g. "display_name", "system_prompt_addendum", "guest_policy". Includes "is_virtual" when this update was the first administrator action on an auto-provisioned agent — a durable state change even when no other field was supplied.
-
- - `CcrChannelManagerAdded object`
+ - `CcrSessionCreated object`
- An org owner/admin assigned an organization member to manage the Claude-in-Slack configuration of one Slack channel.
+ A Claude Code session was created. A session is one coding interaction with Claude.
- - `type: optional "ccr_channel_manager_added"`
+ - `type: optional "ccr_session_created"`
- default: ccr_channel_manager_added
+ default: ccr_session_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -142582,26 +144074,18 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `agent_id: string`
-
- The channel's Claude agent (cagt_...) the assignment is recorded against.
-
- - `slack_channel_id: string`
-
- The Slack channel the member may now manage, e.g. "C01ABC...".
-
- - `slack_team_id: string`
-
- The Slack workspace containing the channel, e.g. "T01ABC...".
-
- - `user_id: string`
+ - `session_id: string`
- Tagged ID of the member who was assigned.
+ The session that was created, e.g. "cse_01HX...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `agent_id: optional string or null`
+
+ The Claude Code agent attached to the session, e.g. "cagt_01HX...". Omitted when the session was created without an agent.
+
- `created_at: optional string`
When this activity occurred.
@@ -142616,13 +144100,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrChannelManagerRemoved object`
+ - `CcrSessionDeleted object`
- An org owner/admin removed an organization member's assignment to manage the Claude-in-Slack configuration of one Slack channel.
+ A Claude Code session was deleted.
- - `type: optional "ccr_channel_manager_removed"`
+ - `type: optional "ccr_session_deleted"`
- default: ccr_channel_manager_removed
+ default: ccr_session_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -142830,21 +144314,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `agent_id: string`
-
- The channel's Claude agent (cagt_...) the assignment was recorded against.
-
- - `slack_channel_id: string`
-
- The Slack channel the member managed, e.g. "C01ABC...".
-
- - `slack_team_id: string`
-
- The Slack workspace containing the channel, e.g. "T01ABC...".
-
- - `user_id: string`
+ - `session_id: string`
- Tagged ID of the member whose assignment was removed.
+ The session that was deleted, e.g. "cse_01HX...".
- `id: optional string`
@@ -142864,13 +144336,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrRoleChannelAssignmentDeleted object`
+ - `CcrSessionUpdated object`
- CcrRoleChannelAssignmentDeleted is emitted when an org owner/admin removes an RBAC role's channel assignment row (the role reverts to granting zero channels).
+ A Claude Code session's settings were updated.
- - `type: optional "ccr_role_channel_assignment_deleted"`
+ - `type: optional "ccr_session_updated"`
- default: ccr_role_channel_assignment_deleted
+ default: ccr_session_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -143078,13 +144550,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `previous_channel_count: number`
-
- Number of (team, channel) pairs the role was assigned before deletion.
-
- - `role_id: string`
+ - `session_id: string`
- Tagged ID of the role whose channel assignment was removed.
+ The session that was updated, e.g. "cse_01HX...".
- `id: optional string`
@@ -143104,13 +144572,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrRoleChannelAssignmentUpdated object`
+ - `updated_fields: optional array of string`
- CcrRoleChannelAssignmentUpdated is emitted when an org owner/admin sets or replaces the list of Slack channels an RBAC role's holders may configure via the delegated Claude-in-Slack channel-manage surface.
+ Names of the fields included in the update, e.g. "add_tags", "remove_tags".
- - `type: optional "ccr_role_channel_assignment_updated"`
+ - `CcrSlackChannelJoined object`
- default: ccr_role_channel_assignment_updated
+ Claude's Slack app joined a public Slack channel at an organization administrator's request.
+
+ - `type: optional "ccr_slack_channel_joined"`
+
+ default: ccr_slack_channel_joined
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -143318,26 +144790,18 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `channel_count: number`
-
- Number of channels assigned after the write.
-
- - `previous_channel_count: number`
+ - `slack_channel_id: string`
- Number of channels assigned before the write.
+ The Slack channel the app joined, e.g. "C01ABC...".
- - `role_id: string`
+ - `slack_team_id: string`
- Tagged ID of the role whose channel assignment was written.
+ The Slack workspace containing the channel, e.g. "T01ABC...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `agent_ids: optional array of string`
-
- The channel-silo agents (cagt_...) assigned after the write. Capped at 100 entries; channel_count carries the uncapped total.
-
- `created_at: optional string`
When this activity occurred.
@@ -143352,13 +144816,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrSessionCreated object`
+ - `ClaudeChatSettingsUpdated object`
- A Claude Code session was created. A session is one coding interaction with Claude.
+ User updated the settings for a conversation.
- - `type: optional "ccr_session_created"`
+ - `type: optional "claude_chat_settings_updated"`
- default: ccr_session_created
+ default: claude_chat_settings_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -143566,17 +145030,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `session_id: string`
+ - `claude_chat_id: string`
- The session that was created, e.g. "cse_01HX...".
+ Tagged ID of the conversation whose settings were updated, e.g. "claude_chat_01HX...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `agent_id: optional string or null`
+ - `claude_project_id: optional string or null`
- The Claude Code agent attached to the session, e.g. "cagt_01HX...". Omitted when the session was created without an agent.
+ Project ID this chat belongs to, if any
- `created_at: optional string`
@@ -143592,13 +145056,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrSessionDeleted object`
+ - `ClaudeChatSnapshotCreated object`
- A Claude Code session was deleted.
+ User created/shared a chat snapshot.
- - `type: optional "ccr_session_deleted"`
+ - `type: optional "claude_chat_snapshot_created"`
- default: ccr_session_deleted
+ default: claude_chat_snapshot_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -143806,9 +145270,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `session_id: string`
+ - `claude_chat_id: string`
- The session that was deleted, e.g. "cse_01HX...".
+ - `claude_chat_snapshot_id: string`
- `id: optional string`
@@ -143828,13 +145292,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `CcrSessionUpdated object`
+ - `ClaudeChatSnapshotDeleted object`
- A Claude Code session's settings were updated.
+ User deleted/unshared a chat snapshot.
- - `type: optional "ccr_session_updated"`
+ - `type: optional "claude_chat_snapshot_deleted"`
- default: ccr_session_updated
+ default: claude_chat_snapshot_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -144042,14 +145506,14 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `session_id: string`
-
- The session that was updated, e.g. "cse_01HX...".
+ - `claude_chat_snapshot_id: string`
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `claude_chat_id: optional string or null`
+
- `created_at: optional string`
When this activity occurred.
@@ -144064,17 +145528,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `updated_fields: optional array of string`
-
- Names of the fields included in the update, e.g. "add_tags", "remove_tags".
-
- - `CcrSlackChannelJoined object`
+ - `ClaudeChatSnapshotViewed object`
- Claude's Slack app joined a public Slack channel at an organization administrator's request.
+ User viewed a chat snapshot (authenticated or public/unauthenticated).
- - `type: optional "ccr_slack_channel_joined"`
+ - `type: optional "claude_chat_snapshot_viewed"`
- default: ccr_slack_channel_joined
+ default: claude_chat_snapshot_viewed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -144282,18 +145742,14 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `slack_channel_id: string`
-
- The Slack channel the app joined, e.g. "C01ABC...".
-
- - `slack_team_id: string`
-
- The Slack workspace containing the channel, e.g. "T01ABC...".
+ - `claude_chat_snapshot_id: string`
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `claude_chat_id: optional string or null`
+
- `created_at: optional string`
When this activity occurred.
@@ -144308,13 +145764,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeChatSettingsUpdated object`
+ - `ClaudeArtifactDuplicated object`
- User updated the settings for a conversation.
+ A user duplicated an artifact they could view into a new artifact that they own. The actor is the user who created the copy; the source artifact is not modified.
- - `type: optional "claude_chat_settings_updated"`
+ - `type: optional "claude_artifact_duplicated"`
- default: claude_chat_settings_updated
+ default: claude_artifact_duplicated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -144522,17 +145978,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_chat_id: string`
+ - `claude_artifact_id: string`
- Tagged ID of the conversation whose settings were updated, e.g. "claude_chat_01HX...".
+ Tagged ID of the new artifact created by the duplication. It is owned by the actor and is independent of the source artifact.
- - `id: optional string`
+ - `source_claude_artifact_id: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ Tagged ID of the artifact that was copied.
- - `claude_project_id: optional string or null`
+ - `id: optional string`
- Project ID this chat belongs to, if any
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -144548,13 +146004,27 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeChatSnapshotCreated object`
+ - `source_claude_artifact_version_id: optional string or null`
- User created/shared a chat snapshot.
+ The version of the source artifact that was copied into the new artifact.
- - `type: optional "claude_chat_snapshot_created"`
+ - `ClaudeArtifactExternalSharingPermissionUpdated object`
- default: claude_chat_snapshot_created
+ An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.
+
+ - `type: optional "claude_artifact_external_sharing_permission_updated"`
+
+ default: claude_artifact_external_sharing_permission_updated
+
+ - `action: "allowed" or "revoked" or "unspecified"`
+
+ Whether the permission was allowed or revoked.
+
+ - `"allowed"`
+
+ - `"revoked"`
+
+ - `"unspecified"`
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -144762,9 +146232,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_chat_id: string`
+ - `claude_artifact_id: string`
- - `claude_chat_snapshot_id: string`
+ Tagged ID of the artifact.
- `id: optional string`
@@ -144784,13 +146254,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeChatSnapshotDeleted object`
+ - `ClaudeChatAccessFailed object`
- User deleted/unshared a chat snapshot.
+ A user was denied access to a Claude.ai chat conversation.
- - `type: optional "claude_chat_snapshot_deleted"`
+ - `type: optional "claude_chat_access_failed"`
- default: claude_chat_snapshot_deleted
+ default: claude_chat_access_failed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -144998,14 +146468,14 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_chat_snapshot_id: string`
+ - `claude_chat_id: string`
+
+ The chat conversation the user was denied access to, e.g. "claude_chat_01Ab...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `claude_chat_id: optional string or null`
-
- `created_at: optional string`
When this activity occurred.
@@ -145020,13 +146490,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeChatSnapshotViewed object`
+ - `ClaudeChatCreated object`
- User viewed a chat snapshot (authenticated or public/unauthenticated).
+ User created a chat.
- - `type: optional "claude_chat_snapshot_viewed"`
+ - `type: optional "claude_chat_created"`
- default: claude_chat_snapshot_viewed
+ default: claude_chat_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -145234,13 +146704,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_chat_snapshot_id: string`
+ - `claude_chat_id: string`
+
+ Tagged ID of the created conversation, e.g. "claude_chat_01HX...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `claude_chat_id: optional string or null`
+ - `claude_project_id: optional string or null`
+
+ Tagged ID of the project the chat was created in, if any, e.g. "claude_proj_01HX...".
- `created_at: optional string`
@@ -145256,13 +146730,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeArtifactDuplicated object`
+ - `ClaudeChatDeleted object`
- A user duplicated an artifact they could view into a new artifact that they own. The actor is the user who created the copy; the source artifact is not modified.
+ A user deleted a Claude.ai chat conversation.
- - `type: optional "claude_artifact_duplicated"`
+ - `type: optional "claude_chat_deleted"`
- default: claude_artifact_duplicated
+ default: claude_chat_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -145470,18 +146944,18 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_artifact_id: string`
-
- Tagged ID of the new artifact created by the duplication. It is owned by the actor and is independent of the source artifact.
-
- - `source_claude_artifact_id: string`
+ - `claude_chat_id: string`
- Tagged ID of the artifact that was copied.
+ The chat conversation that was deleted, e.g. "claude_chat_01HX...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `claude_project_id: optional string or null`
+
+ The project the chat belonged to, if any, e.g. "claude_proj_01HX...".
+
- `created_at: optional string`
When this activity occurred.
@@ -145496,27 +146970,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `source_claude_artifact_version_id: optional string or null`
-
- The version of the source artifact that was copied into the new artifact.
-
- - `ClaudeArtifactExternalSharingPermissionUpdated object`
-
- An organization admin allowed one artifact to be shared outside the organization by link while the organization-wide external sharing setting was off, or revoked that permission.
-
- - `type: optional "claude_artifact_external_sharing_permission_updated"`
-
- default: claude_artifact_external_sharing_permission_updated
-
- - `action: "allowed" or "revoked" or "unspecified"`
-
- Whether the permission was allowed or revoked.
+ - `ClaudeChatDeletionFailed object`
- - `"allowed"`
+ A request to delete a Claude.ai chat conversation failed.
- - `"revoked"`
+ - `type: optional "claude_chat_deletion_failed"`
- - `"unspecified"`
+ default: claude_chat_deletion_failed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -145724,9 +147184,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_artifact_id: string`
+ - `claude_chat_id: string`
- Tagged ID of the artifact.
+ The chat conversation the user attempted to delete, e.g. "claude_chat_01HX...".
- `id: optional string`
@@ -145746,13 +147206,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeChatAccessFailed object`
+ - `ClaudeChatSyncSourceCreated object`
- A user was denied access to a Claude.ai chat conversation.
+ A sync source was connected for syncing external content into Claude chats.
- - `type: optional "claude_chat_access_failed"`
+ - `type: optional "claude_chat_sync_source_created"`
- default: claude_chat_access_failed
+ default: claude_chat_sync_source_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -145960,9 +147420,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_chat_id: string`
+ - `claude_chat_sync_source_id: string`
- The chat conversation the user was denied access to, e.g. "claude_chat_01Ab...".
+ Tagged ID of the chat-scoped sync source that was created.
+
+ - `provider: string`
+
+ The external provider backing the sync source, e.g. `github`, `google_drive`, `outline`, `slack`, `salesforce`, `google_calendar`, `gmail`, `asana`, or `mcp_resources`.
- `id: optional string`
@@ -145982,13 +147446,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeChatCreated object`
+ - `resource_descriptor: optional string or null`
- User created a chat.
+ A short provider-specific identifier for the external resource that was connected, e.g. `owner/repo` for GitHub or a file ID for Google Drive.
- - `type: optional "claude_chat_created"`
+ - `ClaudeChatSyncSourceDeleted object`
- default: claude_chat_created
+ A sync source was disconnected from Claude chats.
+
+ - `type: optional "claude_chat_sync_source_deleted"`
+
+ default: claude_chat_sync_source_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -146196,17 +147664,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_chat_id: string`
+ - `claude_chat_sync_source_id: string`
- Tagged ID of the created conversation, e.g. "claude_chat_01HX...".
+ Tagged ID of the chat-scoped sync source that was deleted.
- - `id: optional string`
+ - `provider: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ The external provider backing the sync source. Always `unspecified` for deletion events.
- - `claude_project_id: optional string or null`
+ - `id: optional string`
- Tagged ID of the project the chat was created in, if any, e.g. "claude_proj_01HX...".
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -146222,13 +147690,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeChatDeleted object`
+ - `ClaudeChatSyncSourceUpdated object`
- A user deleted a Claude.ai chat conversation.
+ A Claude chat sync source's configuration was updated.
- - `type: optional "claude_chat_deleted"`
+ - `type: optional "claude_chat_sync_source_updated"`
- default: claude_chat_deleted
+ default: claude_chat_sync_source_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -146436,17 +147904,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_chat_id: string`
+ - `claude_chat_sync_source_id: string`
- The chat conversation that was deleted, e.g. "claude_chat_01HX...".
+ Tagged ID of the chat-scoped sync source that was updated.
+
+ - `provider: string`
+
+ The external provider backing the sync source, e.g. `github`, `google_drive`, `outline`, `slack`, `salesforce`, `google_calendar`, `gmail`, `asana`, or `mcp_resources`.
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `claude_project_id: optional string or null`
+ - `config_changed: optional boolean or null`
- The project the chat belonged to, if any, e.g. "claude_proj_01HX...".
+ Whether the update changed the stored sync-source configuration, including sync settings such as path filters. False for a re-sync or a metadata-only refresh of the same resource.
- `created_at: optional string`
@@ -146462,13 +147934,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeChatDeletionFailed object`
+ - `resource_descriptor: optional string or null`
- A request to delete a Claude.ai chat conversation failed.
+ A short provider-specific identifier for the external resource after the update, e.g. `owner/repo` for GitHub or a file ID for Google Drive.
- - `type: optional "claude_chat_deletion_failed"`
+ - `ClaudeChatUpdated object`
- default: claude_chat_deletion_failed
+ User updated the chat metadata (e.g name, model).
+
+ - `type: optional "claude_chat_updated"`
+
+ default: claude_chat_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -146678,12 +148154,16 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `claude_chat_id: string`
- The chat conversation the user attempted to delete, e.g. "claude_chat_01HX...".
+ Tagged ID of the updated conversation, e.g. "claude_chat_01HX...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `claude_project_id: optional string or null`
+
+ Tagged ID of the project the chat belongs to, if any, e.g. "claude_proj_01HX...".
+
- `created_at: optional string`
When this activity occurred.
@@ -146698,13 +148178,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeChatSyncSourceCreated object`
+ - `ClaudeChatViewed object`
- A sync source was connected for syncing external content into Claude chats.
+ A user viewed a Claude.ai chat conversation.
- - `type: optional "claude_chat_sync_source_created"`
+ - `type: optional "claude_chat_viewed"`
- default: claude_chat_sync_source_created
+ default: claude_chat_viewed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -146912,18 +148392,18 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_chat_sync_source_id: string`
-
- Tagged ID of the chat-scoped sync source that was created.
-
- - `provider: string`
+ - `claude_chat_id: string`
- The external provider backing the sync source, e.g. `github`, `google_drive`, `outline`, `slack`, `salesforce`, `google_calendar`, `gmail`, `asana`, or `mcp_resources`.
+ The chat conversation that was viewed, e.g. "claude_chat_01Ab...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `claude_project_id: optional string or null`
+
+ The project the chat belongs to, if any, e.g. "claude_proj_01Ab...".
+
- `created_at: optional string`
When this activity occurred.
@@ -146938,17 +148418,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `resource_descriptor: optional string or null`
-
- A short provider-specific identifier for the external resource that was connected, e.g. `owner/repo` for GitHub or a file ID for Google Drive.
-
- - `ClaudeChatSyncSourceDeleted object`
+ - `ClaudeCodeCredentialRevoked object`
- A sync source was disconnected from Claude chats.
+ A Claude Code credential (runner pool key, runner token, or session token) was revoked. The credential itself is never recorded.
- - `type: optional "claude_chat_sync_source_deleted"`
+ - `type: optional "claude_code_credential_revoked"`
- default: claude_chat_sync_source_deleted
+ default: claude_code_credential_revoked
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -147156,24 +148632,40 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_chat_sync_source_id: string`
+ - `credential_type: "runner_pool_key" or "runner_token" or "session_token" or "unspecified"`
- Tagged ID of the chat-scoped sync source that was deleted.
+ The kind of credential the revoked target identifies, when known. Subject-targeted revocations cascade to every credential delegated from the target regardless of kind; this field describes the target itself, not the full set of credentials the cascade reached. For a revocation submitted as a pasted credential the kind is best-effort and may be inaccurate; the recorded jti and the revocation itself are unaffected.
- - `provider: string`
+ - `"runner_pool_key"`
- The external provider backing the sync source. Always `unspecified` for deletion events.
+ - `"runner_token"`
+
+ - `"session_token"`
+
+ - `"unspecified"`
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `agent_id: optional string or null`
+
+ The agent identity whose Claude Code credentials were revoked, when revocation targeted every session created by an agent identity, e.g. "cagt_01HX...".
+
- `created_at: optional string`
When this activity occurred.
format: date-time
+ - `delegating_jti: optional string or null`
+
+ The credential identifier whose delegated credentials were revoked (a chain revoke): every credential delegated from this one was revoked, but the credential itself was not. Distinct from `jti`, which records a revocation of the credential itself and its delegates.
+
+ - `jti: optional string or null`
+
+ The unique identifier of the revoked credential, recorded in its canonical form. Revoking a runner pool key also revokes every runner and session token delegated from it. A revocation submitted as a pasted credential is recorded by that credential's identifier.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -147182,13 +148674,29 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeChatSyncSourceUpdated object`
+ - `runner_id: optional string or null`
- A Claude chat sync source's configuration was updated.
+ The runner whose credentials were revoked, when revocation targeted every credential delegated from the runner, e.g. "ccrunner_01HX...".
- - `type: optional "claude_chat_sync_source_updated"`
+ - `runner_pool_id: optional string or null`
- default: claude_chat_sync_source_updated
+ The runner pool whose credentials were revoked, when revocation targeted every credential delegated from the pool, e.g. "ccpool_01HX...".
+
+ - `session_id: optional string or null`
+
+ The session whose credentials were revoked, when revocation targeted every credential delegated from the session, e.g. "cse_01HX...".
+
+ - `user_id: optional string or null`
+
+ The user whose Claude Code credentials were revoked, when revocation targeted every credential minted for a user. Carries the user's tagged account ID, e.g. "user_01HX..." — the only form the revocation API accepts, so the field joins against other activities' account identifiers and never carries an email.
+
+ - `ClaudeCodeReviewConfigUpdated object`
+
+ Claude Code Review configuration was enabled/disabled for an org.
+
+ - `type: optional "claude_code_review_config_updated"`
+
+ default: claude_code_review_config_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -147396,28 +148904,28 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_chat_sync_source_id: string`
-
- Tagged ID of the chat-scoped sync source that was updated.
-
- - `provider: string`
+ - `enabled: boolean`
- The external provider backing the sync source, e.g. `github`, `google_drive`, `outline`, `slack`, `salesforce`, `google_calendar`, `gmail`, `asana`, or `mcp_resources`.
+ Whether code review is now enabled
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `config_changed: optional boolean or null`
-
- Whether the update changed the stored sync-source configuration, including sync settings such as path filters. False for a re-sync or a metadata-only refresh of the same resource.
-
- `created_at: optional string`
When this activity occurred.
format: date-time
+ - `environment_id: optional string or null`
+
+ Environment used for code review
+
+ - `model: optional string or null`
+
+ Model configured for code review
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -147426,17 +148934,49 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `resource_descriptor: optional string or null`
+ - `per_review_limit_usd: optional string or null`
- A short provider-specific identifier for the external resource after the update, e.g. `owner/repo` for GitHub or a file ID for Google Drive.
+ Per-review spend limit in USD
- - `ClaudeChatUpdated object`
+ - `previous_enabled: optional boolean or null`
- User updated the chat metadata (e.g name, model).
+ Whether code review was enabled before the change. Absent when no configuration existed before this update.
- - `type: optional "claude_chat_updated"`
+ - `previous_environment_id: optional string or null`
- default: claude_chat_updated
+ Environment used for code review before the change. Absent when no configuration existed before this update or no environment was set.
+
+ - `previous_model: optional string or null`
+
+ Model configured for code review before the change. Absent when no configuration existed before this update or no model was set.
+
+ - `previous_per_review_limit_usd: optional string or null`
+
+ Per-review spend limit in USD before the change. Absent when no configuration existed before this update or no limit was set.
+
+ - `previous_show_tips: optional boolean or null`
+
+ Whether tip-style pull-request comments were enabled before the change. Absent when no configuration existed before this update.
+
+ - `previous_verification_enabled: optional boolean or null`
+
+ Whether the verification stage of code review was enabled for the organization before the change. Absent when no configuration existed before this update or no preference was set.
+
+ - `show_tips: optional boolean or null`
+
+ Whether tip-style pull-request comments are now enabled
+
+ - `verification_enabled: optional boolean or null`
+
+ Whether the verification stage of code review is now enabled for the organization. Absent when the organization has not set a preference and the default applies.
+
+ - `ClaudeCodeReviewRepositoryAdded object`
+
+ A repository was added to org-level Claude Code Review configuration.
+
+ - `type: optional "claude_code_review_repository_added"`
+
+ default: claude_code_review_repository_added
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -147644,17 +149184,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_chat_id: string`
+ - `config_id: string`
- Tagged ID of the updated conversation, e.g. "claude_chat_01HX...".
+ ID of the repository configuration
- - `id: optional string`
+ - `repo_name: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ Repository name
- - `claude_project_id: optional string or null`
+ - `repo_owner: string`
- Tagged ID of the project the chat belongs to, if any, e.g. "claude_proj_01HX...".
+ Repository owner (GitHub org/user)
+
+ - `trigger_mode: string`
+
+ When code review is triggered
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -147670,13 +149218,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeChatViewed object`
+ - `ClaudeCodeReviewRepositoryRemoved object`
- A user viewed a Claude.ai chat conversation.
+ A repository was removed from org-level Claude Code Review configuration.
- - `type: optional "claude_chat_viewed"`
+ - `type: optional "claude_code_review_repository_removed"`
- default: claude_chat_viewed
+ default: claude_code_review_repository_removed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -147884,17 +149432,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_chat_id: string`
+ - `config_id: string`
- The chat conversation that was viewed, e.g. "claude_chat_01Ab...".
+ ID of the deleted repository configuration
- - `id: optional string`
+ - `repo_name: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ Repository name at deletion time
- - `claude_project_id: optional string or null`
+ - `repo_owner: string`
- The project the chat belongs to, if any, e.g. "claude_proj_01Ab...".
+ Repository owner at deletion time
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -147910,13 +149462,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeCredentialRevoked object`
+ - `ClaudeCodeReviewRepositoryUpdated object`
- A Claude Code credential (runner pool key, runner token, or session token) was revoked. The credential itself is never recorded.
+ A Claude Code Review repository configuration was updated.
- - `type: optional "claude_code_credential_revoked"`
+ - `type: optional "claude_code_review_repository_updated"`
- default: claude_code_credential_revoked
+ default: claude_code_review_repository_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -148124,40 +149676,28 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `credential_type: "runner_pool_key" or "runner_token" or "session_token" or "unspecified"`
+ - `config_id: string`
- The kind of credential the revoked target identifies, when known. Subject-targeted revocations cascade to every credential delegated from the target regardless of kind; this field describes the target itself, not the full set of credentials the cascade reached. For a revocation submitted as a pasted credential the kind is best-effort and may be inaccurate; the recorded jti and the revocation itself are unaffected.
+ ID of the repository configuration
- - `"runner_pool_key"`
+ - `repo_name: string`
- - `"runner_token"`
+ Repository name
- - `"session_token"`
+ - `repo_owner: string`
- - `"unspecified"`
+ Repository owner
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `agent_id: optional string or null`
-
- The agent identity whose Claude Code credentials were revoked, when revocation targeted every session created by an agent identity, e.g. "cagt_01HX...".
-
- `created_at: optional string`
When this activity occurred.
format: date-time
- - `delegating_jti: optional string or null`
-
- The credential identifier whose delegated credentials were revoked (a chain revoke): every credential delegated from this one was revoked, but the credential itself was not. Distinct from `jti`, which records a revocation of the credential itself and its delegates.
-
- - `jti: optional string or null`
-
- The unique identifier of the revoked credential, recorded in its canonical form. Revoking a runner pool key also revokes every runner and session token delegated from it. A revocation submitted as a pasted credential is recorded by that credential's identifier.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -148166,29 +149706,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `runner_id: optional string or null`
-
- The runner whose credentials were revoked, when revocation targeted every credential delegated from the runner, e.g. "ccrunner_01HX...".
-
- - `runner_pool_id: optional string or null`
-
- The runner pool whose credentials were revoked, when revocation targeted every credential delegated from the pool, e.g. "ccpool_01HX...".
-
- - `session_id: optional string or null`
+ - `status: optional string or null`
- The session whose credentials were revoked, when revocation targeted every credential delegated from the session, e.g. "cse_01HX...".
+ Updated status (ACTIVE/INACTIVE)
- - `user_id: optional string or null`
+ - `trigger_mode: optional string or null`
- The user whose Claude Code credentials were revoked, when revocation targeted every credential minted for a user. Carries the user's tagged account ID, e.g. "user_01HX..." — the only form the revocation API accepts, so the field joins against other activities' account identifiers and never carries an email.
+ Updated trigger mode
- - `ClaudeCodeReviewConfigUpdated object`
+ - `ClaudeCodeRunnerDeleted object`
- Claude Code Review configuration was enabled/disabled for an org.
+ A self-hosted runner was forcibly removed from its pool. Sessions assigned to the runner were returned to the pool queue, unless a session had already been requeued repeatedly, in which case it was marked stuck instead of being requeued again.
- - `type: optional "claude_code_review_config_updated"`
+ - `type: optional "claude_code_runner_deleted"`
- default: claude_code_review_config_updated
+ default: claude_code_runner_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -148396,9 +149928,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `enabled: boolean`
+ - `runner_id: string`
- Whether code review is now enabled
+ The runner that was removed, e.g. "ccrunner_01HX...".
- `id: optional string`
@@ -148410,14 +149942,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `environment_id: optional string or null`
-
- Environment used for code review
-
- - `model: optional string or null`
-
- Model configured for code review
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -148426,49 +149950,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `per_review_limit_usd: optional string or null`
-
- Per-review spend limit in USD
-
- - `previous_enabled: optional boolean or null`
-
- Whether code review was enabled before the change. Absent when no configuration existed before this update.
-
- - `previous_environment_id: optional string or null`
-
- Environment used for code review before the change. Absent when no configuration existed before this update or no environment was set.
-
- - `previous_model: optional string or null`
-
- Model configured for code review before the change. Absent when no configuration existed before this update or no model was set.
-
- - `previous_per_review_limit_usd: optional string or null`
-
- Per-review spend limit in USD before the change. Absent when no configuration existed before this update or no limit was set.
-
- - `previous_show_tips: optional boolean or null`
-
- Whether tip-style pull-request comments were enabled before the change. Absent when no configuration existed before this update.
-
- - `previous_verification_enabled: optional boolean or null`
-
- Whether the verification stage of code review was enabled for the organization before the change. Absent when no configuration existed before this update or no preference was set.
-
- - `show_tips: optional boolean or null`
-
- Whether tip-style pull-request comments are now enabled
-
- - `verification_enabled: optional boolean or null`
+ - `runner_pool_id: optional string or null`
- Whether the verification stage of code review is now enabled for the organization. Absent when the organization has not set a preference and the default applies.
+ The pool the runner was removed from, e.g. "ccpool_01HX...".
- - `ClaudeCodeReviewRepositoryAdded object`
+ - `ClaudeCodeRunnerPoolCreated object`
- A repository was added to org-level Claude Code Review configuration.
+ A self-hosted runner pool for Claude Code was created.
- - `type: optional "claude_code_review_repository_added"`
+ - `type: optional "claude_code_runner_pool_created"`
- default: claude_code_review_repository_added
+ default: claude_code_runner_pool_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -148676,21 +150168,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `config_id: string`
-
- ID of the repository configuration
-
- - `repo_name: string`
-
- Repository name
-
- - `repo_owner: string`
+ - `display_name: string`
- Repository owner (GitHub org/user)
+ The display name the pool was created with.
- - `trigger_mode: string`
+ - `runner_pool_id: string`
- When code review is triggered
+ The runner pool that was created, e.g. "ccpool_01HX...".
- `id: optional string`
@@ -148710,13 +150194,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeReviewRepositoryRemoved object`
+ - `ClaudeCodeRunnerPoolDeleted object`
- A repository was removed from org-level Claude Code Review configuration.
+ A self-hosted runner pool was deleted.
- - `type: optional "claude_code_review_repository_removed"`
+ - `type: optional "claude_code_runner_pool_deleted"`
- default: claude_code_review_repository_removed
+ default: claude_code_runner_pool_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -148924,17 +150408,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `config_id: string`
-
- ID of the deleted repository configuration
-
- - `repo_name: string`
-
- Repository name at deletion time
-
- - `repo_owner: string`
+ - `runner_pool_id: string`
- Repository owner at deletion time
+ The runner pool that was deleted, e.g. "ccpool_01HX...".
- `id: optional string`
@@ -148946,6 +150422,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `display_name: optional string or null`
+
+ The pool's display name at deletion time.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -148954,13 +150434,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeReviewRepositoryUpdated object`
+ - `ClaudeCodeRunnerPoolSecretMinted object`
- A Claude Code Review repository configuration was updated.
+ A registration key for a self-hosted runner pool was minted. Runners present this key to join the pool. The key itself is never recorded.
- - `type: optional "claude_code_review_repository_updated"`
+ - `type: optional "claude_code_runner_pool_secret_minted"`
- default: claude_code_review_repository_updated
+ default: claude_code_runner_pool_secret_minted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -149168,17 +150648,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `config_id: string`
-
- ID of the repository configuration
-
- - `repo_name: string`
+ - `jti: string`
- Repository name
+ The minted key's unique identifier (its JWT `jti` claim), usable to revoke that key later.
- - `repo_owner: string`
+ - `runner_pool_id: string`
- Repository owner
+ The runner pool the key was minted for, e.g. "ccpool_01HX...".
- `id: optional string`
@@ -149190,6 +150666,16 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `expires_at: optional string or null`
+
+ When the minted key expires.
+
+ format: date-time
+
+ - `label: optional string or null`
+
+ The label the key was minted with. The key minted automatically when a pool is created carries the label "Initial key".
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -149198,21 +150684,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `status: optional string or null`
+ - `ClaudeCodeRunnerPoolSessionQueueUpdated object`
- Updated status (ACTIVE/INACTIVE)
+ An admin changed a session's position in its self-hosted runner pool's queue: requeued it onto a different runner, dismissed it from the queue, or re-admitted it for another runner provisioning attempt.
- - `trigger_mode: optional string or null`
+ - `type: optional "claude_code_runner_pool_session_queue_updated"`
- Updated trigger mode
+ default: claude_code_runner_pool_session_queue_updated
- - `ClaudeCodeRunnerDeleted object`
+ - `action: "dismissed" or "provisioning_retried" or "requeued" or "unspecified"`
- A self-hosted runner was forcibly removed from its pool. Sessions assigned to the runner were returned to the pool queue, unless a session had already been requeued repeatedly, in which case it was marked stuck instead of being requeued again.
+ What changed about the session's queue state.
- - `type: optional "claude_code_runner_deleted"`
+ - `"dismissed"`
- default: claude_code_runner_deleted
+ - `"provisioning_retried"`
+
+ - `"requeued"`
+
+ - `"unspecified"`
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -149420,9 +150910,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `runner_id: string`
+ - `session_id: string`
- The runner that was removed, e.g. "ccrunner_01HX...".
+ The session whose queue state changed, e.g. "cse_01HX...".
- `id: optional string`
@@ -149434,6 +150924,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `excluded_runner_id: optional string or null`
+
+ The runner the session was moved off, when action is "requeued", e.g. "ccrunner_01HX...".
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -149444,15 +150938,15 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `runner_pool_id: optional string or null`
- The pool the runner was removed from, e.g. "ccpool_01HX...".
+ The runner pool whose queue the session is in, when known, e.g. "ccpool_01HX...".
- - `ClaudeCodeRunnerPoolCreated object`
+ - `ClaudeCodeRunnerPoolUpdated object`
- A self-hosted runner pool for Claude Code was created.
+ A self-hosted runner pool's settings were updated.
- - `type: optional "claude_code_runner_pool_created"`
+ - `type: optional "claude_code_runner_pool_updated"`
- default: claude_code_runner_pool_created
+ default: claude_code_runner_pool_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -149662,11 +151156,11 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `display_name: string`
- The display name the pool was created with.
+ The pool's display name after the update.
- `runner_pool_id: string`
- The runner pool that was created, e.g. "ccpool_01HX...".
+ The runner pool that was updated, e.g. "ccpool_01HX...".
- `id: optional string`
@@ -149686,13 +151180,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeRunnerPoolDeleted object`
+ - `previous_display_name: optional string or null`
- A self-hosted runner pool was deleted.
+ The pool's display name before the update. Absent when the name was unchanged or the previous value was unavailable.
- - `type: optional "claude_code_runner_pool_deleted"`
+ - `ClaudeCodeSecurityCenterConfigUpdated object`
- default: claude_code_runner_pool_deleted
+ Claude Code Security Center scanning was enabled/disabled for an org.
+
+ - `type: optional "claude_code_security_center_config_updated"`
+
+ default: claude_code_security_center_config_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -149900,9 +151398,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `runner_pool_id: string`
+ - `enabled: boolean`
- The runner pool that was deleted, e.g. "ccpool_01HX...".
+ Whether Security Center is now enabled
- `id: optional string`
@@ -149914,9 +151412,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `display_name: optional string or null`
+ - `environment_id: optional string or null`
- The pool's display name at deletion time.
+ Environment used for security scanning
- `organization_id: optional string or null`
@@ -149926,13 +151424,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeRunnerPoolSecretMinted object`
+ - `ClaudeCodeSecurityScanCancelled object`
- A registration key for a self-hosted runner pool was minted. Runners present this key to join the pool. The key itself is never recorded.
+ In-flight Claude Code Security scans were cancelled for a project.
- - `type: optional "claude_code_runner_pool_secret_minted"`
+ - `type: optional "claude_code_security_scan_cancelled"`
- default: claude_code_runner_pool_secret_minted
+ default: claude_code_security_scan_cancelled
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -150140,13 +151638,11 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `jti: string`
-
- The minted key's unique identifier (its JWT `jti` claim), usable to revoke that key later.
+ - `scan_project_id: string`
- - `runner_pool_id: string`
+ Tagged ID of the scan project
- The runner pool the key was minted for, e.g. "ccpool_01HX...".
+ - `scans_cancelled: number`
- `id: optional string`
@@ -150158,16 +151654,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `expires_at: optional string or null`
-
- When the minted key expires.
-
- format: date-time
-
- - `label: optional string or null`
-
- The label the key was minted with. The key minted automatically when a pool is created carries the label "Initial key".
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -150176,25 +151662,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeRunnerPoolSessionQueueUpdated object`
-
- An admin changed a session's position in its self-hosted runner pool's queue: requeued it onto a different runner, dismissed it from the queue, or re-admitted it for another runner provisioning attempt.
-
- - `type: optional "claude_code_runner_pool_session_queue_updated"`
-
- default: claude_code_runner_pool_session_queue_updated
-
- - `action: "dismissed" or "provisioning_retried" or "requeued" or "unspecified"`
-
- What changed about the session's queue state.
-
- - `"dismissed"`
+ - `ClaudeCodeSecurityScanCreated object`
- - `"provisioning_retried"`
+ A Claude Code Security scan was started.
- - `"requeued"`
+ - `type: optional "claude_code_security_scan_created"`
- - `"unspecified"`
+ default: claude_code_security_scan_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -150402,9 +151876,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `session_id: string`
+ - `scan_id: string`
- The session whose queue state changed, e.g. "cse_01HX...".
+ Tagged ID of the created scan
+
+ - `scan_project_id: string`
+
+ Tagged ID of the scan project the scan belongs to
- `id: optional string`
@@ -150416,10 +151894,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `excluded_runner_id: optional string or null`
-
- The runner the session was moved off, when action is "requeued", e.g. "ccrunner_01HX...".
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -150428,17 +151902,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `runner_pool_id: optional string or null`
+ - `ClaudeCodeSecurityScanProjectMemberUpdated object`
- The runner pool whose queue the session is in, when known, e.g. "ccpool_01HX...".
+ A person's access to a Claude Code Security scan project was granted, changed, or revoked.
- - `ClaudeCodeRunnerPoolUpdated object`
+ - `type: optional "claude_code_security_scan_project_member_updated"`
- A self-hosted runner pool's settings were updated.
+ default: claude_code_security_scan_project_member_updated
- - `type: optional "claude_code_runner_pool_updated"`
+ - `action: "member_added" or "member_removed" or "member_role_changed" or "unspecified"`
- default: claude_code_runner_pool_updated
+ Whether the member was granted access, had their role changed, or was revoked
+
+ - `"member_added"`
+
+ - `"member_removed"`
+
+ - `"member_role_changed"`
+
+ - `"unspecified"`
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -150646,18 +152128,32 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `display_name: string`
+ - `member_id: string`
- The pool's display name after the update.
+ Tagged ID of the member whose access changed
- - `runner_pool_id: string`
+ - `scan_project_id: string`
- The runner pool that was updated, e.g. "ccpool_01HX...".
+ Tagged ID of the scan project
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null`
+
+ How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved (for example, an automated change); events recorded before this field was introduced omit it.
+
+ - `"member"`
+
+ - `"organization_admin"`
+
+ - `"organization_share"`
+
+ - `"owner"`
+
+ - `"unspecified"`
+
- `created_at: optional string`
When this activity occurred.
@@ -150672,17 +152168,33 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_display_name: optional string or null`
+ - `role: optional string or null`
- The pool's display name before the update. Absent when the name was unchanged or the previous value was unavailable.
+ Role granted to the member (full, view_triage, or view); omitted for revocations
- - `ClaudeCodeSecurityCenterConfigUpdated object`
+ - `ClaudeCodeSecurityScanProjectUpdated object`
- Claude Code Security Center scanning was enabled/disabled for an org.
+ A Claude Code Security scan project was archived, unarchived, created, or migrated to a new product experience.
- - `type: optional "claude_code_security_center_config_updated"`
+ - `type: optional "claude_code_security_scan_project_updated"`
- default: claude_code_security_center_config_updated
+ default: claude_code_security_scan_project_updated
+
+ - `action: "archived" or "created" or "migrated" or 3 more`
+
+ The state change applied to the scan project.
+
+ - `"archived"`
+
+ - `"created"`
+
+ - `"migrated"`
+
+ - `"resumed"`
+
+ - `"unarchived"`
+
+ - `"unspecified"`
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -150890,24 +152402,34 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `enabled: boolean`
+ - `scan_project_id: string`
- Whether Security Center is now enabled
+ Tagged ID of the scan project
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null`
+
+ How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved (the project's creation, or an automated change); events recorded before this field was introduced omit it.
+
+ - `"member"`
+
+ - `"organization_admin"`
+
+ - `"organization_share"`
+
+ - `"owner"`
+
+ - `"unspecified"`
+
- `created_at: optional string`
When this activity occurred.
format: date-time
- - `environment_id: optional string or null`
-
- Environment used for security scanning
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -150916,13 +152438,23 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeSecurityScanCancelled object`
+ - `ClaudeCodeSecurityScanProjectVisibilityUpdated object`
- In-flight Claude Code Security scans were cancelled for a project.
+ A Claude Code Security scan project was shared with the organization or made private.
- - `type: optional "claude_code_security_scan_cancelled"`
+ - `type: optional "claude_code_security_scan_project_visibility_updated"`
- default: claude_code_security_scan_cancelled
+ default: claude_code_security_scan_project_visibility_updated
+
+ - `action: "shared" or "unshared" or "unspecified"`
+
+ Whether the project was shared with the organization or made private
+
+ - `"shared"`
+
+ - `"unshared"`
+
+ - `"unspecified"`
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -151134,12 +152666,28 @@ curl https://api.anthropic.com/v1/compliance/activities \
Tagged ID of the scan project
- - `scans_cancelled: number`
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `access_level: optional string or null`
+
+ Access level granted to organization members (read_only or full); only set when shared
+
+ - `access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null`
+
+ How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved (for example, an automated change); events recorded before this field was introduced omit it.
+
+ - `"member"`
+
+ - `"organization_admin"`
+
+ - `"organization_share"`
+
+ - `"owner"`
+
+ - `"unspecified"`
+
- `created_at: optional string`
When this activity occurred.
@@ -151154,13 +152702,29 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeSecurityScanCreated object`
+ - `ClaudeCodeSecurityScanRunUpdated object`
- A Claude Code Security scan was started.
+ A single Claude Code Security scan run was archived, unarchived, or resumed after a billing pause.
- - `type: optional "claude_code_security_scan_created"`
+ - `type: optional "claude_code_security_scan_run_updated"`
- default: claude_code_security_scan_created
+ default: claude_code_security_scan_run_updated
+
+ - `action: "archived" or "created" or "migrated" or 3 more`
+
+ The state change applied to the scan run
+
+ - `"archived"`
+
+ - `"created"`
+
+ - `"migrated"`
+
+ - `"resumed"`
+
+ - `"unarchived"`
+
+ - `"unspecified"`
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -151370,11 +152934,7 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `scan_id: string`
- Tagged ID of the created scan
-
- - `scan_project_id: string`
-
- Tagged ID of the scan project the scan belongs to
+ Tagged ID of the scan the request named — for archive/unarchive any scan in the run, not necessarily its canonical (run_index=0) scan; for resume, the paused scan
- `id: optional string`
@@ -151394,25 +152954,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeSecurityScanProjectMemberUpdated object`
-
- A person's access to a Claude Code Security scan project was granted, changed, or revoked.
-
- - `type: optional "claude_code_security_scan_project_member_updated"`
-
- default: claude_code_security_scan_project_member_updated
-
- - `action: "member_added" or "member_removed" or "member_role_changed" or "unspecified"`
-
- Whether the member was granted access, had their role changed, or was revoked
-
- - `"member_added"`
+ - `ClaudeCodeSecurityScanScheduleDeleted object`
- - `"member_removed"`
+ A recurring scan schedule was deleted for a Claude Code Security project.
- - `"member_role_changed"`
+ - `type: optional "claude_code_security_scan_schedule_deleted"`
- - `"unspecified"`
+ default: claude_code_security_scan_schedule_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -151620,10 +153168,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `member_id: string`
-
- Tagged ID of the member whose access changed
-
- `scan_project_id: string`
Tagged ID of the scan project
@@ -151632,20 +153176,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null`
-
- How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved (for example, an automated change); events recorded before this field was introduced omit it.
-
- - `"member"`
-
- - `"organization_admin"`
-
- - `"organization_share"`
-
- - `"owner"`
-
- - `"unspecified"`
-
- `created_at: optional string`
When this activity occurred.
@@ -151660,33 +153190,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `role: optional string or null`
-
- Role granted to the member (full, view_triage, or view); omitted for revocations
-
- - `ClaudeCodeSecurityScanProjectUpdated object`
-
- A Claude Code Security scan project was archived, unarchived, created, or migrated to a new product experience.
-
- - `type: optional "claude_code_security_scan_project_updated"`
-
- default: claude_code_security_scan_project_updated
-
- - `action: "archived" or "created" or "migrated" or 3 more`
-
- The state change applied to the scan project.
-
- - `"archived"`
-
- - `"created"`
-
- - `"migrated"`
+ - `ClaudeCodeSecurityScanScheduleUpdated object`
- - `"resumed"`
+ A recurring scan schedule was set or replaced for a Claude Code Security project.
- - `"unarchived"`
+ - `type: optional "claude_code_security_scan_schedule_updated"`
- - `"unspecified"`
+ default: claude_code_security_scan_schedule_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -151894,6 +153404,8 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `cadence: string`
+
- `scan_project_id: string`
Tagged ID of the scan project
@@ -151902,20 +153414,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null`
-
- How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved (the project's creation, or an automated change); events recorded before this field was introduced omit it.
-
- - `"member"`
-
- - `"organization_admin"`
-
- - `"organization_share"`
-
- - `"owner"`
-
- - `"unspecified"`
-
- `created_at: optional string`
When this activity occurred.
@@ -151930,23 +153428,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeSecurityScanProjectVisibilityUpdated object`
-
- A Claude Code Security scan project was shared with the organization or made private.
-
- - `type: optional "claude_code_security_scan_project_visibility_updated"`
-
- default: claude_code_security_scan_project_visibility_updated
-
- - `action: "shared" or "unshared" or "unspecified"`
-
- Whether the project was shared with the organization or made private
+ - `ClaudeCodeSecurityVulnerabilityDeleted object`
- - `"shared"`
+ A Claude Code Security vulnerability finding was permanently deleted.
- - `"unshared"`
+ - `type: optional "claude_code_security_vulnerability_deleted"`
- - `"unspecified"`
+ default: claude_code_security_vulnerability_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -152154,31 +153642,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `scan_project_id: string`
-
- Tagged ID of the scan project
-
- - `id: optional string`
-
- Unique identifier for the activity e.g. 'activity_abcd1234'
-
- - `access_level: optional string or null`
-
- Access level granted to organization members (read_only or full); only set when shared
-
- - `access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null`
-
- How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved (for example, an automated change); events recorded before this field was introduced omit it.
+ - `scan_id: string`
- - `"member"`
+ Tagged ID of the scan the finding belonged to
- - `"organization_admin"`
+ - `vulnerability_id: number`
- - `"organization_share"`
+ Numeric ID of the deleted finding, as shown in the product
- - `"owner"`
+ - `id: optional string`
- - `"unspecified"`
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -152194,29 +153668,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeSecurityScanRunUpdated object`
-
- A single Claude Code Security scan run was archived, unarchived, or resumed after a billing pause.
-
- - `type: optional "claude_code_security_scan_run_updated"`
-
- default: claude_code_security_scan_run_updated
-
- - `action: "archived" or "created" or "migrated" or 3 more`
-
- The state change applied to the scan run
-
- - `"archived"`
-
- - `"created"`
-
- - `"migrated"`
+ - `ClaudeCodeSecurityVulnerabilityFixSessionCreated object`
- - `"resumed"`
+ A Claude Code remediation session was created for a Claude Code Security vulnerability finding.
- - `"unarchived"`
+ - `type: optional "claude_code_security_vulnerability_fix_session_created"`
- - `"unspecified"`
+ default: claude_code_security_vulnerability_fix_session_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -152426,12 +153884,30 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `scan_id: string`
- Tagged ID of the scan the request named — for archive/unarchive any scan in the run, not necessarily its canonical (run_index=0) scan; for resume, the paused scan
+ Tagged ID of the scan the finding belongs to
+
+ - `session_id: string`
+
+ ID of the created remediation session
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null`
+
+ How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved; events recorded before this field was introduced omit it.
+
+ - `"member"`
+
+ - `"organization_admin"`
+
+ - `"organization_share"`
+
+ - `"owner"`
+
+ - `"unspecified"`
+
- `created_at: optional string`
When this activity occurred.
@@ -152446,13 +153922,27 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeSecurityScanScheduleDeleted object`
+ - `ClaudeCodeSecurityVulnerabilityUpdated object`
- A recurring scan schedule was deleted for a Claude Code Security project.
+ A Claude Code Security vulnerability finding was dismissed, restored, marked fixed, or reopened.
- - `type: optional "claude_code_security_scan_schedule_deleted"`
+ - `type: optional "claude_code_security_vulnerability_updated"`
- default: claude_code_security_scan_schedule_deleted
+ default: claude_code_security_vulnerability_updated
+
+ - `action: "dismissed" or "fixed" or "restored" or 2 more`
+
+ The state change applied to the finding
+
+ - `"dismissed"`
+
+ - `"fixed"`
+
+ - `"restored"`
+
+ - `"unfixed"`
+
+ - `"unspecified"`
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -152660,9 +154150,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `scan_project_id: string`
+ - `scan_id: string`
- Tagged ID of the scan project
+ Tagged ID of the scan the finding belongs to
- `id: optional string`
@@ -152674,6 +154164,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `dismissal_reason: optional string or null`
+
+ The categorized dismissal reason (only set when the finding was dismissed)
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -152682,13 +154176,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeSecurityScanScheduleUpdated object`
+ - `ClaudeCodeSecurityWebhookCreated object`
- A recurring scan schedule was set or replaced for a Claude Code Security project.
+ A Claude Code Security outbound webhook was created.
- - `type: optional "claude_code_security_scan_schedule_updated"`
+ - `type: optional "claude_code_security_webhook_created"`
- default: claude_code_security_scan_schedule_updated
+ default: claude_code_security_webhook_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -152896,11 +154390,11 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `cadence: string`
+ - `url: string`
- - `scan_project_id: string`
+ - `webhook_id: string`
- Tagged ID of the scan project
+ Tagged ID of the webhook
- `id: optional string`
@@ -152920,13 +154414,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeSecurityVulnerabilityDeleted object`
+ - `scan_project_id: optional string or null`
- A Claude Code Security vulnerability finding was permanently deleted.
+ Tagged ID of the scan project (null for organization-wide webhooks)
- - `type: optional "claude_code_security_vulnerability_deleted"`
+ - `ClaudeCodeSecurityWebhookDeleted object`
- default: claude_code_security_vulnerability_deleted
+ A Claude Code Security outbound webhook was deleted.
+
+ - `type: optional "claude_code_security_webhook_deleted"`
+
+ default: claude_code_security_webhook_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -153134,13 +154632,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `scan_id: string`
-
- Tagged ID of the scan the finding belonged to
-
- - `vulnerability_id: number`
+ - `webhook_id: string`
- Numeric ID of the deleted finding, as shown in the product
+ Tagged ID of the webhook
- `id: optional string`
@@ -153160,13 +154654,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeSecurityVulnerabilityFixSessionCreated object`
+ - `scan_project_id: optional string or null`
- A Claude Code remediation session was created for a Claude Code Security vulnerability finding.
+ Tagged ID of the scan project (null for organization-wide webhooks)
- - `type: optional "claude_code_security_vulnerability_fix_session_created"`
+ - `ClaudeCodeSecurityWebhookSecretUpdated object`
- default: claude_code_security_vulnerability_fix_session_created
+ The HMAC signing secret for a Claude Code Security webhook was rotated.
+
+ - `type: optional "claude_code_security_webhook_secret_updated"`
+
+ default: claude_code_security_webhook_secret_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -153374,32 +154872,14 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `scan_id: string`
-
- Tagged ID of the scan the finding belongs to
-
- - `session_id: string`
+ - `webhook_id: string`
- ID of the created remediation session
+ Tagged ID of the webhook
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `access_via: optional "member" or "organization_admin" or "organization_share" or 2 more or null`
-
- How the actor was authorized to make this change: "owner" (the scan project's owner), "member" (an individually added member), "organization_share" (the project is shared with the actor's organization), or "organization_admin" (an administrator of the organization's security scanning). Absent when no project relationship was involved; events recorded before this field was introduced omit it.
-
- - `"member"`
-
- - `"organization_admin"`
-
- - `"organization_share"`
-
- - `"owner"`
-
- - `"unspecified"`
-
- `created_at: optional string`
When this activity occurred.
@@ -153414,27 +154894,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeSecurityVulnerabilityUpdated object`
-
- A Claude Code Security vulnerability finding was dismissed, restored, marked fixed, or reopened.
-
- - `type: optional "claude_code_security_vulnerability_updated"`
-
- default: claude_code_security_vulnerability_updated
-
- - `action: "dismissed" or "fixed" or "restored" or 2 more`
-
- The state change applied to the finding
+ - `scan_project_id: optional string or null`
- - `"dismissed"`
+ Tagged ID of the scan project (null for organization-wide webhooks)
- - `"fixed"`
+ - `ClaudeCodeSecurityWebhookUpdated object`
- - `"restored"`
+ A Claude Code Security outbound webhook was updated.
- - `"unfixed"`
+ - `type: optional "claude_code_security_webhook_updated"`
- - `"unspecified"`
+ default: claude_code_security_webhook_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -153642,9 +155112,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `scan_id: string`
+ - `webhook_id: string`
- Tagged ID of the scan the finding belongs to
+ Tagged ID of the webhook
- `id: optional string`
@@ -153656,10 +155126,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `dismissal_reason: optional string or null`
-
- The categorized dismissal reason (only set when the finding was dismissed)
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -153668,13 +155134,27 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCodeSecurityWebhookCreated object`
+ - `scan_project_id: optional string or null`
- A Claude Code Security outbound webhook was created.
+ Tagged ID of the scan project (null for organization-wide webhooks)
- - `type: optional "claude_code_security_webhook_created"`
+ - `ClaudeCodeTeamMemoryACLUpdated object`
- default: claude_code_security_webhook_created
+ An RBAC group was added to or removed from the Claude Code team-memory ACL.
+
+ - `type: optional "claude_code_team_memory_acl_updated"`
+
+ default: claude_code_team_memory_acl_updated
+
+ - `action: "removed" or "set" or "unspecified"`
+
+ Whether the group was set (added/updated) or removed
+
+ - `"removed"`
+
+ - `"set"`
+
+ - `"unspecified"`
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -153882,16 +155362,18 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `url: string`
-
- - `webhook_id: string`
+ - `group_id: string`
- Tagged ID of the webhook
+ Tagged ID of the RBAC group
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `access_level: optional string or null`
+
+ Access level granted (when action=set)
+
- `created_at: optional string`
When this activity occurred.
@@ -153906,17 +155388,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `scan_project_id: optional string or null`
+ - `previous_access_level: optional string or null`
- Tagged ID of the scan project (null for organization-wide webhooks)
+ Access level the group had before this change; absent when the group was not previously in the access list. For removals this is the access level that was removed.
- - `ClaudeCodeSecurityWebhookDeleted object`
+ - `ClaudeCodeTeamMemoryUpdated object`
- A Claude Code Security outbound webhook was deleted.
+ Claude Code team memory shared with the organization was updated.
- - `type: optional "claude_code_security_webhook_deleted"`
+ - `type: optional "claude_code_team_memory_updated"`
- default: claude_code_security_webhook_deleted
+ default: claude_code_team_memory_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -154124,9 +155606,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `webhook_id: string`
+ - `deleted_all: boolean`
- Tagged ID of the webhook
+ True when the entire team memory store for this scope was deleted in one request.
- `id: optional string`
@@ -154138,6 +155620,26 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `keys_deleted: optional array of string`
+
+ Withdrawn — never populated. See `keys_deleted_count`.
+
+ - `keys_deleted_count: optional number or null`
+
+ Number of team memory entries removed.
+
+ - `keys_written: optional array of string`
+
+ Withdrawn — never populated. See `keys_written_count`.
+
+ - `keys_written_count: optional number or null`
+
+ Number of team memory entries created or updated.
+
+ - `new_checksum: optional string or null`
+
+ Checksum of the team memory after this change.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -154146,17 +155648,37 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `scan_project_id: optional string or null`
+ - `previous_checksum: optional string or null`
- Tagged ID of the scan project (null for organization-wide webhooks)
+ Checksum of the team memory before this change; null when it did not exist.
- - `ClaudeCodeSecurityWebhookSecretUpdated object`
+ - `repo: optional string or null`
- The HMAC signing secret for a Claude Code Security webhook was rotated.
+ Withdrawn — never populated.
- - `type: optional "claude_code_security_webhook_secret_updated"`
+ - `version: optional number or null`
- default: claude_code_security_webhook_secret_updated
+ Version number of the team memory store after this change.
+
+ - `ClaudeCodeTeamOnboardingGuideUpdated object`
+
+ A Claude Code team onboarding guide was created, updated, or deleted.
+
+ - `type: optional "claude_code_team_onboarding_guide_updated"`
+
+ default: claude_code_team_onboarding_guide_updated
+
+ - `action: "created" or "deleted" or "unspecified" or "updated"`
+
+ The state change applied to the onboarding guide.
+
+ - `"created"`
+
+ - `"deleted"`
+
+ - `"unspecified"`
+
+ - `"updated"`
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -154364,9 +155886,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `webhook_id: string`
+ - `guide_short_code: string`
- Tagged ID of the webhook
+ Short code identifying the onboarding guide — the public URL handle shown in the share link.
- `id: optional string`
@@ -154378,6 +155900,18 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `guide_id: optional string or null`
+
+ Tagged ID of the onboarding guide.
+
+ - `guide_name: optional string or null`
+
+ Withdrawn — never populated.
+
+ - `new_checksum: optional string or null`
+
+ Checksum of the guide content after this change; null when the guide was deleted.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -154386,17 +155920,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `scan_project_id: optional string or null`
+ - `previous_checksum: optional string or null`
- Tagged ID of the scan project (null for organization-wide webhooks)
+ Checksum of the guide content before this change; null when the guide did not exist.
- - `ClaudeCodeSecurityWebhookUpdated object`
+ - `ClaudeCodeUserMarketplacesUpdated object`
- A Claude Code Security outbound webhook was updated.
+ A user's Claude Code plugin marketplace selections were updated on Anthropic servers.
- - `type: optional "claude_code_security_webhook_updated"`
+ - `type: optional "claude_code_user_marketplaces_updated"`
- default: claude_code_security_webhook_updated
+ default: claude_code_user_marketplaces_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -154604,9 +156138,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `webhook_id: string`
+ - `deleted_all: boolean`
- Tagged ID of the webhook
+ True when all of the user's marketplace selections were removed in one request.
- `id: optional string`
@@ -154618,35 +156152,45 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `organization_id: optional string or null`
+ - `keys_deleted: optional array of string`
- Organization ID this activity is associated with
+ Withdrawn — never populated. See `keys_deleted_count`.
- - `organization_uuid: optional string or null`
+ - `keys_deleted_count: optional number or null`
- Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+ Number of marketplace selections removed.
- - `scan_project_id: optional string or null`
+ - `keys_written: optional array of string`
- Tagged ID of the scan project (null for organization-wide webhooks)
+ Withdrawn — never populated. See `keys_written_count`.
- - `ClaudeCodeTeamMemoryACLUpdated object`
+ - `keys_written_count: optional number or null`
- An RBAC group was added to or removed from the Claude Code team-memory ACL.
+ Number of marketplace selections added or whose source changed.
- - `type: optional "claude_code_team_memory_acl_updated"`
+ - `new_value: optional string or null`
- default: claude_code_team_memory_acl_updated
+ Withdrawn — never populated.
- - `action: "removed" or "set" or "unspecified"`
+ - `organization_id: optional string or null`
- Whether the group was set (added/updated) or removed
+ Organization ID this activity is associated with
- - `"removed"`
+ - `organization_uuid: optional string or null`
- - `"set"`
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `"unspecified"`
+ - `previous_value: optional string or null`
+
+ Withdrawn — never populated.
+
+ - `ClaudeCodeUserMemoryUpdated object`
+
+ A user's synced private Claude Code memory was updated or deleted on Anthropic servers.
+
+ - `type: optional "claude_code_user_memory_updated"`
+
+ default: claude_code_user_memory_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -154854,24 +156398,40 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `group_id: string`
+ - `deleted_all: boolean`
- Tagged ID of the RBAC group
+ True when the user's entire synced memory for this scope was deleted in one request.
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `access_level: optional string or null`
-
- Access level granted (when action=set)
-
- `created_at: optional string`
When this activity occurred.
format: date-time
+ - `keys_deleted: optional array of string`
+
+ Withdrawn — never populated. See `keys_deleted_count`.
+
+ - `keys_deleted_count: optional number or null`
+
+ Number of memory file paths removed.
+
+ - `keys_written: optional array of string`
+
+ Withdrawn — never populated. See `keys_written_count`.
+
+ - `keys_written_count: optional number or null`
+
+ Number of memory file paths created or updated.
+
+ - `new_checksum: optional string or null`
+
+ Checksum of the user's synced memory after this change.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -154880,17 +156440,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_access_level: optional string or null`
+ - `previous_checksum: optional string or null`
- Access level the group had before this change; absent when the group was not previously in the access list. For removals this is the access level that was removed.
+ Checksum of the user's synced memory before this change; null when the store did not exist.
- - `ClaudeCodeTeamMemoryUpdated object`
+ - `repo: optional string or null`
- Claude Code team memory shared with the organization was updated.
+ Withdrawn — never populated.
- - `type: optional "claude_code_team_memory_updated"`
+ - `ClaudeCodeUserPluginsUpdated object`
- default: claude_code_team_memory_updated
+ A user's Claude Code plugin selections — which plugins are installed and enabled — were updated on Anthropic servers.
+
+ - `type: optional "claude_code_user_plugins_updated"`
+
+ default: claude_code_user_plugins_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -155100,7 +156664,7 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `deleted_all: boolean`
- True when the entire team memory store for this scope was deleted in one request.
+ True when all of the user's plugin selections were removed in one request.
- `id: optional string`
@@ -155118,7 +156682,7 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `keys_deleted_count: optional number or null`
- Number of team memory entries removed.
+ Number of plugin selections removed.
- `keys_written: optional array of string`
@@ -155126,11 +156690,11 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `keys_written_count: optional number or null`
- Number of team memory entries created or updated.
+ Number of plugin selections added or whose enabled state changed.
- - `new_checksum: optional string or null`
+ - `new_value: optional string or null`
- Checksum of the team memory after this change.
+ The targeted plugin's new enabled state, when a single plugin's state changed.
- `organization_id: optional string or null`
@@ -155140,37 +156704,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_checksum: optional string or null`
-
- Checksum of the team memory before this change; null when it did not exist.
-
- - `repo: optional string or null`
-
- Withdrawn — never populated.
-
- - `version: optional number or null`
-
- Version number of the team memory store after this change.
-
- - `ClaudeCodeTeamOnboardingGuideUpdated object`
-
- A Claude Code team onboarding guide was created, updated, or deleted.
-
- - `type: optional "claude_code_team_onboarding_guide_updated"`
-
- default: claude_code_team_onboarding_guide_updated
-
- - `action: "created" or "deleted" or "unspecified" or "updated"`
+ - `previous_value: optional string or null`
- The state change applied to the onboarding guide.
+ The targeted plugin's previous enabled state, when a single plugin's state changed; null when the plugin did not previously exist or multiple plugins changed.
- - `"created"`
+ - `ClaudeCodeUserSettingsUpdated object`
- - `"deleted"`
+ A user's synced Claude Code settings were updated or deleted on Anthropic servers.
- - `"unspecified"`
+ - `type: optional "claude_code_user_settings_updated"`
- - `"updated"`
+ default: claude_code_user_settings_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -155378,9 +156922,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `guide_short_code: string`
+ - `deleted_all: boolean`
- Short code identifying the onboarding guide — the public URL handle shown in the share link.
+ True when the user's entire synced settings store was deleted in one request.
- `id: optional string`
@@ -155392,17 +156936,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `guide_id: optional string or null`
+ - `keys_deleted: optional array of string`
- Tagged ID of the onboarding guide.
+ Withdrawn — never populated. See `keys_deleted_count`.
- - `guide_name: optional string or null`
+ - `keys_deleted_count: optional number or null`
- Withdrawn — never populated.
+ Number of settings entries removed.
+
+ - `keys_written: optional array of string`
+
+ Withdrawn — never populated. See `keys_written_count`.
+
+ - `keys_written_count: optional number or null`
+
+ Number of settings entries created or updated.
- `new_checksum: optional string or null`
- Checksum of the guide content after this change; null when the guide was deleted.
+ Checksum of the user's synced settings after this change.
- `organization_id: optional string or null`
@@ -155414,15 +156966,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `previous_checksum: optional string or null`
- Checksum of the guide content before this change; null when the guide did not exist.
+ Checksum of the user's synced settings before this change; null when the store did not exist.
- - `ClaudeCodeUserMarketplacesUpdated object`
+ - `ClaudeEnterpriseUpgradeCreditUpdated object`
- A user's Claude Code plugin marketplace selections were updated on Anthropic servers.
+ An organization admin cancelled, or turned back on, the monthly usage credit the organization receives for upgrading from the Team plan to the Enterprise plan, together with the recurring monthly charge that accompanies it.
- - `type: optional "claude_code_user_marketplaces_updated"`
+ - `type: optional "claude_enterprise_upgrade_credit_updated"`
- default: claude_code_user_marketplaces_updated
+ default: claude_enterprise_upgrade_credit_updated
+
+ - `action: "cancelled" or "resumed" or "unspecified"`
+
+ Whether the credit was cancelled or turned back on
+
+ - `"cancelled"`
+
+ - `"resumed"`
+
+ - `"unspecified"`
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -155630,10 +157192,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `deleted_all: boolean`
-
- True when all of the user's marketplace selections were removed in one request.
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -155644,26 +157202,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `keys_deleted: optional array of string`
-
- Withdrawn — never populated. See `keys_deleted_count`.
-
- - `keys_deleted_count: optional number or null`
-
- Number of marketplace selections removed.
-
- - `keys_written: optional array of string`
-
- Withdrawn — never populated. See `keys_written_count`.
-
- - `keys_written_count: optional number or null`
-
- Number of marketplace selections added or whose source changed.
-
- - `new_value: optional string or null`
-
- Withdrawn — never populated.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -155672,17 +157210,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_value: optional string or null`
-
- Withdrawn — never populated.
-
- - `ClaudeCodeUserMemoryUpdated object`
+ - `ClaudeFileAccessFailed object`
- A user's synced private Claude Code memory was updated or deleted on Anthropic servers.
+ A user was denied access to a file in Claude.ai.
- - `type: optional "claude_code_user_memory_updated"`
+ - `type: optional "claude_file_access_failed"`
- default: claude_code_user_memory_updated
+ default: claude_file_access_failed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -155890,39 +157424,27 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `deleted_all: boolean`
+ - `claude_file_id: string`
- True when the user's entire synced memory for this scope was deleted in one request.
+ The file the user was denied access to, e.g. "claude_file_01HX...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `created_at: optional string`
-
- When this activity occurred.
-
- format: date-time
-
- - `keys_deleted: optional array of string`
-
- Withdrawn — never populated. See `keys_deleted_count`.
-
- - `keys_deleted_count: optional number or null`
-
- Number of memory file paths removed.
+ - `claude_artifact_id: optional string or null`
- - `keys_written: optional array of string`
+ The artifact the file was accessed through, if any, e.g. "claude_artifact_01HX...".
- Withdrawn — never populated. See `keys_written_count`.
+ - `claude_project_id: optional string or null`
- - `keys_written_count: optional number or null`
+ The project the file was accessed through, if any, e.g. "claude_proj_01HX...".
- Number of memory file paths created or updated.
+ - `created_at: optional string`
- - `new_checksum: optional string or null`
+ When this activity occurred.
- Checksum of the user's synced memory after this change.
+ format: date-time
- `organization_id: optional string or null`
@@ -155932,21 +157454,19 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_checksum: optional string or null`
-
- Checksum of the user's synced memory before this change; null when the store did not exist.
+ - `filename: optional string or null`
- - `repo: optional string or null`
+ **Deprecated**
- Withdrawn — never populated.
+ Deprecated — DO NOT USE. Always empty; the file's display name is intentionally omitted.
- - `ClaudeCodeUserPluginsUpdated object`
+ - `ClaudeFileExported object`
- A user's Claude Code plugin selections — which plugins are installed and enabled — were updated on Anthropic servers.
+ A file was exported from Claude to an external storage destination.
- - `type: optional "claude_code_user_plugins_updated"`
+ - `type: optional "claude_file_exported"`
- default: claude_code_user_plugins_updated
+ default: claude_file_exported
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -156154,39 +157674,35 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `deleted_all: boolean`
-
- True when all of the user's plugin selections were removed in one request.
-
- - `id: optional string`
+ - `export_destination: "google_drive" or "unspecified"`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ The external destination the file was exported to.
- - `created_at: optional string`
+ - `"google_drive"`
- When this activity occurred.
+ - `"unspecified"`
- format: date-time
+ - `filename: string`
- - `keys_deleted: optional array of string`
+ Name of the exported file.
- Withdrawn — never populated. See `keys_deleted_count`.
+ - `id: optional string`
- - `keys_deleted_count: optional number or null`
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- Number of plugin selections removed.
+ - `claude_chat_id: optional string or null`
- - `keys_written: optional array of string`
+ The chat conversation the file was exported from, if the export originated in a chat, e.g. "claude_chat_01HX...".
- Withdrawn — never populated. See `keys_written_count`.
+ - `claude_file_id: optional string or null`
- - `keys_written_count: optional number or null`
+ The exported file, e.g. "claude_file_01HX...", if the file has a stored file record; files that exist only inside a session have no file ID.
- Number of plugin selections added or whose enabled state changed.
+ - `created_at: optional string`
- - `new_value: optional string or null`
+ When this activity occurred.
- The targeted plugin's new enabled state, when a single plugin's state changed.
+ format: date-time
- `organization_id: optional string or null`
@@ -156196,17 +157712,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_value: optional string or null`
-
- The targeted plugin's previous enabled state, when a single plugin's state changed; null when the plugin did not previously exist or multiple plugins changed.
-
- - `ClaudeCodeUserSettingsUpdated object`
+ - `ClaudeFileViewed object`
- A user's synced Claude Code settings were updated or deleted on Anthropic servers.
+ A user viewed a file in Claude.ai.
- - `type: optional "claude_code_user_settings_updated"`
+ - `type: optional "claude_file_viewed"`
- default: claude_code_user_settings_updated
+ default: claude_file_viewed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -156414,39 +157926,27 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `deleted_all: boolean`
+ - `claude_file_id: string`
- True when the user's entire synced settings store was deleted in one request.
+ The file that was viewed, e.g. "claude_file_01HX...".
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `created_at: optional string`
-
- When this activity occurred.
-
- format: date-time
-
- - `keys_deleted: optional array of string`
-
- Withdrawn — never populated. See `keys_deleted_count`.
-
- - `keys_deleted_count: optional number or null`
-
- Number of settings entries removed.
+ - `claude_artifact_id: optional string or null`
- - `keys_written: optional array of string`
+ The artifact the file was accessed through, if any, e.g. "claude_artifact_01HX...".
- Withdrawn — never populated. See `keys_written_count`.
+ - `claude_project_id: optional string or null`
- - `keys_written_count: optional number or null`
+ The project the file was accessed through, if any, e.g. "claude_proj_01HX...".
- Number of settings entries created or updated.
+ - `created_at: optional string`
- - `new_checksum: optional string or null`
+ When this activity occurred.
- Checksum of the user's synced settings after this change.
+ format: date-time
- `organization_id: optional string or null`
@@ -156456,27 +157956,19 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_checksum: optional string or null`
-
- Checksum of the user's synced settings before this change; null when the store did not exist.
-
- - `ClaudeEnterpriseUpgradeCreditUpdated object`
-
- An organization admin cancelled, or turned back on, the monthly usage credit the organization receives for upgrading from the Team plan to the Enterprise plan, together with the recurring monthly charge that accompanies it.
-
- - `type: optional "claude_enterprise_upgrade_credit_updated"`
+ - `filename: optional string or null`
- default: claude_enterprise_upgrade_credit_updated
+ **Deprecated**
- - `action: "cancelled" or "resumed" or "unspecified"`
+ Deprecated — DO NOT USE. Always empty; the file's display name is intentionally omitted.
- Whether the credit was cancelled or turned back on
+ - `ClaudeProjectSyncSourceCreated object`
- - `"cancelled"`
+ A sync source was connected to a Claude project's knowledge base.
- - `"resumed"`
+ - `type: optional "claude_project_sync_source_created"`
- - `"unspecified"`
+ default: claude_project_sync_source_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -156684,6 +158176,18 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `claude_project_id: string`
+
+ Tagged ID of the project the sync source was connected to.
+
+ - `claude_project_sync_source_id: string`
+
+ Tagged ID of the per-project sync source that was created.
+
+ - `provider: string`
+
+ The external provider backing the sync source, e.g. `github`, `google_drive`, `outline`, `slack`, `salesforce`, `google_calendar`, `gmail`, `asana`, or `mcp_resources`.
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -156702,13 +158206,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeFileAccessFailed object`
+ - `resource_descriptor: optional string or null`
- A user was denied access to a file in Claude.ai.
+ A short provider-specific identifier for the external resource that was connected, e.g. `owner/repo` for GitHub or a file ID for Google Drive.
- - `type: optional "claude_file_access_failed"`
+ - `ClaudeProjectSyncSourceDeleted object`
- default: claude_file_access_failed
+ A sync source was disconnected from a Claude project's knowledge base.
+
+ - `type: optional "claude_project_sync_source_deleted"`
+
+ default: claude_project_sync_source_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -156916,21 +158424,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_file_id: string`
+ - `claude_project_id: string`
- The file the user was denied access to, e.g. "claude_file_01HX...".
+ Tagged ID of the project the sync source was disconnected from.
- - `id: optional string`
+ - `claude_project_sync_source_id: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ Tagged ID of the per-project sync source that was deleted.
- - `claude_artifact_id: optional string or null`
+ - `provider: string`
- The artifact the file was accessed through, if any, e.g. "claude_artifact_01HX...".
+ The external provider backing the sync source. Always `unspecified` for deletion events.
- - `claude_project_id: optional string or null`
+ - `id: optional string`
- The project the file was accessed through, if any, e.g. "claude_proj_01HX...".
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -156946,19 +158454,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `filename: optional string or null`
-
- **Deprecated**
-
- Deprecated — DO NOT USE. Always empty; the file's display name is intentionally omitted.
-
- - `ClaudeFileExported object`
+ - `ClaudeProjectSyncSourceUpdated object`
- A file was exported from Claude to an external storage destination.
+ A Claude project sync source's configuration was updated.
- - `type: optional "claude_file_exported"`
+ - `type: optional "claude_project_sync_source_updated"`
- default: claude_file_exported
+ default: claude_project_sync_source_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -157166,29 +158668,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `export_destination: "google_drive" or "unspecified"`
+ - `claude_project_id: string`
- The external destination the file was exported to.
+ Tagged ID of the project the sync source belongs to.
- - `"google_drive"`
+ - `claude_project_sync_source_id: string`
- - `"unspecified"`
+ Tagged ID of the per-project sync source that was updated.
- - `filename: string`
+ - `provider: string`
- Name of the exported file.
+ The external provider backing the sync source, e.g. `github`, `google_drive`, `outline`, `slack`, `salesforce`, `google_calendar`, `gmail`, `asana`, or `mcp_resources`.
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `claude_chat_id: optional string or null`
-
- The chat conversation the file was exported from, if the export originated in a chat, e.g. "claude_chat_01HX...".
-
- - `claude_file_id: optional string or null`
+ - `config_changed: optional boolean or null`
- The exported file, e.g. "claude_file_01HX...", if the file has a stored file record; files that exist only inside a session have no file ID.
+ Whether the update changed the stored sync-source configuration, including sync settings such as path filters. False for a re-sync or a metadata-only refresh of the same resource.
- `created_at: optional string`
@@ -157204,13 +158702,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeFileViewed object`
+ - `resource_descriptor: optional string or null`
- A user viewed a file in Claude.ai.
+ A short provider-specific identifier for the external resource after the update, e.g. `owner/repo` for GitHub or a file ID for Google Drive.
- - `type: optional "claude_file_viewed"`
+ - `ClaudeUserSeatTierUpdated object`
- default: claude_file_viewed
+ An organization member's seat tier was changed. A null `previous_seat_tier` means the member previously had no seat assigned; a null `current_seat_tier` means the seat was removed.
+
+ - `type: optional "claude_user_seat_tier_updated"`
+
+ default: claude_user_seat_tier_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -157418,21 +158920,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_file_id: string`
-
- The file that was viewed, e.g. "claude_file_01HX...".
-
- - `id: optional string`
+ - `user_email: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ Email address of the member at the time of the change.
- - `claude_artifact_id: optional string or null`
+ - `user_id: string`
- The artifact the file was accessed through, if any, e.g. "claude_artifact_01HX...".
+ Tagged ID of the member whose seat tier changed.
- - `claude_project_id: optional string or null`
+ - `id: optional string`
- The project the file was accessed through, if any, e.g. "claude_proj_01HX...".
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -157440,6 +158938,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `current_seat_tier: optional string or null`
+
+ The member's seat tier after this change, or null if the seat was removed.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -157448,19 +158950,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `filename: optional string or null`
-
- **Deprecated**
+ - `previous_seat_tier: optional string or null`
- Deprecated — DO NOT USE. Always empty; the file's display name is intentionally omitted.
+ The member's seat tier before this change, or null if no seat was assigned.
- - `ClaudeProjectSyncSourceCreated object`
+ - `CliPluginExecPolicyUpdated object`
- A sync source was connected to a Claude project's knowledge base.
+ Admin set or cleared the per-op permission ceiling for a plugin CLI.
- - `type: optional "claude_project_sync_source_created"`
+ - `type: optional "cli_plugin_exec_policy_updated"`
- default: claude_project_sync_source_created
+ default: cli_plugin_exec_policy_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -157668,17 +159168,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_project_id: string`
+ - `cli_name: string`
- Tagged ID of the project the sync source was connected to.
+ CLI name as declared by the plugin manifest
- - `claude_project_sync_source_id: string`
+ - `marketplace_id: string`
- Tagged ID of the per-project sync source that was created.
+ Marketplace ID owning the plugin
- - `provider: string`
+ - `op_name: string`
- The external provider backing the sync source, e.g. `github`, `google_drive`, `outline`, `slack`, `salesforce`, `google_calendar`, `gmail`, `asana`, or `mcp_resources`.
+ Op name (or '*' for the per-CLI default)
+
+ - `plugin_id: string`
+
+ Plugin ID resolved from the URL
+
+ - `plugin_name: string`
+
+ Plugin name within its marketplace
- `id: optional string`
@@ -157690,6 +159198,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `max_permission: optional string or null`
+
+ New max_permission value ('allow' | 'ask' | 'blocked'), or null when cleared
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -157698,17 +159210,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `resource_descriptor: optional string or null`
+ - `previous_max_permission: optional string or null`
- A short provider-specific identifier for the external resource that was connected, e.g. `owner/repo` for GitHub or a file ID for Google Drive.
+ Max permission the op had before this change ('allow' | 'ask' | 'blocked'), or null when no policy existed for the op
- - `ClaudeProjectSyncSourceDeleted object`
+ - `ClaudeCommandCreated object`
- A sync source was disconnected from a Claude project's knowledge base.
+ Command was created.
- - `type: optional "claude_project_sync_source_deleted"`
+ - `type: optional "claude_command_created"`
- default: claude_project_sync_source_deleted
+ default: claude_command_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -157916,22 +159428,14 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_project_id: string`
-
- Tagged ID of the project the sync source was disconnected from.
-
- - `claude_project_sync_source_id: string`
-
- Tagged ID of the per-project sync source that was deleted.
-
- - `provider: string`
-
- The external provider backing the sync source. Always `unspecified` for deletion events.
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `command_id: optional string or null`
+
+ - `command_name: optional string or null`
+
- `created_at: optional string`
When this activity occurred.
@@ -157946,13 +159450,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeProjectSyncSourceUpdated object`
+ - `ClaudeCommandDeleted object`
- A Claude project sync source's configuration was updated.
+ Command was deleted.
- - `type: optional "claude_project_sync_source_updated"`
+ - `type: optional "claude_command_deleted"`
- default: claude_project_sync_source_updated
+ default: claude_command_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -158160,25 +159664,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_project_id: string`
-
- Tagged ID of the project the sync source belongs to.
-
- - `claude_project_sync_source_id: string`
-
- Tagged ID of the per-project sync source that was updated.
-
- - `provider: string`
-
- The external provider backing the sync source, e.g. `github`, `google_drive`, `outline`, `slack`, `salesforce`, `google_calendar`, `gmail`, `asana`, or `mcp_resources`.
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `config_changed: optional boolean or null`
+ - `command_id: optional string or null`
- Whether the update changed the stored sync-source configuration, including sync settings such as path filters. False for a re-sync or a metadata-only refresh of the same resource.
+ - `command_name: optional string or null`
- `created_at: optional string`
@@ -158194,17 +159686,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `resource_descriptor: optional string or null`
-
- A short provider-specific identifier for the external resource after the update, e.g. `owner/repo` for GitHub or a file ID for Google Drive.
-
- - `ClaudeUserSeatTierUpdated object`
+ - `ClaudeCommandReplaced object`
- An organization member's seat tier was changed. A null `previous_seat_tier` means the member previously had no seat assigned; a null `current_seat_tier` means the seat was removed.
+ Command was replaced.
- - `type: optional "claude_user_seat_tier_updated"`
+ - `type: optional "claude_command_replaced"`
- default: claude_user_seat_tier_updated
+ default: claude_command_replaced
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -158412,28 +159900,20 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `user_email: string`
-
- Email address of the member at the time of the change.
-
- - `user_id: string`
-
- Tagged ID of the member whose seat tier changed.
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `command_id: optional string or null`
+
+ - `command_name: optional string or null`
+
- `created_at: optional string`
When this activity occurred.
format: date-time
- - `current_seat_tier: optional string or null`
-
- The member's seat tier after this change, or null if the seat was removed.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -158442,17 +159922,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_seat_tier: optional string or null`
-
- The member's seat tier before this change, or null if no seat was assigned.
-
- - `CliPluginExecPolicyUpdated object`
+ - `ComplianceAPIAccessed object`
- Admin set or cleared the per-op permission ceiling for a plugin CLI.
+ Logging event auto-generated for each compliance API request.
- - `type: optional "cli_plugin_exec_policy_updated"`
+ - `type: optional "compliance_api_accessed"`
- default: cli_plugin_exec_policy_updated
+ default: compliance_api_accessed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -158660,25 +160136,31 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `cli_name: string`
+ - `request_id: string`
- CLI name as declared by the plugin manifest
+ Identifier of the request, as returned in the response's request-id header
- - `marketplace_id: string`
+ - `request_method: "DELETE" or "GET" or "POST" or 2 more`
- Marketplace ID owning the plugin
+ HTTP method of the request
- - `op_name: string`
+ - `"DELETE"`
- Op name (or '*' for the per-CLI default)
+ - `"GET"`
- - `plugin_id: string`
+ - `"POST"`
- Plugin ID resolved from the URL
+ - `"PUT"`
- - `plugin_name: string`
+ - `"unspecified"`
- Plugin name within its marketplace
+ - `status_code: number`
+
+ HTTP status code
+
+ - `url: string`
+
+ Full URL that was requested, including any query string
- `id: optional string`
@@ -158690,10 +160172,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `max_permission: optional string or null`
-
- New max_permission value ('allow' | 'ask' | 'blocked'), or null when cleared
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -158702,17 +160180,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_max_permission: optional string or null`
+ - `request_body: optional string or null`
- Max permission the op had before this change ('allow' | 'ask' | 'blocked'), or null when no policy existed for the op
+ Serialized JSON request body
- - `ClaudeCommandCreated object`
+ - `CoworkSessionUpdated object`
- Command was created.
+ A Cowork session was updated.
- - `type: optional "claude_command_created"`
+ - `type: optional "cowork_session_updated"`
- default: claude_command_created
+ default: cowork_session_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -158920,13 +160398,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `cowork_session_id: string`
+
+ Tagged ID of the updated session, e.g. "sess_01HX...".
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `command_id: optional string or null`
+ - `claude_project_id: optional string or null`
- - `command_name: optional string or null`
+ Tagged ID of the project the session was moved to, if any, e.g. "claude_proj_01HX...". Absent when the session was removed from its project.
- `created_at: optional string`
@@ -158942,13 +160424,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCommandDeleted object`
+ - `DesignProjectArtifactPublished object`
- Command was deleted.
+ A Claude Design project's content was published as a claude.ai artifact, making a snapshot of one of its files viewable outside the project's sharing settings.
- - `type: optional "claude_command_deleted"`
+ - `type: optional "design_project_artifact_published"`
- default: claude_command_deleted
+ default: design_project_artifact_published
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -159156,13 +160638,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `id: optional string`
+ - `design_project_id: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ The Design project whose content was published, e.g. "design_proj_01HX...".
- - `command_id: optional string or null`
+ - `id: optional string`
- - `command_name: optional string or null`
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -159170,6 +160652,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `is_public: optional boolean or null`
+
+ True when the published artifact is publicly viewable after this call (anyone with the link). False when it is not — by default, a newly published artifact is visible only to the person who published it.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -159178,13 +160664,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeCommandReplaced object`
+ - `project_type: optional string or null`
- Command was replaced.
+ The project's type: "project", "template", or "design_system".
- - `type: optional "claude_command_replaced"`
+ - `DesignProjectCreated object`
- default: claude_command_replaced
+ A Claude Design project was created.
+
+ - `type: optional "design_project_created"`
+
+ default: design_project_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -159392,13 +160882,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `id: optional string`
+ - `creation_method: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ How the project was created: "direct", "duplicate", "remix", or "template_from_project".
- - `command_id: optional string or null`
+ - `design_project_id: string`
- - `command_name: optional string or null`
+ The Design project that was created, e.g. "design_proj_01HX...".
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -159414,13 +160908,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ComplianceAPIAccessed object`
+ - `project_type: optional string or null`
- Logging event auto-generated for each compliance API request.
+ The project type: "project", "template", or "design_system".
- - `type: optional "compliance_api_accessed"`
+ - `source_project_id: optional string or null`
- default: compliance_api_accessed
+ The source project this was created from, when created via duplicate, remix, or template-from-project. Unset for direct creation.
+
+ - `DesignProjectDeleted object`
+
+ A Claude Design project was deleted.
+
+ - `type: optional "design_project_deleted"`
+
+ default: design_project_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -159628,31 +161130,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `request_id: string`
-
- Identifier of the request, as returned in the response's request-id header
-
- - `request_method: "DELETE" or "GET" or "POST" or 2 more`
-
- HTTP method of the request
-
- - `"DELETE"`
-
- - `"GET"`
-
- - `"POST"`
-
- - `"PUT"`
-
- - `"unspecified"`
-
- - `status_code: number`
-
- HTTP status code
-
- - `url: string`
+ - `design_project_id: string`
- Full URL that was requested, including any query string
+ The Design project that was deleted, e.g. "design_proj_01HX...".
- `id: optional string`
@@ -159672,17 +161152,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `request_body: optional string or null`
-
- Serialized JSON request body
-
- - `CoworkSessionUpdated object`
+ - `DesignProjectMemberAdded object`
- A Cowork session was updated.
+ A member was granted access to a Claude Design project.
- - `type: optional "cowork_session_updated"`
+ - `type: optional "design_project_member_added"`
- default: cowork_session_updated
+ default: design_project_member_added
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -159890,17 +161366,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `cowork_session_id: string`
+ - `design_project_id: string`
- Tagged ID of the updated session, e.g. "sess_01HX...".
+ The Design project the member was added to, e.g. "design_proj_01HX...".
- - `id: optional string`
+ - `principal_id: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ The member's identifier: a tagged user ID (e.g. "user_01HX...") for "account", the group's identifier for "compartment", or the service's identifier for "trusted_service".
- - `claude_project_id: optional string or null`
+ - `principal_type: string`
- Tagged ID of the project the session was moved to, if any, e.g. "claude_proj_01HX...". Absent when the session was removed from its project.
+ The kind of member that was added: "account" (a user), "compartment" (a named access group), or "trusted_service" (an authorized agent).
+
+ - `role: string`
+
+ The role the member was granted: "viewer", "commenter", or "editor". Access-group ("compartment") members are always view-only.
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -159916,13 +161400,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `DesignProjectArtifactPublished object`
+ - `project_type: optional string or null`
- A Claude Design project's content was published as a claude.ai artifact, making a snapshot of one of its files viewable outside the project's sharing settings.
+ The project's type: "project", "template", or "design_system".
- - `type: optional "design_project_artifact_published"`
+ - `DesignProjectMemberRemoved object`
- default: design_project_artifact_published
+ A member's access to a Claude Design project was revoked.
+
+ - `type: optional "design_project_member_removed"`
+
+ default: design_project_member_removed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -160132,7 +161620,15 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `design_project_id: string`
- The Design project whose content was published, e.g. "design_proj_01HX...".
+ The Design project the member was removed from, e.g. "design_proj_01HX...".
+
+ - `principal_id: string`
+
+ The member's identifier: a tagged user ID (e.g. "user_01HX...") for "account", the group's identifier for "compartment", or the service's identifier for "trusted_service".
+
+ - `principal_type: string`
+
+ The kind of member that was removed: "account" (a user), "compartment" (a named access group), or "trusted_service" (an authorized agent).
- `id: optional string`
@@ -160144,10 +161640,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `is_public: optional boolean or null`
-
- True when the published artifact is publicly viewable after this call (anyone with the link). False when it is not — by default, a newly published artifact is visible only to the person who published it.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -160160,13 +161652,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
The project's type: "project", "template", or "design_system".
- - `DesignProjectCreated object`
+ - `DesignProjectMemberRoleUpdated object`
- A Claude Design project was created.
+ A Claude Design project member's role was changed.
- - `type: optional "design_project_created"`
+ - `type: optional "design_project_member_role_updated"`
- default: design_project_created
+ default: design_project_member_role_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -160374,13 +161866,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `creation_method: string`
+ - `design_project_id: string`
- How the project was created: "direct", "duplicate", "remix", or "template_from_project".
+ The Design project the member belongs to, e.g. "design_proj_01HX...".
- - `design_project_id: string`
+ - `principal_id: string`
- The Design project that was created, e.g. "design_proj_01HX...".
+ The member's identifier: a tagged user ID (e.g. "user_01HX...") for "account", the group's identifier for "compartment", or the service's identifier for "trusted_service".
+
+ - `principal_type: string`
+
+ The kind of member whose role was changed: "account" (a user), "compartment" (a named access group), or "trusted_service" (an authorized agent).
+
+ - `role: string`
+
+ The member's role after the change: "viewer", "commenter", or "editor".
- `id: optional string`
@@ -160400,21 +161900,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `project_type: optional string or null`
+ - `previous_role: optional string or null`
- The project type: "project", "template", or "design_system".
+ The member's role before the change.
- - `source_project_id: optional string or null`
+ - `project_type: optional string or null`
- The source project this was created from, when created via duplicate, remix, or template-from-project. Unset for direct creation.
+ The project's type: "project", "template", or "design_system".
- - `DesignProjectDeleted object`
+ - `DesignProjectPublished object`
- A Claude Design project was deleted.
+ A Claude Design template or design system was published, making it discoverable by everyone in its organization.
- - `type: optional "design_project_deleted"`
+ - `type: optional "design_project_published"`
- default: design_project_deleted
+ default: design_project_published
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -160624,7 +162124,7 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `design_project_id: string`
- The Design project that was deleted, e.g. "design_proj_01HX...".
+ The Design project that was published, e.g. "design_proj_01HX...".
- `id: optional string`
@@ -160644,13 +162144,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `DesignProjectMemberAdded object`
+ - `project_type: optional string or null`
- A member was granted access to a Claude Design project.
+ The project's type: "template" or "design_system".
- - `type: optional "design_project_member_added"`
+ - `DesignProjectSharingUpdated object`
- default: design_project_member_added
+ A Claude Design project's link-sharing settings were changed — who the project's link works for, and what people opening it through the link may do. Access granted to individual members is reported separately (see design_project_member_added).
+
+ - `type: optional "design_project_sharing_updated"`
+
+ default: design_project_sharing_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -160860,19 +162364,15 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `design_project_id: string`
- The Design project the member was added to, e.g. "design_proj_01HX...".
-
- - `principal_id: string`
-
- The member's identifier: a tagged user ID (e.g. "user_01HX...") for "account", the group's identifier for "compartment", or the service's identifier for "trusted_service".
+ The Design project whose sharing settings changed, e.g. "design_proj_01HX...".
- - `principal_type: string`
+ - `new_link_permission: string`
- The kind of member that was added: "account" (a user), "compartment" (a named access group), or "trusted_service" (an authorized agent).
+ What people opening the project through its link may do after the change: "view", "comment", or "edit".
- - `role: string`
+ - `new_scope: string`
- The role the member was granted: "viewer", "commenter", or "editor". Access-group ("compartment") members are always view-only.
+ Who the project link is set to work for after the change: "invited" (only the owner and individually invited members) or "org" (anyone in the project's organization, where the organization's own sharing settings allow org-wide visibility). This records the project's stored setting as changed by the actor; organization-level settings can further restrict who the link actually admits, and changes to those settings are not project events. Projects created before link sharing was restricted may also report a legacy "public" value.
- `id: optional string`
@@ -160892,17 +162392,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+ - `previous_link_permission: optional string or null`
+
+ What people opening the project through its link could do before the change.
+
+ - `previous_scope: optional string or null`
+
+ Who the project link was set to work for before the change — the stored setting, with the same organization-level caveat as new_scope. May include the legacy "public" value.
+
- `project_type: optional string or null`
The project's type: "project", "template", or "design_system".
- - `DesignProjectMemberRemoved object`
+ - `DesignProjectUnpublished object`
- A member's access to a Claude Design project was revoked.
+ A Claude Design template or design system was unpublished, removing it from its organization's shared gallery.
- - `type: optional "design_project_member_removed"`
+ - `type: optional "design_project_unpublished"`
- default: design_project_member_removed
+ default: design_project_unpublished
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -161112,15 +162620,7 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `design_project_id: string`
- The Design project the member was removed from, e.g. "design_proj_01HX...".
-
- - `principal_id: string`
-
- The member's identifier: a tagged user ID (e.g. "user_01HX...") for "account", the group's identifier for "compartment", or the service's identifier for "trusted_service".
-
- - `principal_type: string`
-
- The kind of member that was removed: "account" (a user), "compartment" (a named access group), or "trusted_service" (an authorized agent).
+ The Design project that was unpublished, e.g. "design_proj_01HX...".
- `id: optional string`
@@ -161142,15 +162642,15 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `project_type: optional string or null`
- The project's type: "project", "template", or "design_system".
+ The project's type: "template" or "design_system".
- - `DesignProjectMemberRoleUpdated object`
+ - `DesignProjectUpdated object`
- A Claude Design project member's role was changed.
+ A Claude Design project's metadata was updated.
- - `type: optional "design_project_member_role_updated"`
+ - `type: optional "design_project_updated"`
- default: design_project_member_role_updated
+ default: design_project_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -161360,19 +162860,7 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `design_project_id: string`
- The Design project the member belongs to, e.g. "design_proj_01HX...".
-
- - `principal_id: string`
-
- The member's identifier: a tagged user ID (e.g. "user_01HX...") for "account", the group's identifier for "compartment", or the service's identifier for "trusted_service".
-
- - `principal_type: string`
-
- The kind of member whose role was changed: "account" (a user), "compartment" (a named access group), or "trusted_service" (an authorized agent).
-
- - `role: string`
-
- The member's role after the change: "viewer", "commenter", or "editor".
+ The Design project that was updated, e.g. "design_proj_01HX...".
- `id: optional string`
@@ -161392,21 +162880,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_role: optional string or null`
+ - `project_type: optional string or null`
- The member's role before the change.
+ The project's type after the update: "project", "template", or "design_system". Present only when the update changed it.
- - `project_type: optional string or null`
+ - `updated_fields: optional array of string`
- The project's type: "project", "template", or "design_system".
+ Names of the fields changed by this update, e.g. "name", "description", "project_type", "design_systems".
- - `DesignProjectPublished object`
+ - `DesignProjectVersionRestored object`
- A Claude Design template or design system was published, making it discoverable by everyone in its organization.
+ A Claude Design project's working tree was rolled back to a previously saved version, replacing its current files with that version's files.
- - `type: optional "design_project_published"`
+ - `type: optional "design_project_version_restored"`
- default: design_project_published
+ default: design_project_version_restored
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -161616,7 +163104,7 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `design_project_id: string`
- The Design project that was published, e.g. "design_proj_01HX...".
+ The Design project that was restored, e.g. "design_proj_01HX...".
- `id: optional string`
@@ -161638,15 +163126,19 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `project_type: optional string or null`
- The project's type: "template" or "design_system".
+ The project's type: "project", "template", or "design_system".
- - `DesignProjectSharingUpdated object`
+ - `DesignProjectViewed object`
- A Claude Design project's link-sharing settings were changed — who the project's link works for, and what people opening it through the link may do. Access granted to individual members is reported separately (see design_project_member_added).
+ A Claude Design project's content was read. The surface field records which kind of read — a project open, a full-content read, a single-file read, a saved-version read, or an export request. The actor is the reader.
- - `type: optional "design_project_sharing_updated"`
+ This activity type is retired: project content reads are no longer
+ recorded. Events of this type may still appear in feeds for reads that
+ occurred while it was active.
- default: design_project_sharing_updated
+ - `type: optional "design_project_viewed"`
+
+ default: design_project_viewed
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -161856,20 +163348,20 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `design_project_id: string`
- The Design project whose sharing settings changed, e.g. "design_proj_01HX...".
-
- - `new_link_permission: string`
-
- What people opening the project through its link may do after the change: "view", "comment", or "edit".
+ The Design project whose content was read, e.g. "design_proj_01HX...".
- - `new_scope: string`
+ - `surface: string`
- Who the project link is set to work for after the change: "invited" (only the owner and individually invited members) or "org" (anyone in the project's organization, where the organization's own sharing settings allow org-wide visibility). This records the project's stored setting as changed by the actor; organization-level settings can further restrict who the link actually admits, and changes to those settings are not project events. Projects created before link sharing was restricted may also report a legacy "public" value.
+ Which read surface recorded this open: "project" (the project was opened), "project_data" (the project's full contents were read or made readable — either a direct data read, which also includes the project's conversations when the reader's access extends to them, or a render-token request, which exposes the project's files for the token's lifetime; the two share this value and are not distinguished), "file" (one of the project's files was read), "version" (a saved version of the project's files, including their contents, was read — version-history browsing that lists names without contents is not recorded), or "export" (an authenticated export of the project's contents was requested).
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `access_via: optional string or null`
+
+ How the viewer was authorized to open the project: "owner" (the project's owner), "member_grant" (an individually invited member), "org_link" (org-wide link sharing), "trusted_service" (an authorized agent), or "design_system_reference" (an indirect read of a design system through a project that uses it).
+
- `created_at: optional string`
When this activity occurred.
@@ -161884,25 +163376,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_link_permission: optional string or null`
-
- What people opening the project through its link could do before the change.
-
- - `previous_scope: optional string or null`
-
- Who the project link was set to work for before the change — the stored setting, with the same organization-level caveat as new_scope. May include the legacy "public" value.
-
- `project_type: optional string or null`
The project's type: "project", "template", or "design_system".
- - `DesignProjectUnpublished object`
+ - `DesktopExtensionAllowlisted object`
- A Claude Design template or design system was unpublished, removing it from its organization's shared gallery.
+ A desktop extension was added to an org's allowlist.
- - `type: optional "design_project_unpublished"`
+ - `type: optional "desktop_extension_allowlisted"`
- default: design_project_unpublished
+ default: desktop_extension_allowlisted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -162110,9 +163594,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `design_project_id: string`
+ - `extension_id: string`
- The Design project that was unpublished, e.g. "design_proj_01HX...".
+ Allowlisted DXT extension ID
- `id: optional string`
@@ -162132,17 +163616,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `project_type: optional string or null`
-
- The project's type: "template" or "design_system".
-
- - `DesignProjectUpdated object`
+ - `DesktopExtensionBlocklisted object`
- A Claude Design project's metadata was updated.
+ A desktop extension was added to the global blocklist.
- - `type: optional "design_project_updated"`
+ - `type: optional "desktop_extension_blocklisted"`
- default: design_project_updated
+ default: desktop_extension_blocklisted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -162350,9 +163830,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `design_project_id: string`
+ - `extension_id: string`
- The Design project that was updated, e.g. "design_proj_01HX...".
+ Blocklisted DXT extension ID
- `id: optional string`
@@ -162372,21 +163852,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `project_type: optional string or null`
-
- The project's type after the update: "project", "template", or "design_system". Present only when the update changed it.
-
- - `updated_fields: optional array of string`
-
- Names of the fields changed by this update, e.g. "name", "description", "project_type", "design_systems".
-
- - `DesignProjectVersionRestored object`
+ - `DesktopExtensionDeleted object`
- A Claude Design project's working tree was rolled back to a previously saved version, replacing its current files with that version's files.
+ A desktop extension was deleted, either globally by an admin or org-scoped by an org owner.
- - `type: optional "design_project_version_restored"`
+ - `type: optional "desktop_extension_deleted"`
- default: design_project_version_restored
+ default: desktop_extension_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -162594,9 +164066,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `design_project_id: string`
+ - `extension_id: string`
- The Design project that was restored, e.g. "design_proj_01HX...".
+ DXT extension ID
- `id: optional string`
@@ -162616,21 +164088,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `project_type: optional string or null`
-
- The project's type: "project", "template", or "design_system".
+ - `version: optional string or null`
- - `DesignProjectViewed object`
+ Specific version deleted (null if all versions)
- A Claude Design project's content was read. The surface field records which kind of read — a project open, a full-content read, a single-file read, a saved-version read, or an export request. The actor is the reader.
+ - `DesktopExtensionRemovedFromAllowlist object`
- This activity type is retired: project content reads are no longer
- recorded. Events of this type may still appear in feeds for reads that
- occurred while it was active.
+ A desktop extension was removed from an org's allowlist.
- - `type: optional "design_project_viewed"`
+ - `type: optional "desktop_extension_removed_from_allowlist"`
- default: design_project_viewed
+ default: desktop_extension_removed_from_allowlist
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -162838,22 +164306,14 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `design_project_id: string`
-
- The Design project whose content was read, e.g. "design_proj_01HX...".
-
- - `surface: string`
+ - `extension_id: string`
- Which read surface recorded this open: "project" (the project was opened), "project_data" (the project's full contents were read or made readable — either a direct data read, which also includes the project's conversations when the reader's access extends to them, or a render-token request, which exposes the project's files for the token's lifetime; the two share this value and are not distinguished), "file" (one of the project's files was read), "version" (a saved version of the project's files, including their contents, was read — version-history browsing that lists names without contents is not recorded), or "export" (an authenticated export of the project's contents was requested).
+ DXT extension ID removed from allowlist
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `access_via: optional string or null`
-
- How the viewer was authorized to open the project: "owner" (the project's owner), "member_grant" (an individually invited member), "org_link" (org-wide link sharing), "trusted_service" (an authorized agent), or "design_system_reference" (an indirect read of a design system through a project that uses it).
-
- `created_at: optional string`
When this activity occurred.
@@ -162868,17 +164328,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `project_type: optional string or null`
-
- The project's type: "project", "template", or "design_system".
-
- - `DesktopExtensionAllowlisted object`
+ - `DesktopExtensionUnblocked object`
- A desktop extension was added to an org's allowlist.
+ A desktop extension was removed from the global blocklist.
- - `type: optional "desktop_extension_allowlisted"`
+ - `type: optional "desktop_extension_unblocked"`
- default: desktop_extension_allowlisted
+ default: desktop_extension_unblocked
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -163088,7 +164544,7 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `extension_id: string`
- Allowlisted DXT extension ID
+ Unblocked DXT extension ID
- `id: optional string`
@@ -163108,13 +164564,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `DesktopExtensionBlocklisted object`
+ - `DesktopExtensionUploaded object`
- A desktop extension was added to the global blocklist.
+ A desktop extension was uploaded, either globally by an admin or org-scoped by an org owner.
- - `type: optional "desktop_extension_blocklisted"`
+ - `type: optional "desktop_extension_uploaded"`
- default: desktop_extension_blocklisted
+ default: desktop_extension_uploaded
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -163324,7 +164780,11 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `extension_id: string`
- Blocklisted DXT extension ID
+ DXT extension ID
+
+ - `version: string`
+
+ Version string from the manifest
- `id: optional string`
@@ -163344,13 +164804,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `DesktopExtensionDeleted object`
+ - `DesktopExtensionVersionUploaded object`
- A desktop extension was deleted, either globally by an admin or org-scoped by an org owner.
+ A new version of an existing org-owned desktop extension was uploaded.
- - `type: optional "desktop_extension_deleted"`
+ - `type: optional "desktop_extension_version_uploaded"`
- default: desktop_extension_deleted
+ default: desktop_extension_version_uploaded
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -163562,6 +165022,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
DXT extension ID
+ - `version: string`
+
+ Version string from the manifest
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -163580,17 +165044,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `version: optional string or null`
-
- Specific version deleted (null if all versions)
-
- - `DesktopExtensionRemovedFromAllowlist object`
+ - `InferenceHooksConfigDeleted object`
- A desktop extension was removed from an org's allowlist.
+ Inference hooks configuration was removed for the organization.
- - `type: optional "desktop_extension_removed_from_allowlist"`
+ - `type: optional "inference_hooks_config_deleted"`
- default: desktop_extension_removed_from_allowlist
+ default: inference_hooks_config_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -163798,10 +165258,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `extension_id: string`
-
- DXT extension ID removed from allowlist
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -163820,13 +165276,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `DesktopExtensionUnblocked object`
+ - `InferenceHooksConfigUpdated object`
- A desktop extension was removed from the global blocklist.
+ Inference hooks configuration was created or updated for the organization.
- - `type: optional "desktop_extension_unblocked"`
+ - `type: optional "inference_hooks_config_updated"`
- default: desktop_extension_unblocked
+ default: inference_hooks_config_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -164034,9 +165490,29 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `extension_id: string`
+ - `enabled: boolean`
- Unblocked DXT extension ID
+ Whether Inference hooks enforcement is enabled after this change.
+
+ - `enforcement_mode: string`
+
+ Whether Inference hooks inspects both prompts and responses (prompt_and_response) or prompts only (prompt_only).
+
+ - `fail_mode: string`
+
+ Whether requests are allowed (fail_open) or blocked (fail_closed) when the Inference hooks endpoint cannot be reached.
+
+ - `final_verdict_timeout_ms: number`
+
+ Milliseconds inference waits for the Inference hooks verdict on the response.
+
+ - `prompt_verdict_timeout_ms: number`
+
+ Milliseconds inference waits for the Inference hooks verdict on the prompt.
+
+ - `webhook_url: string`
+
+ The endpoint that inspected prompts and responses are sent to.
- `id: optional string`
@@ -164048,6 +165524,18 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `deny_message: optional string or null`
+
+ Administrator-written text shown to users at the end of the error message when a request is blocked by the organization's Inference hooks policy, as configured after this change. Null when the built-in default message is in effect; an empty string when the administrator configured an empty message, in which case no text is appended.
+
+ - `deny_message_enabled: optional boolean or null`
+
+ Whether the organization has the appended deny message turned on, as configured after this change. When on, the administrator-written message (or the built-in default, when none is configured) is appended to the error users see when a request is blocked by the organization's Inference hooks policy; no text is appended when the administrator-written message is empty, or when this is off.
+
+ - `extra_header_names: optional array of string or null`
+
+ Names of the custom HTTP headers attached to every Inference hooks request after this change, or null when this update did not change headers. Header values are write-only and are not recorded.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -164056,13 +165544,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `DesktopExtensionUploaded object`
+ - `reset_circuit_breaker: optional boolean or null`
- A desktop extension was uploaded, either globally by an admin or org-scoped by an org owner.
+ Whether this update carried an explicit request to clear the circuit breaker. A tripped breaker otherwise survives configuration updates; it also clears whenever an update enables enforcement.
- - `type: optional "desktop_extension_uploaded"`
+ - `rollout_percentage: optional number or null`
- default: desktop_extension_uploaded
+ Percentage of requests (0-100) inspected by Inference hooks after this change, or null when this update did not change it. 0 disables inspection; 100 inspects every request.
+
+ - `shadow_mode: optional boolean or null`
+
+ Whether the organization's Inference hooks run in shadow mode after this change, or null when this update did not change it. In shadow mode, prompts are still sent to the organization's endpoint and verdicts are recorded, but requests are never blocked.
+
+ - `InferenceHooksSigningSecretGenerated object`
+
+ A request signing secret was generated for the organization's Inference hooks configuration.
+
+ - `type: optional "inference_hooks_signing_secret_generated"`
+
+ default: inference_hooks_signing_secret_generated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -164270,13 +165770,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `extension_id: string`
-
- DXT extension ID
-
- - `version: string`
+ - `rotated: boolean`
- Version string from the manifest
+ Whether this generation replaced an existing signing secret (true) or created the organization's first one (false). Replacing a secret invalidates the previous one immediately.
- `id: optional string`
@@ -164296,13 +165792,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `DesktopExtensionVersionUploaded object`
+ - `DomainClaimInitiated object`
- A new version of an existing org-owned desktop extension was uploaded.
+ Domain capture claim initiated over personal accounts on verified domains.
- - `type: optional "desktop_extension_version_uploaded"`
+ - `type: optional "domain_claim_initiated"`
- default: desktop_extension_version_uploaded
+ default: domain_claim_initiated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -164510,14 +166006,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `extension_id: string`
-
- DXT extension ID
-
- - `version: string`
-
- Version string from the manifest
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -164536,13 +166024,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `InferenceHooksConfigDeleted object`
+ - `EndUserInviteRequested object`
- Inference hooks configuration was removed for the organization.
+ Non-admin member submitted an invite request for a new org member.
- - `type: optional "inference_hooks_config_deleted"`
+ - `type: optional "end_user_invite_requested"`
- default: inference_hooks_config_deleted
+ default: end_user_invite_requested
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -164750,6 +166238,8 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `invitee_email: string`
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -164768,13 +166258,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `InferenceHooksConfigUpdated object`
+ - `ExtraUsageBillingEnabled object`
- Inference hooks configuration was created or updated for the organization.
+ Usage credit billing was enabled for an organization.
- - `type: optional "inference_hooks_config_updated"`
+ - `type: optional "extra_usage_billing_enabled"`
- default: inference_hooks_config_updated
+ default: extra_usage_billing_enabled
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -164982,30 +166472,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `enabled: boolean`
-
- Whether Inference hooks enforcement is enabled after this change.
-
- - `enforcement_mode: string`
-
- Whether Inference hooks inspects both prompts and responses (prompt_and_response) or prompts only (prompt_only).
-
- - `fail_mode: string`
-
- Whether requests are allowed (fail_open) or blocked (fail_closed) when the Inference hooks endpoint cannot be reached.
-
- - `final_verdict_timeout_ms: number`
-
- Milliseconds inference waits for the Inference hooks verdict on the response.
-
- - `prompt_verdict_timeout_ms: number`
-
- Milliseconds inference waits for the Inference hooks verdict on the prompt.
-
- - `webhook_url: string`
-
- The endpoint that inspected prompts and responses are sent to.
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -165016,18 +166482,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `deny_message: optional string or null`
-
- Administrator-written text shown to users at the end of the error message when a request is blocked by the organization's Inference hooks policy, as configured after this change. Null when the built-in default message is in effect; an empty string when the administrator configured an empty message, in which case no text is appended.
-
- - `deny_message_enabled: optional boolean or null`
-
- Whether the organization has the appended deny message turned on, as configured after this change. When on, the administrator-written message (or the built-in default, when none is configured) is appended to the error users see when a request is blocked by the organization's Inference hooks policy; no text is appended when the administrator-written message is empty, or when this is off.
-
- - `extra_header_names: optional array of string or null`
-
- Names of the custom HTTP headers attached to every Inference hooks request after this change, or null when this update did not change headers. Header values are write-only and are not recorded.
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -165036,25 +166490,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `reset_circuit_breaker: optional boolean or null`
-
- Whether this update carried an explicit request to clear the circuit breaker. A tripped breaker otherwise survives configuration updates; it also clears whenever an update enables enforcement.
-
- - `rollout_percentage: optional number or null`
-
- Percentage of requests (0-100) inspected by Inference hooks after this change, or null when this update did not change it. 0 disables inspection; 100 inspects every request.
-
- - `shadow_mode: optional boolean or null`
-
- Whether the organization's Inference hooks run in shadow mode after this change, or null when this update did not change it. In shadow mode, prompts are still sent to the organization's endpoint and verdicts are recorded, but requests are never blocked.
-
- - `InferenceHooksSigningSecretGenerated object`
+ - `ExtraUsageCreditGranted object`
- A request signing secret was generated for the organization's Inference hooks configuration.
+ A promotional usage credit grant was claimed.
- - `type: optional "inference_hooks_signing_secret_generated"`
+ - `type: optional "extra_usage_credit_granted"`
- default: inference_hooks_signing_secret_generated
+ default: extra_usage_credit_granted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -165262,10 +166704,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `rotated: boolean`
-
- Whether this generation replaced an existing signing secret (true) or created the organization's first one (false). Replacing a secret invalidates the previous one immediately.
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -165284,13 +166722,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `DomainClaimInitiated object`
+ - `ExtraUsageSpendLimitCreated object`
- Domain capture claim initiated over personal accounts on verified domains.
+ Usage credit spend limit was created.
- - `type: optional "domain_claim_initiated"`
+ - `type: optional "extra_usage_spend_limit_created"`
- default: domain_claim_initiated
+ default: extra_usage_spend_limit_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -165502,12 +166940,24 @@ curl https://api.anthropic.com/v1/compliance/activities \
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `amount: optional number or null`
+
+ The monthly credit limit amount in minor units (e.g. cents).
+
- `created_at: optional string`
When this activity occurred.
format: date-time
+ - `is_enabled: optional boolean or null`
+
+ Whether the spend limit is enabled.
+
+ - `limit_type: optional string or null`
+
+ The type of spend limit created (e.g. organization, seat_tier, member, service, group).
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -165516,13 +166966,23 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `EndUserInviteRequested object`
+ - `spend_limit_id: optional string or null`
- Non-admin member submitted an invite request for a new org member.
+ Tagged ID of the spend limit.
- - `type: optional "end_user_invite_requested"`
+ - `user_id: optional string or null`
- default: end_user_invite_requested
+ **Deprecated**
+
+ Deprecated. Tagged ID of the admin who performed the action — not the target member. Use `spend_limit_id` to look up the target member.
+
+ - `ExtraUsageSpendLimitDeleted object`
+
+ Usage credit spend limit was deleted.
+
+ - `type: optional "extra_usage_spend_limit_deleted"`
+
+ default: extra_usage_spend_limit_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -165730,8 +167190,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `invitee_email: string`
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -165750,13 +167208,23 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ExtraUsageBillingEnabled object`
+ - `spend_limit_id: optional string or null`
- Usage credit billing was enabled for an organization.
+ Tagged ID of the spend limit.
- - `type: optional "extra_usage_billing_enabled"`
+ - `user_id: optional string or null`
- default: extra_usage_billing_enabled
+ **Deprecated**
+
+ Deprecated. Tagged ID of the admin who performed the action — not the target member. Use `spend_limit_id` to look up the target member.
+
+ - `ExtraUsageSpendLimitIncreaseRequestApproved object`
+
+ A usage credit spend limit increase request was approved.
+
+ - `type: optional "extra_usage_spend_limit_increase_request_approved"`
+
+ default: extra_usage_spend_limit_increase_request_approved
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -165968,6 +167436,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
Unique identifier for the activity e.g. 'activity_abcd1234'
+ - `amount: optional number or null`
+
+ The approved spend limit amount in minor units (e.g. cents).
+
- `created_at: optional string`
When this activity occurred.
@@ -165982,13 +167454,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ExtraUsageCreditGranted object`
+ - `requester_user_id: optional string or null`
- A promotional usage credit grant was claimed.
+ Tagged ID of the member who requested the increase, e.g. "user_01HX...".
- - `type: optional "extra_usage_credit_granted"`
+ - `spend_limit_id: optional string or null`
- default: extra_usage_credit_granted
+ Tagged ID of the member's spend limit that the approval created or updated.
+
+ - `spend_limit_increase_request_id: optional string or null`
+
+ Tagged ID of the spend limit increase request that was approved.
+
+ - `ExtraUsageSpendLimitIncreaseRequestDenied object`
+
+ A usage credit spend limit increase request was denied.
+
+ - `type: optional "extra_usage_spend_limit_increase_request_denied"`
+
+ default: extra_usage_spend_limit_increase_request_denied
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -166214,13 +167698,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ExtraUsageSpendLimitCreated object`
+ - `requester_user_id: optional string or null`
- Usage credit spend limit was created.
+ Tagged ID of the member who requested the increase, e.g. "user_01HX...".
- - `type: optional "extra_usage_spend_limit_created"`
+ - `spend_limit_increase_request_id: optional string or null`
- default: extra_usage_spend_limit_created
+ Tagged ID of the spend limit increase request that was denied.
+
+ - `ExtraUsageSpendLimitUpdated object`
+
+ Usage credit spend limit was updated.
+
+ - `type: optional "extra_usage_spend_limit_updated"`
+
+ default: extra_usage_spend_limit_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -166434,7 +167926,7 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `amount: optional number or null`
- The monthly credit limit amount in minor units (e.g. cents).
+ The new monthly credit limit amount in minor units (e.g. cents).
- `created_at: optional string`
@@ -166448,7 +167940,7 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `limit_type: optional string or null`
- The type of spend limit created (e.g. organization, seat_tier, member, service, group).
+ The type of spend limit updated (e.g. organization, seat_tier, member, service, group).
- `organization_id: optional string or null`
@@ -166468,13 +167960,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Deprecated. Tagged ID of the admin who performed the action — not the target member. Use `spend_limit_id` to look up the target member.
- - `ExtraUsageSpendLimitDeleted object`
+ - `ClaudeFileDeleted object`
- Usage credit spend limit was deleted.
+ A file was deleted.
- - `type: optional "extra_usage_spend_limit_deleted"`
+ - `type: optional "claude_file_deleted"`
- default: extra_usage_spend_limit_deleted
+ default: claude_file_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -166682,6 +168174,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `claude_file_id: string`
+
+ Tagged ID of the file that was deleted, e.g. "claude_file_01HX...".
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -166692,6 +168188,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `filename: optional string or null`
+
+ Name of the deleted file, when known.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -166700,23 +168200,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `spend_limit_id: optional string or null`
-
- Tagged ID of the spend limit.
-
- - `user_id: optional string or null`
-
- **Deprecated**
-
- Deprecated. Tagged ID of the admin who performed the action — not the target member. Use `spend_limit_id` to look up the target member.
-
- - `ExtraUsageSpendLimitIncreaseRequestApproved object`
+ - `ClaudeFileUploaded object`
- A usage credit spend limit increase request was approved.
+ A file was uploaded.
- - `type: optional "extra_usage_spend_limit_increase_request_approved"`
+ - `type: optional "claude_file_uploaded"`
- default: extra_usage_spend_limit_increase_request_approved
+ default: claude_file_uploaded
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -166924,13 +168414,21 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `claude_file_id: string`
+
+ Tagged ID of the file that was uploaded, e.g. "claude_file_01HX...".
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `amount: optional number or null`
+ - `claude_chat_id: optional string or null`
- The approved spend limit amount in minor units (e.g. cents).
+ Chat ID if known at upload time (null for the upload-then-attach flow). To find which chats a file was later attached to, use `GET /v1/compliance/apps/chats/files/{claude_file_id}`.
+
+ - `claude_project_id: optional string or null`
+
+ Project ID if file was uploaded to a project
- `created_at: optional string`
@@ -166938,6 +168436,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `filename: optional string or null`
+
+ Name of the uploaded file, when known.
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -166946,25 +168448,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `requester_user_id: optional string or null`
-
- Tagged ID of the member who requested the increase, e.g. "user_01HX...".
-
- - `spend_limit_id: optional string or null`
-
- Tagged ID of the member's spend limit that the approval created or updated.
-
- - `spend_limit_increase_request_id: optional string or null`
-
- Tagged ID of the spend limit increase request that was approved.
-
- - `ExtraUsageSpendLimitIncreaseRequestDenied object`
+ - `GheConfigurationCreated object`
- A usage credit spend limit increase request was denied.
+ Admin created a GHE configuration.
- - `type: optional "extra_usage_spend_limit_increase_request_denied"`
+ - `type: optional "ghe_configuration_created"`
- default: extra_usage_spend_limit_increase_request_denied
+ default: ghe_configuration_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -167172,6 +168662,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `ghe_configuration_id: string`
+
+ ID of the GHE configuration
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -167182,6 +168676,14 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
+ - `display_name: optional string or null`
+
+ Display name given to the configuration
+
+ - `hostname: optional string or null`
+
+ Hostname of the GitHub Enterprise instance
+
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -167190,21 +168692,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `requester_user_id: optional string or null`
-
- Tagged ID of the member who requested the increase, e.g. "user_01HX...".
-
- - `spend_limit_increase_request_id: optional string or null`
+ - `port: optional number or null`
- Tagged ID of the spend limit increase request that was denied.
+ Custom port, if not the HTTPS default
- - `ExtraUsageSpendLimitUpdated object`
+ - `GheConfigurationDeleted object`
- Usage credit spend limit was updated.
+ Admin deleted a GHE configuration.
- - `type: optional "extra_usage_spend_limit_updated"`
+ - `type: optional "ghe_configuration_deleted"`
- default: extra_usage_spend_limit_updated
+ default: ghe_configuration_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -167412,13 +168910,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `id: optional string`
+ - `ghe_configuration_id: string`
- Unique identifier for the activity e.g. 'activity_abcd1234'
+ ID of the GHE configuration
- - `amount: optional number or null`
+ - `id: optional string`
- The new monthly credit limit amount in minor units (e.g. cents).
+ Unique identifier for the activity e.g. 'activity_abcd1234'
- `created_at: optional string`
@@ -167426,13 +168924,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `is_enabled: optional boolean or null`
+ - `display_name: optional string or null`
- Whether the spend limit is enabled.
+ Display name the configuration had when deleted
- - `limit_type: optional string or null`
+ - `hostname: optional string or null`
- The type of spend limit updated (e.g. organization, seat_tier, member, service, group).
+ Hostname of the GitHub Enterprise instance
- `organization_id: optional string or null`
@@ -167442,23 +168940,17 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `spend_limit_id: optional string or null`
-
- Tagged ID of the spend limit.
-
- - `user_id: optional string or null`
-
- **Deprecated**
+ - `port: optional number or null`
- Deprecated. Tagged ID of the admin who performed the action — not the target member. Use `spend_limit_id` to look up the target member.
+ Custom port, if not the HTTPS default
- - `ClaudeFileDeleted object`
+ - `GheConfigurationUpdated object`
- A file was deleted.
+ Admin updated a GHE configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.
- - `type: optional "claude_file_deleted"`
+ - `type: optional "ghe_configuration_updated"`
- default: claude_file_deleted
+ default: ghe_configuration_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -167666,9 +169158,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_file_id: string`
+ - `ghe_configuration_id: string`
- Tagged ID of the file that was deleted, e.g. "claude_file_01HX...".
+ ID of the GHE configuration
- `id: optional string`
@@ -167680,9 +169172,37 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `filename: optional string or null`
+ - `custom_ca_certificate_updated: optional boolean or null`
- Name of the deleted file, when known.
+ Whether the custom CA certificate was replaced in this update
+
+ - `display_name: optional string or null`
+
+ New display name, when it changed
+
+ - `github_app_client_id: optional string or null`
+
+ New GitHub App client ID, when it changed
+
+ - `github_app_client_secret_updated: optional boolean or null`
+
+ Whether the GitHub App client secret was replaced in this update
+
+ - `github_app_id: optional number or null`
+
+ New GitHub App ID, when it changed
+
+ - `github_app_private_key_updated: optional boolean or null`
+
+ Whether the GitHub App private key was replaced in this update
+
+ - `hostname: optional string or null`
+
+ Hostname of the GitHub Enterprise instance (immutable; included for context)
+
+ - `is_active: optional boolean or null`
+
+ New active state, when it changed
- `organization_id: optional string or null`
@@ -167692,13 +169212,45 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeFileUploaded object`
+ - `port: optional number or null`
- A file was uploaded.
+ New port, when it changed
- - `type: optional "claude_file_uploaded"`
+ - `previous_display_name: optional string or null`
- default: claude_file_uploaded
+ Display name before the change, when it changed
+
+ - `previous_github_app_client_id: optional string or null`
+
+ GitHub App client ID before the change, when it changed
+
+ - `previous_github_app_id: optional number or null`
+
+ GitHub App ID before the change, when it changed
+
+ - `previous_is_active: optional boolean or null`
+
+ Active state before the change, when it changed
+
+ - `previous_port: optional number or null`
+
+ Port before the change, when it changed
+
+ - `read_replica_hostnames_updated: optional boolean or null`
+
+ Whether the read replica hostnames were replaced in this update
+
+ - `webhook_secret_updated: optional boolean or null`
+
+ Whether the webhook secret was replaced in this update
+
+ - `GheUserConnected object`
+
+ User connected to a GHE instance.
+
+ - `type: optional "ghe_user_connected"`
+
+ default: ghe_user_connected
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -167906,31 +169458,19 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `claude_file_id: string`
-
- Tagged ID of the file that was uploaded, e.g. "claude_file_01HX...".
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
- - `claude_chat_id: optional string or null`
-
- Chat ID if known at upload time (null for the upload-then-attach flow). To find which chats a file was later attached to, use `GET /v1/compliance/apps/chats/files/{claude_file_id}`.
-
- - `claude_project_id: optional string or null`
-
- Project ID if file was uploaded to a project
-
- `created_at: optional string`
When this activity occurred.
format: date-time
- - `filename: optional string or null`
+ - `ghe_configuration_id: optional string or null`
- Name of the uploaded file, when known.
+ ID of the GHE configuration
- `organization_id: optional string or null`
@@ -167940,13 +169480,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `GheConfigurationCreated object`
+ - `GheUserDisconnected object`
- Admin created a GHE configuration.
+ User disconnected from a GHE instance.
- - `type: optional "ghe_configuration_created"`
+ - `type: optional "ghe_user_disconnected"`
- default: ghe_configuration_created
+ default: ghe_user_disconnected
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -168154,10 +169694,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `ghe_configuration_id: string`
-
- ID of the GHE configuration
-
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -168168,13 +169704,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `display_name: optional string or null`
-
- Display name given to the configuration
-
- - `hostname: optional string or null`
+ - `ghe_configuration_id: optional string or null`
- Hostname of the GitHub Enterprise instance
+ ID of the GHE configuration
- `organization_id: optional string or null`
@@ -168184,17 +169716,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `port: optional number or null`
-
- Custom port, if not the HTTPS default
-
- - `GheConfigurationDeleted object`
+ - `GheWebhookSignatureInvalid object`
- Admin deleted a GHE configuration.
+ Webhook signature validation failed.
- - `type: optional "ghe_configuration_deleted"`
+ - `type: optional "ghe_webhook_signature_invalid"`
- default: ghe_configuration_deleted
+ default: ghe_webhook_signature_invalid
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -168416,14 +169944,6 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `display_name: optional string or null`
-
- Display name the configuration had when deleted
-
- - `hostname: optional string or null`
-
- Hostname of the GitHub Enterprise instance
-
- `organization_id: optional string or null`
Organization ID this activity is associated with
@@ -168432,17 +169952,13 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `port: optional number or null`
-
- Custom port, if not the HTTPS default
-
- - `GheConfigurationUpdated object`
+ - `ClaudeGitHubIntegrationCreated object`
- Admin updated a GHE configuration. Previous/new field pairs are recorded only for settings that changed in the update; secret credentials are never recorded, only whether they were replaced.
+ A GitHub integration was enabled for the organization.
- - `type: optional "ghe_configuration_updated"`
+ - `type: optional "claude_github_integration_created"`
- default: ghe_configuration_updated
+ default: claude_github_integration_created
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -168650,9 +170166,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `ghe_configuration_id: string`
+ - `integration_id: string`
- ID of the GHE configuration
+ Tagged ID of the GitHub integration, e.g. "claude_sync_source_01HX...".
- `id: optional string`
@@ -168664,85 +170180,37 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `custom_ca_certificate_updated: optional boolean or null`
-
- Whether the custom CA certificate was replaced in this update
-
- - `display_name: optional string or null`
-
- New display name, when it changed
-
- - `github_app_client_id: optional string or null`
-
- New GitHub App client ID, when it changed
-
- - `github_app_client_secret_updated: optional boolean or null`
-
- Whether the GitHub App client secret was replaced in this update
-
- - `github_app_id: optional number or null`
-
- New GitHub App ID, when it changed
-
- - `github_app_private_key_updated: optional boolean or null`
-
- Whether the GitHub App private key was replaced in this update
-
- - `hostname: optional string or null`
-
- Hostname of the GitHub Enterprise instance (immutable; included for context)
-
- - `is_active: optional boolean or null`
+ - `enabled: optional boolean or null`
- New active state, when it changed
+ Whether the integration is enabled after this change.
- `organization_id: optional string or null`
Organization ID this activity is associated with
- - `organization_uuid: optional string or null`
-
- Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
-
- - `port: optional number or null`
-
- New port, when it changed
-
- - `previous_display_name: optional string or null`
-
- Display name before the change, when it changed
-
- - `previous_github_app_client_id: optional string or null`
-
- GitHub App client ID before the change, when it changed
-
- - `previous_github_app_id: optional number or null`
-
- GitHub App ID before the change, when it changed
-
- - `previous_is_active: optional boolean or null`
+ - `organization_name: optional string or null`
- Active state before the change, when it changed
+ Name of the GitHub organization the integration is connected to, when known.
- - `previous_port: optional number or null`
+ - `organization_uuid: optional string or null`
- Port before the change, when it changed
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `read_replica_hostnames_updated: optional boolean or null`
+ - `previous_enabled: optional boolean or null`
- Whether the read replica hostnames were replaced in this update
+ Whether the integration was enabled before this change; null when the integration had never been configured.
- - `webhook_secret_updated: optional boolean or null`
+ - `repository_name: optional string or null`
- Whether the webhook secret was replaced in this update
+ Name of the GitHub repository the integration is connected to, when known.
- - `GheUserConnected object`
+ - `ClaudeGitHubIntegrationDeleted object`
- User connected to a GHE instance.
+ A GitHub integration was disabled for the organization.
- - `type: optional "ghe_user_connected"`
+ - `type: optional "claude_github_integration_deleted"`
- default: ghe_user_connected
+ default: claude_github_integration_deleted
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -168950,6 +170418,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
+ - `integration_id: string`
+
+ Tagged ID of the GitHub integration, e.g. "claude_sync_source_01HX...".
+
- `id: optional string`
Unique identifier for the activity e.g. 'activity_abcd1234'
@@ -168960,261 +170432,37 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `ghe_configuration_id: optional string or null`
+ - `enabled: optional boolean or null`
- ID of the GHE configuration
+ Whether the integration is enabled after this change.
- `organization_id: optional string or null`
Organization ID this activity is associated with
- - `organization_uuid: optional string or null`
-
- Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
-
- - `GheUserDisconnected object`
-
- User disconnected from a GHE instance.
-
- - `type: optional "ghe_user_disconnected"`
-
- default: ghe_user_disconnected
-
- - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
-
- - `APIActor object`
-
- - `type: optional "api_actor"`
-
- default: api_actor
-
- - `api_key_id: string`
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `UserActor object`
-
- - `type: optional "user_actor"`
-
- default: user_actor
-
- - `email_address: string`
-
- format: email
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `user_id: string`
-
- - `UnauthenticatedUserActor object`
-
- - `type: optional "unauthenticated_user_actor"`
-
- default: unauthenticated_user_actor
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `unauthenticated_email_address: optional string or null`
-
- format: email
-
- - `AnthropicActor object`
-
- - `type: optional "anthropic_actor"`
-
- default: anthropic_actor
-
- - `email_address: optional string or null`
-
- format: email
-
- - `SystemActor object`
-
- Automated background processing performed by Anthropic systems, acting
- without a user or customer credential.
-
- - `type: optional "system_actor"`
-
- default: system_actor
-
- - `service: optional string or null`
-
- Name of the automated process that performed the action, when known.
-
- - `AdminAPIKeyActor object`
-
- - `type: optional "admin_api_key_actor"`
-
- default: admin_api_key_actor
-
- - `admin_api_key_id: string`
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `ServiceAccountActor object`
-
- - `type: optional "service_account_actor"`
-
- default: service_account_actor
-
- - `ip_address: string`
-
- - `service_account_id: string`
-
- - `user_agent: string`
-
- - `ScimDirectorySyncActor object`
-
- - `type: optional "scim_directory_sync_actor"`
-
- default: scim_directory_sync_actor
-
- - `directory_id: string`
-
- - `workos_event_id: string`
-
- - `idp_connection_type: optional string or null`
-
- - `FederatedIdentityActor object`
-
- A federated external workload authenticated via a verified OIDC token.
-
- Carries the verified issuer, subject, and audience claims from the
- presented JWT.
-
- - `type: optional "federated_identity_actor"`
-
- default: federated_identity_actor
-
- - `issuer: string`
-
- - `subject: string`
-
- - `audience: optional array of string`
-
- - `ip_address: optional string or null`
-
- - `user_agent: optional string or null`
-
- - `FederatedActor object`
-
- An external identity asserted by a trusted provider — a cloud-provider
- gateway or a customer-registered federation issuer — acting without an
- Anthropic-provisioned account or service account.
-
- - `type: optional "federated_actor"`
-
- default: federated_actor
-
- - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
-
- - `FederatedActorAwsProvider object`
-
- Asserting party: the AWS account the organization is bound to.
-
- - `type: optional "aws"`
-
- default: aws
-
- - `account_id: string`
-
- - `signed_principal: string`
-
- The AWS-signed ARN of the IAM principal that requested the token.
-
- - `FederatedActorAzureProvider object`
-
- Asserting party: the Azure subscription the organization is bound to.
-
- - `type: optional "azure"`
-
- default: azure
-
- - `subscription_id: string`
-
- - `FederatedActorGcpProvider object`
-
- Asserting party: the GCP project the organization is bound to.
-
- - `type: optional "gcp"`
-
- default: gcp
-
- - `project_number: string`
-
- - `FederatedActorOidcProvider object`
-
- Asserting party: a customer-registered OIDC federation issuer.
-
- - `type: optional "oidc"`
-
- default: oidc
-
- - `issuer: optional string or null`
-
- The federation issuer's URL. Null when the presented credential failed verification.
-
- - `ip_address: optional string or null`
-
- - `subject: optional string or null`
-
- The provider's verified identifier for the caller; its form depends on the provider.
-
- - `user_agent: optional string or null`
-
- - `AttestedDeviceActor object`
-
- An attested mobile device authenticated via Apple App Attest.
-
- - `type: optional "attested_device_actor"`
-
- default: attested_device_actor
-
- - `external_client_id: string`
-
- - `kid_hash: string`
-
- - `ip_address: optional string or null`
-
- - `user_agent: optional string or null`
-
- - `id: optional string`
-
- Unique identifier for the activity e.g. 'activity_abcd1234'
-
- - `created_at: optional string`
-
- When this activity occurred.
+ - `organization_name: optional string or null`
- format: date-time
+ Name of the GitHub organization the integration was connected to, when known.
- - `ghe_configuration_id: optional string or null`
+ - `organization_uuid: optional string or null`
- ID of the GHE configuration
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `organization_id: optional string or null`
+ - `previous_enabled: optional boolean or null`
- Organization ID this activity is associated with
+ Whether the integration was enabled before this change; null when the integration had never been configured.
- - `organization_uuid: optional string or null`
+ - `repository_name: optional string or null`
- Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+ Name of the GitHub repository the integration was connected to, when known.
- - `GheWebhookSignatureInvalid object`
+ - `ClaudeGitHubIntegrationUpdated object`
- Webhook signature validation failed.
+ A GitHub integration's configuration was updated.
- - `type: optional "ghe_webhook_signature_invalid"`
+ - `type: optional "claude_github_integration_updated"`
- default: ghe_webhook_signature_invalid
+ default: claude_github_integration_updated
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -169422,9 +170670,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `ghe_configuration_id: string`
+ - `integration_id: string`
- ID of the GHE configuration
+ Tagged ID of the GitHub integration, e.g. "claude_sync_source_01HX...".
- `id: optional string`
@@ -169440,17 +170688,25 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization ID this activity is associated with
+ - `organization_name: optional string or null`
+
+ Name of the GitHub organization the integration is connected to, when known.
+
- `organization_uuid: optional string or null`
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `ClaudeGitHubIntegrationCreated object`
+ - `repository_name: optional string or null`
- A GitHub integration was enabled for the organization.
+ Name of the GitHub repository the integration is connected to, when known.
- - `type: optional "claude_github_integration_created"`
+ - `GitHubAppInstallationLinked object`
- default: claude_github_integration_created
+ An installation of the Claude GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Claude Code features act on that GitHub account's repositories.
+
+ - `type: optional "github_app_installation_linked"`
+
+ default: github_app_installation_linked
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -169658,9 +170914,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `integration_id: string`
+ - `github_installation_id: number`
- Tagged ID of the GitHub integration, e.g. "claude_sync_source_01HX...".
+ Numeric GitHub ID of the installation that was linked
- `id: optional string`
@@ -169672,37 +170928,29 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `enabled: optional boolean or null`
+ - `github_account_login: optional string or null`
- Whether the integration is enabled after this change.
+ Login of the GitHub organization or user account the App is installed on
- - `organization_id: optional string or null`
+ - `github_account_type: optional string or null`
- Organization ID this activity is associated with
+ Whether that GitHub account is an organization or a user account, as reported by GitHub ("Organization" or "User")
- - `organization_name: optional string or null`
+ - `organization_id: optional string or null`
- Name of the GitHub organization the integration is connected to, when known.
+ Organization ID this activity is associated with
- `organization_uuid: optional string or null`
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `previous_enabled: optional boolean or null`
-
- Whether the integration was enabled before this change; null when the integration had never been configured.
-
- - `repository_name: optional string or null`
+ - `GitHubAppInstallationUnlinked object`
- Name of the GitHub repository the integration is connected to, when known.
+ An installation of the Claude GitHub App was unlinked from the organization, so the organization's Claude Code features can no longer act on that GitHub account's repositories through it.
- - `ClaudeGitHubIntegrationDeleted object`
+ - `type: optional "github_app_installation_unlinked"`
- A GitHub integration was disabled for the organization.
-
- - `type: optional "claude_github_integration_deleted"`
-
- default: claude_github_integration_deleted
+ default: github_app_installation_unlinked
- `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
@@ -169910,9 +171158,9 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `user_agent: optional string or null`
- - `integration_id: string`
+ - `github_installation_id: number`
- Tagged ID of the GitHub integration, e.g. "claude_sync_source_01HX...".
+ Numeric GitHub ID of the installation that was unlinked
- `id: optional string`
@@ -169924,274 +171172,22 @@ curl https://api.anthropic.com/v1/compliance/activities \
format: date-time
- - `enabled: optional boolean or null`
-
- Whether the integration is enabled after this change.
-
- - `organization_id: optional string or null`
-
- Organization ID this activity is associated with
-
- - `organization_name: optional string or null`
-
- Name of the GitHub organization the integration was connected to, when known.
-
- - `organization_uuid: optional string or null`
-
- Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
-
- - `previous_enabled: optional boolean or null`
-
- Whether the integration was enabled before this change; null when the integration had never been configured.
-
- - `repository_name: optional string or null`
-
- Name of the GitHub repository the integration was connected to, when known.
-
- - `ClaudeGitHubIntegrationUpdated object`
-
- A GitHub integration's configuration was updated.
-
- - `type: optional "claude_github_integration_updated"`
-
- default: claude_github_integration_updated
-
- - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
-
- - `APIActor object`
-
- - `type: optional "api_actor"`
-
- default: api_actor
-
- - `api_key_id: string`
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `UserActor object`
-
- - `type: optional "user_actor"`
-
- default: user_actor
-
- - `email_address: string`
-
- format: email
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `user_id: string`
-
- - `UnauthenticatedUserActor object`
-
- - `type: optional "unauthenticated_user_actor"`
-
- default: unauthenticated_user_actor
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `unauthenticated_email_address: optional string or null`
-
- format: email
-
- - `AnthropicActor object`
-
- - `type: optional "anthropic_actor"`
-
- default: anthropic_actor
-
- - `email_address: optional string or null`
-
- format: email
-
- - `SystemActor object`
-
- Automated background processing performed by Anthropic systems, acting
- without a user or customer credential.
-
- - `type: optional "system_actor"`
-
- default: system_actor
-
- - `service: optional string or null`
-
- Name of the automated process that performed the action, when known.
-
- - `AdminAPIKeyActor object`
-
- - `type: optional "admin_api_key_actor"`
-
- default: admin_api_key_actor
-
- - `admin_api_key_id: string`
-
- - `ip_address: string`
-
- - `user_agent: string`
-
- - `ServiceAccountActor object`
-
- - `type: optional "service_account_actor"`
-
- default: service_account_actor
-
- - `ip_address: string`
-
- - `service_account_id: string`
-
- - `user_agent: string`
-
- - `ScimDirectorySyncActor object`
-
- - `type: optional "scim_directory_sync_actor"`
-
- default: scim_directory_sync_actor
-
- - `directory_id: string`
-
- - `workos_event_id: string`
-
- - `idp_connection_type: optional string or null`
-
- - `FederatedIdentityActor object`
-
- A federated external workload authenticated via a verified OIDC token.
-
- Carries the verified issuer, subject, and audience claims from the
- presented JWT.
-
- - `type: optional "federated_identity_actor"`
-
- default: federated_identity_actor
-
- - `issuer: string`
-
- - `subject: string`
-
- - `audience: optional array of string`
-
- - `ip_address: optional string or null`
-
- - `user_agent: optional string or null`
-
- - `FederatedActor object`
-
- An external identity asserted by a trusted provider — a cloud-provider
- gateway or a customer-registered federation issuer — acting without an
- Anthropic-provisioned account or service account.
-
- - `type: optional "federated_actor"`
-
- default: federated_actor
-
- - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
-
- - `FederatedActorAwsProvider object`
-
- Asserting party: the AWS account the organization is bound to.
-
- - `type: optional "aws"`
-
- default: aws
-
- - `account_id: string`
-
- - `signed_principal: string`
-
- The AWS-signed ARN of the IAM principal that requested the token.
-
- - `FederatedActorAzureProvider object`
-
- Asserting party: the Azure subscription the organization is bound to.
-
- - `type: optional "azure"`
-
- default: azure
-
- - `subscription_id: string`
-
- - `FederatedActorGcpProvider object`
-
- Asserting party: the GCP project the organization is bound to.
+ - `github_account_login: optional string or null`
- - `type: optional "gcp"`
+ Login of the GitHub organization or user account the App is installed on
- default: gcp
+ - `github_account_type: optional string or null`
- - `project_number: string`
-
- - `FederatedActorOidcProvider object`
-
- Asserting party: a customer-registered OIDC federation issuer.
-
- - `type: optional "oidc"`
-
- default: oidc
-
- - `issuer: optional string or null`
-
- The federation issuer's URL. Null when the presented credential failed verification.
-
- - `ip_address: optional string or null`
-
- - `subject: optional string or null`
-
- The provider's verified identifier for the caller; its form depends on the provider.
-
- - `user_agent: optional string or null`
-
- - `AttestedDeviceActor object`
-
- An attested mobile device authenticated via Apple App Attest.
-
- - `type: optional "attested_device_actor"`
-
- default: attested_device_actor
-
- - `external_client_id: string`
-
- - `kid_hash: string`
-
- - `ip_address: optional string or null`
-
- - `user_agent: optional string or null`
-
- - `integration_id: string`
-
- Tagged ID of the GitHub integration, e.g. "claude_sync_source_01HX...".
-
- - `id: optional string`
-
- Unique identifier for the activity e.g. 'activity_abcd1234'
-
- - `created_at: optional string`
-
- When this activity occurred.
-
- format: date-time
+ Whether that GitHub account is an organization or a user account, as reported by GitHub ("Organization" or "User")
- `organization_id: optional string or null`
Organization ID this activity is associated with
- - `organization_name: optional string or null`
-
- Name of the GitHub organization the integration is connected to, when known.
-
- `organization_uuid: optional string or null`
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
- - `repository_name: optional string or null`
-
- Name of the GitHub repository the integration is connected to, when known.
-
- `GitHubTokenImport object`
A user attempted to import a personal GitHub access token for use with Claude Code. The `result` field indicates the outcome of the import (imported, rejected, or failed).
@@ -205456,7 +206452,7 @@ curl https://api.anthropic.com/v1/compliance/activities \
- `ClaudeCodeWebEnabled object`
- The Claude Code on the web setting was changed for the organization.
+ The Claude Code cloud sessions setting was changed for the organization.
- `type: optional "claude_code_web_enabled"`
@@ -250185,6 +251181,10 @@ curl https://api.anthropic.com/v1/compliance/activities \
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+ - `tunnel_token_id: optional string or null`
+
+ Id of the tunnel token issued with the tunnel and returned once in the create response; set only when creating the tunnel also issued its token, and absent for a tunnel whose token is revealed separately
+
- `TunnelTokenMinted object`
An OAuth bearer token for the tunnel management API was minted.
diff --git a/content/en/api/compliance/activities/list.md b/content/en/api/compliance/activities/list.md
index 22d9f332b3..e9390002fd 100644
--- a/content/en/api/compliance/activities/list.md
+++ b/content/en/api/compliance/activities/list.md
@@ -15,7 +15,7 @@ compliance activities that can be filtered by various criteria.
## Query parameters
-- `activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 501 more`
+- `activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 503 more`
Filter activities by type. See the response `data` schema for the additional fields each type returns. Cannot be combined with `exclude_activity_types[]`.
@@ -819,6 +819,14 @@ compliance activities that can be filtered by various criteria.
Webhook signature validation failed.
+ - `"github_app_installation_linked"`
+
+ An installation of the Claude GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Claude Code features act on that GitHub account's repositories.
+
+ - `"github_app_installation_unlinked"`
+
+ An installation of the Claude GitHub App was unlinked from the organization, so the organization's Claude Code features can no longer act on that GitHub account's repositories through it.
+
- `"github_token_import"`
A user attempted to import a personal GitHub access token for use with Claude Code. The `result` field indicates the outcome of the import (imported, rejected, or failed).
@@ -2090,7 +2098,7 @@ compliance activities that can be filtered by various criteria.
format: date-time
-- `exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 501 more`
+- `exclude_activity_types: optional array of "abuse_decision_received" or "account_deleted" or "admin_api_key_created" or 503 more`
Exclude activities of these types. Cannot be combined with `activity_types[]`.
@@ -2894,6 +2902,14 @@ compliance activities that can be filtered by various criteria.
Webhook signature validation failed.
+ - `"github_app_installation_linked"`
+
+ An installation of the Claude GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Claude Code features act on that GitHub account's repositories.
+
+ - `"github_app_installation_unlinked"`
+
+ An installation of the Claude GitHub App was unlinked from the organization, so the organization's Claude Code features can no longer act on that GitHub account's repositories through it.
+
- `"github_token_import"`
A user attempted to import a personal GitHub access token for use with Claude Code. The `result` field indicates the outcome of the import (imported, rejected, or failed).
@@ -4157,7 +4173,7 @@ compliance activities that can be filtered by various criteria.
## Returns
-- `data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 501 more`
+- `data: optional array of AbuseDecisionReceived or AccountDeleted or AdminAPIKeyCreated or 503 more`
List of activity records. Each element's `type` field identifies which activity it is and which additional fields are present.
@@ -45053,6 +45069,494 @@ compliance activities that can be filtered by various criteria.
Name of the GitHub repository the integration is connected to, when known.
+ - `GitHubAppInstallationLinked object`
+
+ An installation of the Claude GitHub App (a GitHub organization or user account where the App is installed) was linked to the organization, letting the organization's Claude Code features act on that GitHub account's repositories.
+
+ - `type: optional "github_app_installation_linked"`
+
+ default: github_app_installation_linked
+
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+
+ - `APIActor object`
+
+ - `type: optional "api_actor"`
+
+ default: api_actor
+
+ - `api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `UserActor object`
+
+ - `type: optional "user_actor"`
+
+ default: user_actor
+
+ - `email_address: string`
+
+ format: email
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `user_id: string`
+
+ - `UnauthenticatedUserActor object`
+
+ - `type: optional "unauthenticated_user_actor"`
+
+ default: unauthenticated_user_actor
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `unauthenticated_email_address: optional string or null`
+
+ format: email
+
+ - `AnthropicActor object`
+
+ - `type: optional "anthropic_actor"`
+
+ default: anthropic_actor
+
+ - `email_address: optional string or null`
+
+ format: email
+
+ - `SystemActor object`
+
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
+
+ - `type: optional "system_actor"`
+
+ default: system_actor
+
+ - `service: optional string or null`
+
+ Name of the automated process that performed the action, when known.
+
+ - `AdminAPIKeyActor object`
+
+ - `type: optional "admin_api_key_actor"`
+
+ default: admin_api_key_actor
+
+ - `admin_api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `ServiceAccountActor object`
+
+ - `type: optional "service_account_actor"`
+
+ default: service_account_actor
+
+ - `ip_address: string`
+
+ - `service_account_id: string`
+
+ - `user_agent: string`
+
+ - `ScimDirectorySyncActor object`
+
+ - `type: optional "scim_directory_sync_actor"`
+
+ default: scim_directory_sync_actor
+
+ - `directory_id: string`
+
+ - `workos_event_id: string`
+
+ - `idp_connection_type: optional string or null`
+
+ - `FederatedIdentityActor object`
+
+ A federated external workload authenticated via a verified OIDC token.
+
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
+
+ - `type: optional "federated_identity_actor"`
+
+ default: federated_identity_actor
+
+ - `issuer: string`
+
+ - `subject: string`
+
+ - `audience: optional array of string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `FederatedActor object`
+
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
+
+ - `type: optional "federated_actor"`
+
+ default: federated_actor
+
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+
+ - `FederatedActorAwsProvider object`
+
+ Asserting party: the AWS account the organization is bound to.
+
+ - `type: optional "aws"`
+
+ default: aws
+
+ - `account_id: string`
+
+ - `signed_principal: string`
+
+ The AWS-signed ARN of the IAM principal that requested the token.
+
+ - `FederatedActorAzureProvider object`
+
+ Asserting party: the Azure subscription the organization is bound to.
+
+ - `type: optional "azure"`
+
+ default: azure
+
+ - `subscription_id: string`
+
+ - `FederatedActorGcpProvider object`
+
+ Asserting party: the GCP project the organization is bound to.
+
+ - `type: optional "gcp"`
+
+ default: gcp
+
+ - `project_number: string`
+
+ - `FederatedActorOidcProvider object`
+
+ Asserting party: a customer-registered OIDC federation issuer.
+
+ - `type: optional "oidc"`
+
+ default: oidc
+
+ - `issuer: optional string or null`
+
+ The federation issuer's URL. Null when the presented credential failed verification.
+
+ - `ip_address: optional string or null`
+
+ - `subject: optional string or null`
+
+ The provider's verified identifier for the caller; its form depends on the provider.
+
+ - `user_agent: optional string or null`
+
+ - `AttestedDeviceActor object`
+
+ An attested mobile device authenticated via Apple App Attest.
+
+ - `type: optional "attested_device_actor"`
+
+ default: attested_device_actor
+
+ - `external_client_id: string`
+
+ - `kid_hash: string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `github_installation_id: number`
+
+ Numeric GitHub ID of the installation that was linked
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
+
+ - `created_at: optional string`
+
+ When this activity occurred.
+
+ format: date-time
+
+ - `github_account_login: optional string or null`
+
+ Login of the GitHub organization or user account the App is installed on
+
+ - `github_account_type: optional string or null`
+
+ Whether that GitHub account is an organization or a user account, as reported by GitHub ("Organization" or "User")
+
+ - `organization_id: optional string or null`
+
+ Organization ID this activity is associated with
+
+ - `organization_uuid: optional string or null`
+
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+
+ - `GitHubAppInstallationUnlinked object`
+
+ An installation of the Claude GitHub App was unlinked from the organization, so the organization's Claude Code features can no longer act on that GitHub account's repositories through it.
+
+ - `type: optional "github_app_installation_unlinked"`
+
+ default: github_app_installation_unlinked
+
+ - `actor: APIActor or UserActor or UnauthenticatedUserActor or 8 more`
+
+ - `APIActor object`
+
+ - `type: optional "api_actor"`
+
+ default: api_actor
+
+ - `api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `UserActor object`
+
+ - `type: optional "user_actor"`
+
+ default: user_actor
+
+ - `email_address: string`
+
+ format: email
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `user_id: string`
+
+ - `UnauthenticatedUserActor object`
+
+ - `type: optional "unauthenticated_user_actor"`
+
+ default: unauthenticated_user_actor
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `unauthenticated_email_address: optional string or null`
+
+ format: email
+
+ - `AnthropicActor object`
+
+ - `type: optional "anthropic_actor"`
+
+ default: anthropic_actor
+
+ - `email_address: optional string or null`
+
+ format: email
+
+ - `SystemActor object`
+
+ Automated background processing performed by Anthropic systems, acting
+ without a user or customer credential.
+
+ - `type: optional "system_actor"`
+
+ default: system_actor
+
+ - `service: optional string or null`
+
+ Name of the automated process that performed the action, when known.
+
+ - `AdminAPIKeyActor object`
+
+ - `type: optional "admin_api_key_actor"`
+
+ default: admin_api_key_actor
+
+ - `admin_api_key_id: string`
+
+ - `ip_address: string`
+
+ - `user_agent: string`
+
+ - `ServiceAccountActor object`
+
+ - `type: optional "service_account_actor"`
+
+ default: service_account_actor
+
+ - `ip_address: string`
+
+ - `service_account_id: string`
+
+ - `user_agent: string`
+
+ - `ScimDirectorySyncActor object`
+
+ - `type: optional "scim_directory_sync_actor"`
+
+ default: scim_directory_sync_actor
+
+ - `directory_id: string`
+
+ - `workos_event_id: string`
+
+ - `idp_connection_type: optional string or null`
+
+ - `FederatedIdentityActor object`
+
+ A federated external workload authenticated via a verified OIDC token.
+
+ Carries the verified issuer, subject, and audience claims from the
+ presented JWT.
+
+ - `type: optional "federated_identity_actor"`
+
+ default: federated_identity_actor
+
+ - `issuer: string`
+
+ - `subject: string`
+
+ - `audience: optional array of string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `FederatedActor object`
+
+ An external identity asserted by a trusted provider — a cloud-provider
+ gateway or a customer-registered federation issuer — acting without an
+ Anthropic-provisioned account or service account.
+
+ - `type: optional "federated_actor"`
+
+ default: federated_actor
+
+ - `provider: FederatedActorAwsProvider or FederatedActorAzureProvider or FederatedActorGcpProvider or FederatedActorOidcProvider`
+
+ - `FederatedActorAwsProvider object`
+
+ Asserting party: the AWS account the organization is bound to.
+
+ - `type: optional "aws"`
+
+ default: aws
+
+ - `account_id: string`
+
+ - `signed_principal: string`
+
+ The AWS-signed ARN of the IAM principal that requested the token.
+
+ - `FederatedActorAzureProvider object`
+
+ Asserting party: the Azure subscription the organization is bound to.
+
+ - `type: optional "azure"`
+
+ default: azure
+
+ - `subscription_id: string`
+
+ - `FederatedActorGcpProvider object`
+
+ Asserting party: the GCP project the organization is bound to.
+
+ - `type: optional "gcp"`
+
+ default: gcp
+
+ - `project_number: string`
+
+ - `FederatedActorOidcProvider object`
+
+ Asserting party: a customer-registered OIDC federation issuer.
+
+ - `type: optional "oidc"`
+
+ default: oidc
+
+ - `issuer: optional string or null`
+
+ The federation issuer's URL. Null when the presented credential failed verification.
+
+ - `ip_address: optional string or null`
+
+ - `subject: optional string or null`
+
+ The provider's verified identifier for the caller; its form depends on the provider.
+
+ - `user_agent: optional string or null`
+
+ - `AttestedDeviceActor object`
+
+ An attested mobile device authenticated via Apple App Attest.
+
+ - `type: optional "attested_device_actor"`
+
+ default: attested_device_actor
+
+ - `external_client_id: string`
+
+ - `kid_hash: string`
+
+ - `ip_address: optional string or null`
+
+ - `user_agent: optional string or null`
+
+ - `github_installation_id: number`
+
+ Numeric GitHub ID of the installation that was unlinked
+
+ - `id: optional string`
+
+ Unique identifier for the activity e.g. 'activity_abcd1234'
+
+ - `created_at: optional string`
+
+ When this activity occurred.
+
+ format: date-time
+
+ - `github_account_login: optional string or null`
+
+ Login of the GitHub organization or user account the App is installed on
+
+ - `github_account_type: optional string or null`
+
+ Whether that GitHub account is an organization or a user account, as reported by GitHub ("Organization" or "User")
+
+ - `organization_id: optional string or null`
+
+ Organization ID this activity is associated with
+
+ - `organization_uuid: optional string or null`
+
+ Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+
- `GitHubTokenImport object`
A user attempted to import a personal GitHub access token for use with Claude Code. The `result` field indicates the outcome of the import (imported, rejected, or failed).
@@ -80317,7 +80821,7 @@ compliance activities that can be filtered by various criteria.
- `ClaudeCodeWebEnabled object`
- The Claude Code on the web setting was changed for the organization.
+ The Claude Code cloud sessions setting was changed for the organization.
- `type: optional "claude_code_web_enabled"`
@@ -125046,6 +125550,10 @@ compliance activities that can be filtered by various criteria.
Organization UUID where the activity occurred. Null when the activity is not tied to an organization (for example, login and logout events or calls to the Compliance API).
+ - `tunnel_token_id: optional string or null`
+
+ Id of the tunnel token issued with the tunnel and returned once in the create response; set only when creating the tunnel also issued its token, and absent for a tunnel whose token is revealed separately
+
- `TunnelTokenMinted object`
An OAuth bearer token for the tunnel management API was minted.
diff --git a/content/en/api/csharp/beta.md b/content/en/api/csharp/beta.md
index 4c01add4e1..1d47a42e33 100644
--- a/content/en/api/csharp/beta.md
+++ b/content/en/api/csharp/beta.md
@@ -2181,7 +2181,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -2223,7 +2223,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
@@ -7963,7 +7963,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -8005,7 +8005,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
@@ -11633,7 +11633,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -11675,7 +11675,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
diff --git a/content/en/api/csharp/beta/messages.md b/content/en/api/csharp/beta/messages.md
index 570faf35a5..5f4d904593 100644
--- a/content/en/api/csharp/beta/messages.md
+++ b/content/en/api/csharp/beta/messages.md
@@ -1214,7 +1214,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -1256,7 +1256,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
@@ -6996,7 +6996,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -7038,7 +7038,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
@@ -15947,7 +15947,7 @@ Console.WriteLine(betaMessageTokensCount);
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -15989,7 +15989,7 @@ Console.WriteLine(betaMessageTokensCount);
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
@@ -21984,7 +21984,7 @@ Console.WriteLine(betaMessageTokensCount);
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -22026,7 +22026,7 @@ Console.WriteLine(betaMessageTokensCount);
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
@@ -28322,7 +28322,7 @@ Console.WriteLine(betaMessageTokensCount);
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -28389,7 +28389,7 @@ Console.WriteLine(betaMessageTokensCount);
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -30235,7 +30235,7 @@ Console.WriteLine(betaMessageTokensCount);
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -37790,7 +37790,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -37832,7 +37832,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
diff --git a/content/en/api/csharp/beta/messages/batches.md b/content/en/api/csharp/beta/messages/batches.md
index 3f16961699..e93f952660 100644
--- a/content/en/api/csharp/beta/messages/batches.md
+++ b/content/en/api/csharp/beta/messages/batches.md
@@ -1234,7 +1234,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -1276,7 +1276,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
diff --git a/content/en/api/csharp/beta/messages/batches/create.md b/content/en/api/csharp/beta/messages/batches/create.md
index 57d17baf1a..0aca5b01d4 100644
--- a/content/en/api/csharp/beta/messages/batches/create.md
+++ b/content/en/api/csharp/beta/messages/batches/create.md
@@ -1232,7 +1232,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -1274,7 +1274,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
diff --git a/content/en/api/csharp/beta/messages/count_tokens.md b/content/en/api/csharp/beta/messages/count_tokens.md
index 1b9eb463f8..aa5ee86f18 100644
--- a/content/en/api/csharp/beta/messages/count_tokens.md
+++ b/content/en/api/csharp/beta/messages/count_tokens.md
@@ -1200,7 +1200,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -1242,7 +1242,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
diff --git a/content/en/api/csharp/beta/messages/create.md b/content/en/api/csharp/beta/messages/create.md
index 38706801bb..283218ed63 100644
--- a/content/en/api/csharp/beta/messages/create.md
+++ b/content/en/api/csharp/beta/messages/create.md
@@ -1212,7 +1212,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonElement Type = "mcp_tool_reference"`
@@ -1254,7 +1254,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
diff --git a/content/en/api/go/beta.md b/content/en/api/go/beta.md
index a25ca5cb77..14902927ee 100644
--- a/content/en/api/go/beta.md
+++ b/content/en/api/go/beta.md
@@ -2429,7 +2429,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -2471,7 +2471,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type BetaToolChangeMCPToolsetReference`
@@ -8374,7 +8374,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -8416,7 +8416,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type BetaToolChangeMCPToolsetReference`
@@ -12064,7 +12064,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -12106,7 +12106,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/go/beta/messages.md b/content/en/api/go/beta/messages.md
index e6eb536c26..c76495d893 100644
--- a/content/en/api/go/beta/messages.md
+++ b/content/en/api/go/beta/messages.md
@@ -1210,7 +1210,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -1252,7 +1252,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type BetaToolChangeMCPToolsetReference`
@@ -7155,7 +7155,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -7197,7 +7197,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type BetaToolChangeMCPToolsetReference`
@@ -16360,7 +16360,7 @@ func main() {
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -16402,7 +16402,7 @@ func main() {
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type BetaToolChangeMCPToolsetReference`
@@ -22998,7 +22998,7 @@ func main() {
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -23040,7 +23040,7 @@ func main() {
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type BetaToolChangeMCPToolsetReference`
@@ -29829,7 +29829,7 @@ func main() {
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -29896,7 +29896,7 @@ func main() {
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -31796,7 +31796,7 @@ func main() {
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -39423,7 +39423,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -39465,7 +39465,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/go/beta/messages/batches.md b/content/en/api/go/beta/messages/batches.md
index f2ecb49f19..46d6eec349 100644
--- a/content/en/api/go/beta/messages/batches.md
+++ b/content/en/api/go/beta/messages/batches.md
@@ -1230,7 +1230,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -1272,7 +1272,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/go/beta/messages/batches/create.md b/content/en/api/go/beta/messages/batches/create.md
index e452894890..12572d8f83 100644
--- a/content/en/api/go/beta/messages/batches/create.md
+++ b/content/en/api/go/beta/messages/batches/create.md
@@ -1228,7 +1228,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -1270,7 +1270,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/go/beta/messages/count_tokens.md b/content/en/api/go/beta/messages/count_tokens.md
index 0eae3cb5fc..2219e93b6e 100644
--- a/content/en/api/go/beta/messages/count_tokens.md
+++ b/content/en/api/go/beta/messages/count_tokens.md
@@ -1196,7 +1196,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -1238,7 +1238,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/go/beta/messages/create.md b/content/en/api/go/beta/messages/create.md
index 49cbe44109..3090fa708a 100644
--- a/content/en/api/go/beta/messages/create.md
+++ b/content/en/api/go/beta/messages/create.md
@@ -1208,7 +1208,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `Type MCPToolReference`
@@ -1250,7 +1250,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `type BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/java/beta.md b/content/en/api/java/beta.md
index a90f46e021..4e74dd934d 100644
--- a/content/en/api/java/beta.md
+++ b/content/en/api/java/beta.md
@@ -2391,7 +2391,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -2433,7 +2433,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
@@ -8172,7 +8172,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -8214,7 +8214,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
@@ -11841,7 +11841,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -11883,7 +11883,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
diff --git a/content/en/api/java/beta/messages.md b/content/en/api/java/beta/messages.md
index f47e5a9c1c..bdc9907daf 100644
--- a/content/en/api/java/beta/messages.md
+++ b/content/en/api/java/beta/messages.md
@@ -1316,7 +1316,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -1358,7 +1358,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
@@ -7097,7 +7097,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -7139,7 +7139,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
@@ -15945,7 +15945,7 @@ public final class Main {
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -15987,7 +15987,7 @@ public final class Main {
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
@@ -21982,7 +21982,7 @@ public final class Main {
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -22024,7 +22024,7 @@ public final class Main {
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
@@ -28320,7 +28320,7 @@ public final class Main {
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -28387,7 +28387,7 @@ public final class Main {
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -30233,7 +30233,7 @@ public final class Main {
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -37890,7 +37890,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -37932,7 +37932,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
diff --git a/content/en/api/java/beta/messages/batches.md b/content/en/api/java/beta/messages/batches.md
index 2b9e3345f0..cce8162c62 100644
--- a/content/en/api/java/beta/messages/batches.md
+++ b/content/en/api/java/beta/messages/batches.md
@@ -1336,7 +1336,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -1378,7 +1378,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
diff --git a/content/en/api/java/beta/messages/batches/create.md b/content/en/api/java/beta/messages/batches/create.md
index 82ed70aaf6..02dd1d79a8 100644
--- a/content/en/api/java/beta/messages/batches/create.md
+++ b/content/en/api/java/beta/messages/batches/create.md
@@ -1334,7 +1334,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -1376,7 +1376,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
diff --git a/content/en/api/java/beta/messages/count_tokens.md b/content/en/api/java/beta/messages/count_tokens.md
index 201a5588b0..0828b88980 100644
--- a/content/en/api/java/beta/messages/count_tokens.md
+++ b/content/en/api/java/beta/messages/count_tokens.md
@@ -1302,7 +1302,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -1344,7 +1344,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
diff --git a/content/en/api/java/beta/messages/create.md b/content/en/api/java/beta/messages/create.md
index efd4ba9925..23a3f0520e 100644
--- a/content/en/api/java/beta/messages/create.md
+++ b/content/en/api/java/beta/messages/create.md
@@ -1314,7 +1314,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `JsonValue type = "mcp_tool_reference"`
@@ -1356,7 +1356,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMcpToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMcpToolsetReference`
diff --git a/content/en/api/python/beta.md b/content/en/api/python/beta.md
index b368921e80..37406b960f 100644
--- a/content/en/api/python/beta.md
+++ b/content/en/api/python/beta.md
@@ -2398,7 +2398,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -2440,7 +2440,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
@@ -8651,7 +8651,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -8693,7 +8693,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
@@ -12603,7 +12603,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -12645,7 +12645,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/python/beta/messages.md b/content/en/api/python/beta/messages.md
index 5f9e2fd881..c3c6fcda66 100644
--- a/content/en/api/python/beta/messages.md
+++ b/content/en/api/python/beta/messages.md
@@ -1212,7 +1212,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -1254,7 +1254,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
@@ -7465,7 +7465,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -7507,7 +7507,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
@@ -16992,7 +16992,7 @@ print(beta_message_tokens_count.context_management)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -17034,7 +17034,7 @@ print(beta_message_tokens_count.context_management)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
@@ -23874,7 +23874,7 @@ print(beta_message_tokens_count.context_management)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -23916,7 +23916,7 @@ print(beta_message_tokens_count.context_management)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
@@ -30837,7 +30837,7 @@ print(beta_message_tokens_count.context_management)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -30904,7 +30904,7 @@ print(beta_message_tokens_count.context_management)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -32804,7 +32804,7 @@ print(beta_message_tokens_count.context_management)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -40471,7 +40471,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -40513,7 +40513,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/python/beta/messages/batches.md b/content/en/api/python/beta/messages/batches.md
index 83244eb932..0d4d8a3cfc 100644
--- a/content/en/api/python/beta/messages/batches.md
+++ b/content/en/api/python/beta/messages/batches.md
@@ -1232,7 +1232,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -1274,7 +1274,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/python/beta/messages/batches/create.md b/content/en/api/python/beta/messages/batches/create.md
index e59b995195..1c5ef4425d 100644
--- a/content/en/api/python/beta/messages/batches/create.md
+++ b/content/en/api/python/beta/messages/batches/create.md
@@ -1230,7 +1230,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -1272,7 +1272,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/python/beta/messages/count_tokens.md b/content/en/api/python/beta/messages/count_tokens.md
index d844d159da..d3a0a7d11b 100644
--- a/content/en/api/python/beta/messages/count_tokens.md
+++ b/content/en/api/python/beta/messages/count_tokens.md
@@ -1198,7 +1198,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -1240,7 +1240,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/python/beta/messages/create.md b/content/en/api/python/beta/messages/create.md
index 79866d8b67..81edf1b652 100644
--- a/content/en/api/python/beta/messages/create.md
+++ b/content/en/api/python/beta/messages/create.md
@@ -1210,7 +1210,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: Literal["mcp_tool_reference"]`
@@ -1252,7 +1252,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/ruby/beta.md b/content/en/api/ruby/beta.md
index dcfc0ca710..a26e675906 100644
--- a/content/en/api/ruby/beta.md
+++ b/content/en/api/ruby/beta.md
@@ -2275,7 +2275,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -2317,7 +2317,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
@@ -8356,7 +8356,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -8398,7 +8398,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
@@ -12290,7 +12290,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -12332,7 +12332,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/ruby/beta/messages.md b/content/en/api/ruby/beta/messages.md
index 5607c5cefc..a5e684455d 100644
--- a/content/en/api/ruby/beta/messages.md
+++ b/content/en/api/ruby/beta/messages.md
@@ -1212,7 +1212,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -1254,7 +1254,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
@@ -7293,7 +7293,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -7335,7 +7335,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
@@ -16534,7 +16534,7 @@ puts(beta_message_tokens_count)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -16576,7 +16576,7 @@ puts(beta_message_tokens_count)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
@@ -22930,7 +22930,7 @@ puts(beta_message_tokens_count)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -22972,7 +22972,7 @@ puts(beta_message_tokens_count)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
@@ -29285,7 +29285,7 @@ puts(beta_message_tokens_count)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -29352,7 +29352,7 @@ puts(beta_message_tokens_count)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -31198,7 +31198,7 @@ puts(beta_message_tokens_count)
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -38767,7 +38767,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -38809,7 +38809,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/ruby/beta/messages/batches.md b/content/en/api/ruby/beta/messages/batches.md
index 41a4a8b2ab..1220914ca5 100644
--- a/content/en/api/ruby/beta/messages/batches.md
+++ b/content/en/api/ruby/beta/messages/batches.md
@@ -1232,7 +1232,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -1274,7 +1274,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/ruby/beta/messages/batches/create.md b/content/en/api/ruby/beta/messages/batches/create.md
index 6f2e4c82c0..0c3dd79436 100644
--- a/content/en/api/ruby/beta/messages/batches/create.md
+++ b/content/en/api/ruby/beta/messages/batches/create.md
@@ -1230,7 +1230,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -1272,7 +1272,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/ruby/beta/messages/count_tokens.md b/content/en/api/ruby/beta/messages/count_tokens.md
index 0e468ad232..bcc00eadc5 100644
--- a/content/en/api/ruby/beta/messages/count_tokens.md
+++ b/content/en/api/ruby/beta/messages/count_tokens.md
@@ -1198,7 +1198,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -1240,7 +1240,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/ruby/beta/messages/create.md b/content/en/api/ruby/beta/messages/create.md
index f0a3981393..3edfa0f8c1 100644
--- a/content/en/api/ruby/beta/messages/create.md
+++ b/content/en/api/ruby/beta/messages/create.md
@@ -1210,7 +1210,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: :mcp_tool_reference`
@@ -1252,7 +1252,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `class BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `class BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/skills.md b/content/en/api/skills.md
index 34f97e488a..f924186c6e 100644
--- a/content/en/api/skills.md
+++ b/content/en/api/skills.md
@@ -106,7 +106,7 @@ curl https://api.anthropic.com/v1/skills \
-H 'Content-Type: multipart/form-data' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
- -F files='["Example data"]'
+ -F 'files[]=@/path/to/file'
```
#### Response (200)
@@ -623,7 +623,7 @@ curl https://api.anthropic.com/v1/skills/$SKILL_ID/versions \
-H 'Content-Type: multipart/form-data' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
- -F files='["Example data"]'
+ -F 'files[]=@/path/to/file'
```
##### Response (200)
diff --git a/content/en/api/skills/create.md b/content/en/api/skills/create.md
index e67e7843b7..2d8f8eaaa4 100644
--- a/content/en/api/skills/create.md
+++ b/content/en/api/skills/create.md
@@ -104,7 +104,7 @@ curl https://api.anthropic.com/v1/skills \
-H 'Content-Type: multipart/form-data' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
- -F files='["Example data"]'
+ -F 'files[]=@/path/to/file'
```
### Response (200)
diff --git a/content/en/api/skills/versions.md b/content/en/api/skills/versions.md
index 65203139ca..3881895494 100644
--- a/content/en/api/skills/versions.md
+++ b/content/en/api/skills/versions.md
@@ -80,7 +80,7 @@ curl https://api.anthropic.com/v1/skills/$SKILL_ID/versions \
-H 'Content-Type: multipart/form-data' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
- -F files='["Example data"]'
+ -F 'files[]=@/path/to/file'
```
#### Response (200)
diff --git a/content/en/api/skills/versions/create.md b/content/en/api/skills/versions/create.md
index fd9c598b70..0bbcd24843 100644
--- a/content/en/api/skills/versions/create.md
+++ b/content/en/api/skills/versions/create.md
@@ -78,7 +78,7 @@ curl https://api.anthropic.com/v1/skills/$SKILL_ID/versions \
-H 'Content-Type: multipart/form-data' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
- -F files='["Example data"]'
+ -F 'files[]=@/path/to/file'
```
### Response (200)
diff --git a/content/en/api/typescript/beta.md b/content/en/api/typescript/beta.md
index 7a20cee472..ba940ad7e4 100644
--- a/content/en/api/typescript/beta.md
+++ b/content/en/api/typescript/beta.md
@@ -2410,7 +2410,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -2452,7 +2452,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `interface BetaToolChangeMCPToolsetReference`
@@ -8683,7 +8683,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -8725,7 +8725,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `interface BetaToolChangeMCPToolsetReference`
@@ -12623,7 +12623,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -12665,7 +12665,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `interface BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/typescript/beta/messages.md b/content/en/api/typescript/beta/messages.md
index ec6d65e7e0..666998940a 100644
--- a/content/en/api/typescript/beta/messages.md
+++ b/content/en/api/typescript/beta/messages.md
@@ -1216,7 +1216,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -1258,7 +1258,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `interface BetaToolChangeMCPToolsetReference`
@@ -7489,7 +7489,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -7531,7 +7531,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `interface BetaToolChangeMCPToolsetReference`
@@ -16938,7 +16938,7 @@ console.log(betaMessageTokensCount.context_management);
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -16980,7 +16980,7 @@ console.log(betaMessageTokensCount.context_management);
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `interface BetaToolChangeMCPToolsetReference`
@@ -23560,7 +23560,7 @@ console.log(betaMessageTokensCount.context_management);
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -23602,7 +23602,7 @@ console.log(betaMessageTokensCount.context_management);
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `interface BetaToolChangeMCPToolsetReference`
@@ -30413,7 +30413,7 @@ console.log(betaMessageTokensCount.context_management);
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -30480,7 +30480,7 @@ console.log(betaMessageTokensCount.context_management);
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -32380,7 +32380,7 @@ console.log(betaMessageTokensCount.context_management);
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -40005,7 +40005,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -40047,7 +40047,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `interface BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/typescript/beta/messages/batches.md b/content/en/api/typescript/beta/messages/batches.md
index 0d694a7e86..8de480c90c 100644
--- a/content/en/api/typescript/beta/messages/batches.md
+++ b/content/en/api/typescript/beta/messages/batches.md
@@ -1234,7 +1234,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -1276,7 +1276,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `interface BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/typescript/beta/messages/batches/create.md b/content/en/api/typescript/beta/messages/batches/create.md
index 4e3b22dd38..43e0cb4dbb 100644
--- a/content/en/api/typescript/beta/messages/batches/create.md
+++ b/content/en/api/typescript/beta/messages/batches/create.md
@@ -1232,7 +1232,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -1274,7 +1274,7 @@ Learn more about the Message Batches API in our [user guide](https://platform.cl
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `interface BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/typescript/beta/messages/count_tokens.md b/content/en/api/typescript/beta/messages/count_tokens.md
index bbd2aebb3a..eafc4ee995 100644
--- a/content/en/api/typescript/beta/messages/count_tokens.md
+++ b/content/en/api/typescript/beta/messages/count_tokens.md
@@ -1200,7 +1200,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -1242,7 +1242,7 @@ Learn more about token counting in our [user guide](https://platform.claude.com/
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `interface BetaToolChangeMCPToolsetReference`
diff --git a/content/en/api/typescript/beta/messages/create.md b/content/en/api/typescript/beta/messages/create.md
index 2d675f5f96..a7c4844595 100644
--- a/content/en/api/typescript/beta/messages/create.md
+++ b/content/en/api/typescript/beta/messages/create.md
@@ -1214,7 +1214,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `type: "mcp_tool_reference"`
@@ -1256,7 +1256,7 @@ Learn more about the Messages API in our [user guide](https://platform.claude.co
- `interface BetaToolChangeMCPToolReference`
- Reference to a single MCP tool by its server and remote name — the
+ Reference to a single MCP tool by its server and remote name; the
same `server_name`/`name` pair `mcp_tool_use` carries.
- `interface BetaToolChangeMCPToolsetReference`
diff --git a/content/en/build-with-claude/claude-in-microsoft-foundry.md b/content/en/build-with-claude/claude-in-microsoft-foundry.md
index db289cb8e6..c0652b3ffb 100644
--- a/content/en/build-with-claude/claude-in-microsoft-foundry.md
+++ b/content/en/build-with-claude/claude-in-microsoft-foundry.md
@@ -676,18 +676,18 @@ Lifecycle terms (Deprecated, Retired) are defined in [Model deprecations](https:
The following Claude models are available through Foundry:
| Model | Default deployment name | Hosted on Azure | Hosted on Anthropic |
-| ----------------- | ----------------------- | --------------- | ------------------- |
-| Claude Fable 5.1 | claude-fable-5-1 | | ✓ |
-| Claude Fable 5 | claude-fable-5 | | ✓ |
-| Claude Opus 5 | claude-opus-5 | ✓ | ✓ |
-| Claude Opus 4.8 | claude-opus-4-8 | ✓ | ✓ |
-| Claude Opus 4.7 | claude-opus-4-7 | | ✓ |
-| Claude Opus 4.6 | claude-opus-4-6 | | ✓ |
-| Claude Opus 4.5 | claude-opus-4-5 | | ✓ |
-| Claude Sonnet 5 | claude-sonnet-5 | ✓ | ✓ |
-| Claude Sonnet 4.6 | claude-sonnet-4-6 | | ✓ |
-| Claude Sonnet 4.5 | claude-sonnet-4-5 | | ✓ |
-| Claude Haiku 4.5 | claude-haiku-4-5 | ✓ | ✓ |
+| :---------------- | :---------------------- | :-------------: | :-----------------: |
+| Claude Fable 5.1 | `claude-fable-5-1` | | ✓ |
+| Claude Fable 5 | `claude-fable-5` | | ✓ |
+| Claude Opus 5 | `claude-opus-5` | ✓ | ✓ |
+| Claude Opus 4.8 | `claude-opus-4-8` | ✓ | ✓ |
+| Claude Opus 4.7 | `claude-opus-4-7` | | ✓ |
+| Claude Opus 4.6 | `claude-opus-4-6` | | ✓ |
+| Claude Opus 4.5 | `claude-opus-4-5` | | ✓ |
+| Claude Sonnet 5 | `claude-sonnet-5` | ✓ | ✓ |
+| Claude Sonnet 4.6 | `claude-sonnet-4-6` | | ✓ |
+| Claude Sonnet 4.5 | `claude-sonnet-4-5` | | ✓ |
+| Claude Haiku 4.5 | `claude-haiku-4-5` | ✓ | ✓ |
By default, deployment names match the model IDs shown in the preceding table. However, you can create custom deployments with different names in the Foundry portal to manage different configurations, versions, or rate limits. Use the deployment name (not necessarily the model ID) in your API requests.
diff --git a/content/en/build-with-claude/claude-on-vertex-ai.md b/content/en/build-with-claude/claude-on-vertex-ai.md
index 3315823b7b..9b9c3abd79 100644
--- a/content/en/build-with-claude/claude-on-vertex-ai.md
+++ b/content/en/build-with-claude/claude-on-vertex-ai.md
@@ -115,24 +115,23 @@ Note that Anthropic model availability varies by region. Search for "Claude" in
Lifecycle terms (Deprecated, Retired) are defined in [Model deprecations](https://platform.claude.com/docs/en/about-claude/model-deprecations). Lifecycle dates on partner-operated platforms are set by the partner and can differ from the Claude API schedule. For the current retirement date of any model on Agent Platform, see [Google Cloud's documentation for Claude models on Agent Platform](https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/partner-models/claude).
-| Model | Agent Platform API model ID |
-| ---------------------------- | --------------------------- |
-| Claude Fable 5.1 | claude-fable-5-1 |
-| Claude Fable 5 | claude-fable-5 |
-| Claude Opus 5 | claude-opus-5 |
-| Claude Opus 4.8 | claude-opus-4-8 |
-| Claude Opus 4.7 | claude-opus-4-7 |
-| Claude Opus 4.6 | claude-opus-4-6 |
-| Claude Sonnet 5 | `claude-sonnet-5` |
-| Claude Sonnet 4.6 | claude-sonnet-4-6 |
-| Claude Sonnet 4.5 | claude-sonnet-4-5\@20250929 |
-| Claude Sonnet 4 Deprecated. | claude-sonnet-4\@20250514 |
-| Claude Sonnet 3.7 Retired. | claude-3-7-sonnet\@20250219 |
-| Claude Opus 4.5 | claude-opus-4-5\@20251101 |
-| Claude Opus 4.1 Deprecated. | claude-opus-4-1\@20250805 |
-| Claude Opus 4 Deprecated. | claude-opus-4\@20250514 |
-| Claude Haiku 4.5 | claude-haiku-4-5\@20251001 |
-| Claude Haiku 3.5 Deprecated. | claude-3-5-haiku\@20241022 |
+| Model | Agent Platform API model ID |
+| :--------------------------------------------------------------------------------------------------- | :--------------------------- |
+| Claude Fable 5.1 | `claude-fable-5-1` |
+| Claude Fable 5 | `claude-fable-5` |
+| Claude Opus 5 | `claude-opus-5` |
+| Claude Opus 4.8 | `claude-opus-4-8` |
+| Claude Opus 4.7 | `claude-opus-4-7` |
+| Claude Opus 4.6 | `claude-opus-4-6` |
+| Claude Opus 4.5 | `claude-opus-4-5@20251101` |
+| Claude Opus 4.1 ([deprecated](https://platform.claude.com/docs/en/about-claude/model-deprecations)) | `claude-opus-4-1@20250805` |
+| Claude Opus 4 ([deprecated](https://platform.claude.com/docs/en/about-claude/model-deprecations)) | `claude-opus-4@20250514` |
+| Claude Sonnet 5 | `claude-sonnet-5` |
+| Claude Sonnet 4.6 | `claude-sonnet-4-6` |
+| Claude Sonnet 4.5 | `claude-sonnet-4-5@20250929` |
+| Claude Sonnet 4 ([deprecated](https://platform.claude.com/docs/en/about-claude/model-deprecations)) | `claude-sonnet-4@20250514` |
+| Claude Haiku 4.5 | `claude-haiku-4-5@20251001` |
+| Claude Haiku 3.5 ([deprecated](https://platform.claude.com/docs/en/about-claude/model-deprecations)) | `claude-3-5-haiku@20241022` |
Upgrading to a newer Claude model? In Claude Code, run `/claude-api migrate` to apply model ID swaps and breaking parameter changes across your codebase. The skill detects which cloud platform your code targets and adjusts model ID formats and feature changes for that platform. See [Migrating to a newer Claude model](https://platform.claude.com/docs/en/agents-and-tools/agent-skills/claude-api-skill#migrating-to-a-newer-claude-model).
diff --git a/content/en/build-with-claude/claude-platform-on-aws.md b/content/en/build-with-claude/claude-platform-on-aws.md
index a926d63690..ce989f41f8 100644
--- a/content/en/build-with-claude/claude-platform-on-aws.md
+++ b/content/en/build-with-claude/claude-platform-on-aws.md
@@ -344,19 +344,19 @@ Anthropic's [client SDKs](https://platform.claude.com/docs/en/cli-sdks-libraries
The following models are available on Claude Platform on AWS:
-| Model | Model ID |
-| :---------------- | :---------------- |
-| Claude Fable 5.1 | claude-fable-5-1 |
-| Claude Fable 5 | claude-fable-5 |
-| Claude Opus 5 | claude-opus-5 |
-| Claude Opus 4.8 | claude-opus-4-8 |
-| Claude Opus 4.7 | claude-opus-4-7 |
-| Claude Opus 4.6 | claude-opus-4-6 |
-| Claude Opus 4.5 | claude-opus-4-5 |
-| Claude Sonnet 5 | claude-sonnet-5 |
-| Claude Sonnet 4.6 | claude-sonnet-4-6 |
-| Claude Sonnet 4.5 | claude-sonnet-4-5 |
-| Claude Haiku 4.5 | claude-haiku-4-5 |
+| Model | Model ID |
+| :---------------- | :------------------ |
+| Claude Fable 5.1 | `claude-fable-5-1` |
+| Claude Fable 5 | `claude-fable-5` |
+| Claude Opus 5 | `claude-opus-5` |
+| Claude Opus 4.8 | `claude-opus-4-8` |
+| Claude Opus 4.7 | `claude-opus-4-7` |
+| Claude Opus 4.6 | `claude-opus-4-6` |
+| Claude Opus 4.5 | `claude-opus-4-5` |
+| Claude Sonnet 5 | `claude-sonnet-5` |
+| Claude Sonnet 4.6 | `claude-sonnet-4-6` |
+| Claude Sonnet 4.5 | `claude-sonnet-4-5` |
+| Claude Haiku 4.5 | `claude-haiku-4-5` |
Model IDs are identical to the first-party Claude API. There are no Bedrock-style ARNs or `anthropic.` prefixes.
diff --git a/content/en/build-with-claude/extended-thinking.md b/content/en/build-with-claude/extended-thinking.md
index 141b7da919..81108dcc94 100644
--- a/content/en/build-with-claude/extended-thinking.md
+++ b/content/en/build-with-claude/extended-thinking.md
@@ -54,7 +54,7 @@ Here is an example of using extended thinking in the Messages API:
```bash CLI
ant messages create \
- --transform content --format yaml <<'YAML'
+ --format yaml <<'YAML'
model: claude-sonnet-4-6
max_tokens: 16000
thinking:
diff --git a/content/en/build-with-claude/preserved-thinking.md b/content/en/build-with-claude/preserved-thinking.md
index 6621d758cd..99fe250716 100644
--- a/content/en/build-with-claude/preserved-thinking.md
+++ b/content/en/build-with-claude/preserved-thinking.md
@@ -140,7 +140,6 @@ The following request opts into dropping rather than rejecting. On a first turn
```bash CLI
ant beta:messages create --beta thinking-binding-controls-2026-08-01 \
- --transform '{content.#(type=="text")#.text,input_transformations}' \
--format yaml <<'YAML'
model: claude-fable-5-1
max_tokens: 16000
diff --git a/content/en/build-with-claude/refusals-and-fallback.md b/content/en/build-with-claude/refusals-and-fallback.md
index 0df5844893..0042f68470 100644
--- a/content/en/build-with-claude/refusals-and-fallback.md
+++ b/content/en/build-with-claude/refusals-and-fallback.md
@@ -29,7 +29,7 @@ The simplest setup, in beta on the Claude API: set `fallbacks` to `"default"`, a
"max_tokens": 1024,
"fallbacks": "default",
"messages": [{"role": "user", "content": "Hello, Claude"}]
- }' | jq -r '.model'
+ }'
```
```bash CLI
@@ -38,8 +38,7 @@ The simplest setup, in beta on the Claude API: set `fallbacks` to `"default"`, a
--max-tokens 1024 \
--message '{"role":"user","content":"Hello, Claude"}' \
--fallbacks default \
- --beta server-side-fallback-2026-07-01 \
- --transform model --raw-output
+ --beta server-side-fallback-2026-07-01
```
```python Python
@@ -504,7 +503,7 @@ The highlighted lines are the only difference from the default-routing request.
"max_tokens": 1024,
"fallbacks": [{"model": "claude-opus-4-8"}],
"messages": [{"role": "user", "content": "Hello, Claude"}]
- }' | jq -r '.model'
+ }'
```
```bash CLI
@@ -513,8 +512,7 @@ The highlighted lines are the only difference from the default-routing request.
--max-tokens 1024 \
--message '{"role":"user","content":"Hello, Claude"}' \
--fallbacks '[{"model":"claude-opus-4-8"}]' \
- --beta server-side-fallback-2026-07-01 \
- --transform model --raw-output
+ --beta server-side-fallback-2026-07-01
```
```python Python
diff --git a/content/en/build-with-claude/skills-guide.md b/content/en/build-with-claude/skills-guide.md
index a528d54923..f208e955c4 100644
--- a/content/en/build-with-claude/skills-guide.md
+++ b/content/en/build-with-claude/skills-guide.md
@@ -2166,7 +2166,7 @@ Upload your custom Skill to make it available in your workspace. You can upload
Files are identified by the filename you attach (the `;filename=` suffix in the cURL example and the filename arguments in the SDK examples). For the walkthrough's skill, create a zip with `zip -r financial_skill.zip financial_skill/` and substitute it for the `example_skill.zip` placeholder in the zip-upload options.
-
+
```bash cURL
curl -X POST "https://api.anthropic.com/v1/skills" \
-H "x-api-key: $ANTHROPIC_API_KEY" \
@@ -2471,7 +2471,7 @@ For complete request/response schemas, see the [Create Skill API reference](http
Retrieve all Skills available to your workspace, including both Anthropic pre-built Skills and your custom Skills. Use the `source` parameter to filter by skill type:
-
+
```bash cURL
# List all Skills
curl "https://api.anthropic.com/v1/skills" \
@@ -2617,7 +2617,7 @@ See the [List Skills API reference](https://platform.claude.com/docs/en/api/skil
Get details about a specific Skill:
-
+
```bash cURL
curl "https://api.anthropic.com/v1/skills/skill_01AbCdEfGhIjKlMnOpQrStUv" \
-H "x-api-key: $ANTHROPIC_API_KEY" \
@@ -2714,7 +2714,7 @@ Get details about a specific Skill:
Deleting a Skill also removes all of its versions.
-
+
```bash cURL
curl -X DELETE "https://api.anthropic.com/v1/skills/skill_01AbCdEfGhIjKlMnOpQrStUv" \
-H "x-api-key: $ANTHROPIC_API_KEY" \
@@ -2795,7 +2795,7 @@ Skills support versioning to manage updates safely:
A new version is a complete snapshot, not a delta: upload the Skill's full file set each time. Files you omit are not carried over, and the `name` in the new version's `SKILL.md` must match the Skill's existing name. The following examples re-upload the complete `financial_skill/` bundle from [Creating a Skill](https://platform.claude.com/docs/en/build-with-claude/skills-guide#creating-a-skill).
-
+
```bash cURL
# Create a new version
NEW_VERSION=$(curl -X POST "https://api.anthropic.com/v1/skills/skill_01AbCdEfGhIjKlMnOpQrStUv/versions" \
diff --git a/content/en/build-with-claude/thinking.md b/content/en/build-with-claude/thinking.md
index 05b5c12253..f02d9dfdf2 100644
--- a/content/en/build-with-claude/thinking.md
+++ b/content/en/build-with-claude/thinking.md
@@ -1163,23 +1163,22 @@ You can't prefill the assistant response while thinking is on. Forced tool use (
Each model accepts `max_tokens` up to the ceiling listed here. On the [Message Batches API](https://platform.claude.com/docs/en/build-with-claude/batch-processing#extended-output-beta), the `output-300k-2026-03-24` [beta header](https://platform.claude.com/docs/en/api/beta-headers) raises that ceiling for the models with a batches ceiling listed.
-| Model | Max output tokens | Batches beta ceiling |
-| :---------------- | :---------------- | :------------------- |
-| Claude Fable 5.1 | 128K | — |
-| Claude Mythos 5.1 | 128K | — |
-| Claude Fable 5 | 128K | — |
-| Claude Mythos 5 | 128K | — |
-| Claude Opus 5 | 128K | 300K |
-| Claude Opus 4.8 | 128K | 300K |
-| Claude Opus 4.7 | 128K | 300K |
-| Claude Opus 4.6 | 128K | 300K |
-| Claude Opus 4.5 | 64K | Not available |
-| Claude Sonnet 5 | 128K | 300K |
-| Claude Sonnet 4.6 | 128K | 300K |
-| Claude Sonnet 4.5 | 64K | Not available |
-| Claude Haiku 4.5 | 64K | Not available |
-
-[Claude Mythos Preview](https://anthropic.com/glasswing) accepts `max_tokens` up to 128K; the Batches beta ceiling is not available for it.
+| Model | Max output tokens | Batches beta ceiling |
+| :-------------------- | :---------------- | :------------------- |
+| Claude Fable 5.1 | 128K | — |
+| Claude Mythos 5.1 | 128K | — |
+| Claude Fable 5 | 128K | — |
+| Claude Mythos 5 | 128K | — |
+| Claude Mythos Preview | 128K | Not available |
+| Claude Opus 5 | 128K | 300K |
+| Claude Opus 4.8 | 128K | 300K |
+| Claude Opus 4.7 | 128K | 300K |
+| Claude Opus 4.6 | 128K | 300K |
+| Claude Opus 4.5 | 64K | Not available |
+| Claude Sonnet 5 | 128K | 300K |
+| Claude Sonnet 4.6 | 128K | 300K |
+| Claude Sonnet 4.5 | 64K | Not available |
+| Claude Haiku 4.5 | 64K | Not available |
See the [models overview](https://platform.claude.com/docs/en/models/overview) for limits on legacy models.
diff --git a/content/en/docs/claude-code/artifacts.md b/content/en/docs/claude-code/artifacts.md
index 6ea8a7b160..e5ed747a8d 100644
--- a/content/en/docs/claude-code/artifacts.md
+++ b/content/en/docs/claude-code/artifacts.md
@@ -249,7 +249,7 @@ Turn this migration plan into a checklist artifact. Check items off as you compl
## Improve the visual design
-Claude applies a built-in design skill when it builds an artifact, so pages get a deliberate palette, typography, and layout without extra prompting. Requires Claude Code v2.1.182 or later. That skill also looks for an existing design system in your project before choosing its own. Design tokens are the named color, typography, and spacing values your design system reuses. To keep artifacts consistent with your product's branding, record them where Claude can find them, such as the project's [CLAUDE.md](/docs/en/memory) or a theme file in your repository:
+Claude applies a built-in design skill when it builds an artifact, so pages get a deliberate palette, typography, and layout without extra prompting. That skill also looks for an existing design system in your project before choosing its own. Design tokens are the named color, typography, and spacing values your design system reuses. To keep artifacts consistent with your product's branding, record them where Claude can find them, such as the project's [CLAUDE.md](/docs/en/memory) or a theme file in your repository:
```markdown theme={null}
## Design system
diff --git a/content/en/docs/claude-code/changelog.md b/content/en/docs/claude-code/changelog.md
index bcd481d262..e43e672e9f 100644
--- a/content/en/docs/claude-code/changelog.md
+++ b/content/en/docs/claude-code/changelog.md
@@ -10,6 +10,101 @@ This page is generated from the [CHANGELOG.md on GitHub](https://github.com/anth
Run `claude --version` to check your installed version.
+
+ * Changed auto mode for Claude API and Enterprise users, and on Bedrock, Vertex, Foundry and gateways, to default to the server-side classifier, which does not charge for classifier overhead (`CLAUDE_CODE_AUTO_MODE_SERVER=0` opts out on Bedrock, Vertex, Foundry and gateways); warns on billed fallback. See [https://code.claude.com/docs/en/auto-mode-classifier-billing](https://code.claude.com/docs/en/auto-mode-classifier-billing)
+ * Added an `Auto mode server` row to `/status` showing whether this session's auto mode classifier runs on the server
+
+
+
+ * Added AGENTS.md support: in a project with no CLAUDE.md, Claude Code reads AGENTS.md instead; change it under "Project instructions" in `/config` (not yet on Bedrock, Vertex or Foundry)
+ * Added `CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY=1` for Claude apps gateways whose only egress is a forward proxy: every outbound request hands the proxy the hostname instead of resolving it locally
+ * Added an optional `headers:` map on Claude apps gateway upstreams, to send static headers to a proxy you run in front of a provider
+ * Added a line saying a background task's update is waiting when it finishes while a panel such as `/tasks` is open
+ * Fixed `claude -p` and Agent SDK sessions that could hang with no result after an internal error; they now report the error and exit with code 1
+ * Fixed conversations failing every request with "text content blocks must be non-empty" when an earlier assistant turn held an empty text block beside other content, including after `--resume`
+ * Fixed being unexpectedly logged out when an older Claude Code build (for example an IDE extension's bundled CLI) runs on the same machine as the current one
+ * Fixed interactive start-up hanging or showing an error for `ANTHROPIC_API_KEY` users when `~/.claude.json` holds a malformed `customApiKeyResponses` value
+ * Fixed update checks erroring every 30 minutes, and `claude update` hanging when a minimum or maximum version is set, if a proxy returns an invalid version; a malformed `minimumVersion` is now ignored
+ * Fixed `claude update` on winget- or apk-managed installs reporting "up to date" when the version lookup failed
+ * Fixed `claude plugin install` sometimes failing and breaking the installed copy when reinstalling a plugin version that a session or another program was using; an unchanged copy is now left alone
+ * Fixed Grep and Glob reporting no matches when the search could not start because the system was out of processes, memory or file handles; they now return an error saying so
+ * Fixed the Write tool silently ending the turn as a declined permission when the target path is an existing directory; it now reports a clear error
+ * Fixed the Edit tool treating an escaped backslash followed by `uXXXX` text as a `\uXXXX` escape, which could make an edit of a non-ASCII character rewrite an escaped backslash sequence instead
+ * Fixed the Edit tool reporting "Invalid regular expression: regular expression too large" instead of "String not found in file" when a very large edit containing non-ASCII text did not match the file
+ * Fixed a turn ending early with "Path contains null bytes" when a tool call's file path contained `\u0000` written as an escape sequence; escaped control characters now stay as literal text
+ * Fixed background sessions (`claude --bg`) exiting when a plugin's LSP server exited or closed its stdin
+ * Fixed a crash ("Type error") when opening `/mcp` or `/plugin manage` with a malformed `claudeAiMcpEverConnected` value in `~/.claude.json`
+ * Fixed a crash at launch when `~/.claude.json` holds a malformed `theme` value
+ * Fixed a crash ("unrecoverable interface error") when the prompt held text containing terminal color codes, for example a prompt recalled from history or text loaded from the external editor
+ * Fixed a crash when resuming a session whose saved history holds an assistant message stored as a plain string
+ * Fixed sessions on slow or heavily loaded machines sometimes exiting with "Claude Code exited after an unrecoverable interface error" when the first spinner appeared
+ * Fixed a rare case where the screen could stop updating for the rest of the session after an internal rendering error
+ * Fixed a rare case on Windows where a turn could stop with an error such as "Out of memory" right after Claude replied, so that reply's tool calls never ran
+ * Fixed sessions continued after `/clear` (restart, `--continue`, `--resume`) missing part of their first message when a SessionStart hook printed output, causing a full prompt-cache miss
+ * Fixed messages from other agents (such as a subagent's SendMessage) that arrived mid-turn showing up below the "Ran N shell commands" row instead of where they arrived
+ * Fixed the "copied" notice not appearing after drag-selecting text in the fullscreen `/resume` picker and other panels that cover the prompt area
+ * Fixed `$TMPDIR` expanding empty in Bash commands that run outside the sandbox while sandboxing is enabled
+ * Fixed WebFetch and WebSearch in Cowork cloud sessions not telling Claude why a request was refused, such as a used-up fetch budget or an admin policy
+ * Fixed the Claude apps gateway's telemetry relay ignoring a collector hostname or domain listed in `NO_PROXY` when a proxy is set
+ * Fixed one malformed `strictKnownMarketplaces` or `blockedMarketplaces` entry silently disabling the whole enterprise marketplace policy
+ * Fixed failed auto-updates leaving large staged downloads behind in `~/.cache/claude/staging`
+ * Fixed `/plugin` not stripping terminal control characters from messages on the Installed tab, such as the error of a failed plugin update
+ * Fixed `/plugin` → Installed and `/skills` crashing when a skill or legacy command is named like a built-in Object property such as `constructor` or `toString`
+ * Fixed `/plugin` closing with no message when every install in a multi-select failed
+ * Fixed uninstalled plugins reappearing as "failed to load" rows in `/plugin` Installed, and Remove not clearing such a row
+ * Fixed plugins from the official marketplace being recorded without their commit in `installed_plugins.json`, and `installed_plugins.json` keeping the old commit after updating a pinned-commit plugin
+ * Fixed plugin reload previews keeping every previewed copy of a plugin archive unpacked until exit, and overwriting the cached `--plugin-url` archive a reload falls back to when its download fails
+ * Fixed Remote Control session bookkeeping failing when `~/.claude.json` holds a malformed placeholder record
+ * Fixed the error after a revoked claude.ai login blaming an expired Anthropic profile; it now leads with `/login`
+ * Fixed typed or pasted text occasionally coming out scrambled in the `claude agents` dispatch input during key repeat or very fast input
+ * Fixed a crash ("unrecoverable interface error") when resuming a session whose saved transcript contains a stop hook summary without a well-formed hook list
+ * Fixed Enter on a selected agent panel row doing nothing when `keybindings.json` rebinds Enter in the Chat context, for example to `chat:queueSubmit`
+ * Fixed PDF page reads on Windows failing when the working folder's path is long (about 120 characters or more)
+ * Fixed a headless resume (`claude -p --resume`, the SDK, a VS Code extension window reload) starting the session's cost and usage totals at zero; headless sessions now save their totals at exit
+ * Fixed project skills from the main repository not loading in `--worktree` sessions when `.claude/skills` is untracked
+ * Fixed a `sandbox.excludedCommands` glob exempting an entire compound Bash command from the sandbox when only one part matched; every part must now match
+ * Fixed resumed subagents and teammates re-rendering the MCP tool definitions they had loaded, which broke prompt caching for that agent
+ * Fixed rate-limited artifact publishes telling Claude to stop retrying; Claude is now told nothing was published and when to send the same publish again
+ * Fixed attachments recorded earlier in a conversation being re-rendered after a resume or relaunch, which dropped extended thinking and missed the prompt cache
+ * Fixed Console sign-in showing only "Request failed with status code 400" when the server refuses to create an API key; it now shows the server's message
+ * Fixed messages typed while Claude is still working sometimes being ignored by the model
+ * Improved session start-up for SDK and headless (`-p`) use: the first turn no longer waits on the per-directory CLAUDE.md lookup
+ * Improved the Claude apps gateway's loopback error messages to name `CLAUDE_GATEWAY_ALLOW_LOOPBACK`
+ * Improved `/plugin` Installed: an MCP server listed apart from its plugin now shows which plugin it belongs to
+ * Improved `claude plugin install` on an already-installed plugin: it now says when the marketplace offers a newer version and names the `claude plugin update` command
+ * Improved the startup notice overflow line under the logo: it now reads "N more notices hidden" instead of "+N more · /status"
+ * Improved prompt handling: invisible Unicode formatting and tag characters in a prompt are removed and the cleaned prompt is shown for review before it is sent
+ * Improved `/ultrareview` when there's nothing to review: messages say which case you're in, offer a command that reviews your latest commit, and a new repository's first commit is reviewed in full
+ * Improved artifact link handling so Claude reads claude.ai artifact links with the Artifact tool instead of WebFetch when that tool is available
+ * Improved the dangerous-rm permission prompt to name the flagged rm command and suggest a `${VAR:?}` guard, so headless runs can recover
+ * Improved the Artifact tool's permission prompts: shorter sentences, pages and artifacts named by title or file name, and links listed after the text
+ * Changed Fable to always appear in `/model` on the Anthropic API; it is greyed out only when your organization's settings disable it
+ * Changed the Bash sandbox instructions on Bedrock, Vertex and Foundry to the first-party wording, which frames the sandbox as the boundary of what the task was given
+ * Changed `/ultrareview` in non-interactive sessions to refuse when the repository has no base branch or shared history
+ * Changed subagent results to reach the main agent under a header marking them as subagent output, with the result indented, so text in a subagent's result cannot pass as the session's own instructions
+ * Changed workflow scripts' computed `agent()` prompts on Bedrock, Vertex and Foundry to reach the subagent framed as script-authored text, so the safety classifier does not read them as the user
+ * Removed the background Haiku auto-title request from `claude -p` runs launched outside an SDK or IDE
+ * Removed the deprecated TaskOutput tool; Claude reads a background task's output file with Read instead, and the `taskOutputMaxChars` setting and `TASK_MAX_OUTPUT_LENGTH` no longer have any effect
+ * \[VSCode] Added a Sign out row to the panel menu, with `/logout` in the typed command menu
+ * \[VSCode] Added background shells and other running tasks to the agent map, each with a Stop, and a typed `/tasks` that opens it
+ * \[VSCode] Added a Copy response button on responses and a typed `/copy`
+ * \[VSCode] Added a one-time notice when inactive sessions are archived automatically, and an "Unarchive all" action on the Archived sessions group
+ * \[VSCode] Added the session's cost and token usage to the Account & usage dialog and the session manager where plan limits do not apply (Vertex, Bedrock, Foundry, API key)
+ * \[VSCode] Fixed the "General config" menu row showing `/config` usage text instead of opening settings, and made typed `/mcp`, `/hooks`, `/memory`, `/rewind` and similar commands open their dialogs
+ * \[VSCode] Fixed the effort slider's level not persisting into later sessions on a model that already had a level saved with `/effort`
+ * \[VSCode] Fixed Auto missing from the mode picker for conversations opened in an already-used panel when the saved model setting is a differently-cased alias such as "Sonnet"
+ * \[VSCode] Fixed `/fast` not saving fast mode as the default, so it was lost when the extension relaunched Claude Code
+ * \[Claude Code on the web] Added Personal and Organization sections to the environment picker on Team and Enterprise plans, and admins can now share a personal environment with the organization
+ * \[Claude Code on the web] Changed organization environments to open as a read-only summary from the Code tab on Team and Enterprise plans, with editing under Admin settings → Cloud environments
+ * \[Claude Code on the web] Fixed a cloud environment saved with Custom network access and no domains silently reverting to Trusted; the dialog now asks for at least one domain
+ * \[Claude Code on the web] Changed the admin Claude Code setting labeled "Web" to "Cloud sessions" and removed the redundant read-only Mobile row beneath it
+ * \[Claude Tag] Fixed routines created in a Slack channel on an Enterprise Grid org-wide install failing to read other public channels in their workspace when they ran
+ * \[Claude Tag] Fixed the "Learn more" links on credential presets in Claude Tag access bundles to open each vendor's credential-setup page instead of a generic API reference
+ * \[Claude Tag] Changed the Pylon credential preset in Claude Tag access bundles so admins can point it at Pylon's EU host
+ * \[Claude Tag] Fixed Google Cloud credential forms in Claude Tag access bundles: a refused key file now says why, the website and scopes stay locked, and a rejected rotation keeps the pasted key
+ * \[Claude Tag] Fixed the network events log in Claude Tag admin settings showing no response status for requests through connections that use AWS signing, client certificates or a custom CA
+
+
* Fixed every request failing with `400 … Input tag 'advisor_20260301'` when `ANTHROPIC_BASE_URL` points at a proxy or gateway (2.1.275 regression)
@@ -4430,7 +4525,7 @@ Run `claude --version` to check your installed version.
* Improved `@`-mention typeahead to rank source files above MCP resources with similar names
* Improved PowerShell tool prompt with version-appropriate syntax guidance (5.1 vs 7+)
* Changed `Edit` to work on files viewed via `Bash` with `sed -n` or `cat`, without requiring a separate `Read` call first
- * Changed hook output over 50K characters to be saved to disk with a file path + preview instead of being injected directly into context
+ * Changed hook output over 10,000 characters to be saved to disk with a file path + a 2,000-character preview instead of being injected directly into context
* Changed `cleanupPeriodDays: 0` in settings.json to be rejected with a validation error — it previously silently disabled transcript persistence
* Changed thinking summaries to no longer be generated by default in interactive sessions — set `showThinkingSummaries: true` in settings.json to restore
* Documented `TaskCreated` hook event and its blocking behavior
diff --git a/content/en/docs/claude-code/claude-apps-gateway-config.md b/content/en/docs/claude-code/claude-apps-gateway-config.md
index 998be40a00..6ce0619993 100644
--- a/content/en/docs/claude-code/claude-apps-gateway-config.md
+++ b/content/en/docs/claude-code/claude-apps-gateway-config.md
@@ -84,7 +84,7 @@ OpenID Connect (OIDC) is the SSO protocol the gateway uses with your identity pr
| `id_token_signed_response_alg` | No | Expected id\_token signing algorithm. Default `RS256`. Set for IdPs that sign with ES256, PS256, or EdDSA. |
| `additional_authorized_parties` | No | Extra `azp` values to accept beyond `client_id`, for Keycloak broker and token-exchange flows |
| `discovery_url` | No | Fetch the discovery document from this URL instead of deriving it from `issuer`, for IdPs behind a proxy that rewrites the issuer host. The path must contain `/.well-known/`. |
-| `use_proxy` | No | Send the gateway's own IdP requests through the forward proxy in `HTTPS_PROXY` or `HTTP_PROXY`, honoring `NO_PROXY`. Unset or `false`, those requests go direct. Requires v2.1.227 or later; see [IdP requests through a forward proxy](#idp-requests-through-a-forward-proxy) below. |
+| `use_proxy` | No | Send the gateway's own IdP requests through the forward proxy in `HTTPS_PROXY` or `HTTP_PROXY`, honoring `NO_PROXY`. `false` keeps those requests direct. Requires v2.1.227 or later; see [IdP requests through a forward proxy](#idp-requests-through-a-forward-proxy) below. |
| `form_action_origins` | No | Additional origins for the `/device` page's `Content-Security-Policy: form-action` directive. The gateway already allows `'self'` and the discovered `authorization_endpoint` origin, but Chrome enforces `form-action` against the entire redirect chain. If your IdP redirects through a second host, such as Azure AD federated to ADFS, hub-spoke Okta, or a corporate SSO interceptor, list every origin the authorization request may redirect through. |
| `ca_cert_pem` | No | The PEM-encoded CA certificate itself, not a path to a file. It replaces the system trust store for IdP requests only. To load a mounted file, write `${file:/etc/gateway/idp-ca.pem}`. Use for Keycloak or Dex behind corporate PKI. |
@@ -94,6 +94,43 @@ The inference upstreams honor `HTTPS_PROXY` and `HTTP_PROXY` on every version. T
With `use_proxy: true`, the pod resolves each IdP endpoint's hostname itself and asks the proxy to `CONNECT` to the resolved IP address, so the proxy must accept `CONNECT` to the IP address of every host the discovery document names, not only the issuer. Use an `http://` proxy URL. `ca_cert_pem` and the [SSRF guard](/docs/en/claude-apps-gateway-deploy#threat-model-summary) apply on the proxied path as well.
+[Proxy-only egress](#proxy-only-egress) changes both of these: while it's active, IdP requests follow the proxy unless you set `use_proxy: false`, and the gateway hands the proxy each IdP hostname without resolving it first.
+
+#### Proxy-only egress
+
+Set `CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY=1` in the gateway's environment, next to `HTTPS_PROXY`, when the pod reaches other hosts only through that forward proxy and can't resolve public DNS names itself, or when the proxy refuses `CONNECT` to an IP address. Requires v2.1.277 or later. It's an environment variable rather than a `gateway.yaml` key so that nothing in the config file can relax the gateway's address check.
+
+```bash theme={null}
+export HTTPS_PROXY=http://proxy.corp.example.com:3128
+export NO_PROXY=
+export no_proxy=
+export CLAUDE_GATEWAY_PROXY_IS_EGRESS_BOUNDARY=1
+```
+
+The gateway logs one `network:` line at boot while proxy-only egress is active.
+
+Each row below is one class of outbound request on a gateway with `HTTPS_PROXY` set, by default and while proxy-only egress is active.
+
+| Outbound request | Default | Proxy-only egress active |
+| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- |
+| `provider: anthropic` upstreams, Workload Identity Federation token exchange, `telemetry.forward_to` exports | Resolved and checked locally, then `CONNECT` to the checked IP address through the proxy. A telemetry collector listed in `NO_PROXY` is reached directly instead | Hostname handed to the proxy |
+| IdP discovery, JWKS, token, and userinfo | Direct unless [`oidc.use_proxy: true`](#idp-requests-through-a-forward-proxy), then `CONNECT` to the checked IP address | Hostname handed to the proxy, unless `oidc.use_proxy: false` keeps an internal IdP direct |
+| Amazon Bedrock, Claude Platform on AWS, Google Cloud's Agent Platform, and Microsoft Foundry upstreams; Google group lookups | Hostname handed to the proxy | Unchanged |
+
+Proxy-only egress stays off unless the gateway's environment meets all three of these conditions:
+
+* `HTTPS_PROXY` or `HTTP_PROXY` is set.
+* `NO_PROXY` and `no_proxy` are empty. If your platform injects either into pods, set both to an empty value on the gateway container. Listing a telemetry collector in `NO_PROXY` keeps proxy-only egress off.
+* `CLAUDE_GATEWAY_ALLOW_LOOPBACK` isn't turned on. A collector or IdP on the pod's own loopback can't be combined with proxy-only egress, because a loopback address handed to the proxy would be the proxy host's own, so give those services an address the proxy can reach instead. For the same reason the gateway refuses `localhost`-style names outright while proxy-only egress is active.
+
+When one of those conditions isn't met, the gateway logs a warning at boot naming the variable that stopped it and keeps the default behavior.
+
+Once proxy-only egress is active, allow every destination in the proxy, including an internal collector and any host configured by IP address. You can still keep an internal IdP direct with [`oidc.use_proxy: false`](#idp-requests-through-a-forward-proxy).
+
+
+ Turn this on only when the proxy's allowlist is at least as strict as the gateway's own check. The proxy must refuse cloud metadata endpoints such as `169.254.169.254` and `metadata.google.internal`, link-local addresses, and the proxy host's own loopback, and it must refuse them by the address a name resolves to, not only by name, because the gateway no longer catches a hostname that resolves to one of them. A proxy that connects anywhere it's asked removes the gateway's [SSRF guard](/docs/en/claude-apps-gateway-deploy#threat-model-summary) for these requests.
+
+
### `session`
The `session` block shapes the bearer tokens the gateway mints after sign-in: the secret that signs them and how long they live.
@@ -107,12 +144,13 @@ The `session` block shapes the bearer tokens the gateway mints after sign-in: th
The `store` block points the gateway at its PostgreSQL database, which holds device grants and rate-limit counters.
-| Field | Required | Description |
-| ----------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
-| `postgres_url` | Yes | `postgres://` or `postgresql://` URL. Required: the device-grant rendezvous, where the browser callback writes and the polling CLI reads, needs cross-replica state. The gateway runs its own schema migrations at boot and on upgrade, so the role needs rights to create and alter tables on the target schema. See [Upgrades](/docs/en/claude-apps-gateway-deploy#upgrades) and [Postgres](/docs/en/claude-apps-gateway-deploy#postgres). |
-| `username` | No | Overrides the user in `postgres_url` |
-| `password` | No | Database credential. Set it here rather than in `postgres_url` so the credential stays out of the URL. Accepts any characters and takes precedence over URL credentials. |
-| `max_connections` | No | Postgres connection-pool size per replica. Default `5`, which is conservative and friendly to shared databases. With [spend limits](#admin) enabled, the hot path does a few operations per inference request, so raise it for a dedicated database under load, and keep replicas × this below the database's `max_connections`. |
+| Field | Required | Description |
+| ------------------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
+| `postgres_url` | Yes | `postgres://` or `postgresql://` URL. Required: the device-grant rendezvous, where the browser callback writes and the polling CLI reads, needs cross-replica state. The gateway runs its own schema migrations at boot and on upgrade, so the role needs rights to create and alter tables on the target schema. See [Upgrades](/docs/en/claude-apps-gateway-deploy#upgrades) and [Postgres](/docs/en/claude-apps-gateway-deploy#postgres). |
+| `username` | No | Overrides the user in `postgres_url` |
+| `password` | No | Database credential. Set it here rather than in `postgres_url` so the credential stays out of the URL. Accepts any characters and takes precedence over URL credentials. |
+| `max_connections` | No | Postgres connection-pool size per replica. Default `5`, which is conservative and friendly to shared databases. With [spend limits](#admin) enabled, the hot path does a few operations per inference request, so raise it for a dedicated database under load, and keep replicas × this below the database's `max_connections`. |
+| `connect_timeout_seconds` | No | Seconds the gateway waits when it opens a Postgres connection. A whole number from `1` to `60`, default `5`. Raise it if connection attempts time out when a new gateway instance starts. Requires Claude Code v2.1.274 or later on the gateway server. Earlier versions refuse to start when the key is set. |
For local development, point `postgres_url` at a throwaway Postgres container, for example `docker run --rm -p 5432:5432 -e POSTGRES_HOST_AUTH_METHOD=trust postgres`.
@@ -333,6 +371,51 @@ upstreams:
| ACI / App Service | Enable system-assigned or user-assigned managed identity on the resource. `use_azure_ad: true` picks it up. |
| Anywhere else | `auth: { api_key: "${FOUNDRY_API_KEY}" }`. Quote `${…}` inside `{ }`. |
+#### Static headers on upstream requests
+
+To add fixed headers to the requests the gateway sends to one upstream, set `headers:` on that upstream. Use it when a proxy you run in front of the provider routes or attributes traffic by a header.
+
+`headers:` requires Claude Code v2.1.277 or later on the gateway server. An earlier gateway refuses to start when it finds the key. Upgrade every replica before you add the key, and remove the key before you roll back to an earlier version.
+
+The headers go to the server that `base_url` names, or to the provider's own endpoint when `base_url` is unset. The provider receives them too unless your proxy removes them.
+
+This example reaches a `provider: vertex` upstream through a proxy at `upstream-proxy.internal.example.com`. It sets the `x-source` header the proxy reads, and sends a token from the `PROXY_TOKEN` environment variable as `x-proxy-token`:
+
+```yaml theme={null}
+upstreams:
+ - provider: vertex
+ region: us-east5
+ project_id: example-prod
+ base_url: https://upstream-proxy.internal.example.com
+ auth: {}
+ headers:
+ x-source: claude-apps-gateway
+ x-proxy-token: ${PROXY_TOKEN}
+```
+
+Values are printable ASCII text with no space at either end. Quote a number, `true`, or `false` so YAML reads it as text.
+
+To keep a secret out of the config file, use [secret expansion](#secret-expansion) to load the value from an environment variable with `${VAR}` or from a file with `${file:/path}`. A `${VAR}` that resolves to an empty value stops the gateway from starting.
+
+`headers:` works on every provider, and each upstream sends only its own.
+
+Not every request that the gateway sends to an upstream carries them:
+
+| Request the gateway sends to this upstream | Carries `headers:` |
+| ---------------------------------------------------------------------- | ------------------------------------ |
+| `/v1/messages`, streaming or not, and `/v1/messages/count_tokens` | Yes |
+| A request that failed over from another upstream | Yes, this upstream's `headers:` only |
+| Amazon Bedrock's `CountTokens` call for a request the client abandoned | No |
+| The Workload Identity Federation token exchange | No |
+
+On an Amazon Bedrock or Claude Platform on AWS upstream that signs requests with AWS SigV4, these headers are part of the signature, so your proxy must pass them through unchanged.
+
+If you use a name the gateway reserves, it refuses to start, and the startup error names the header. Reserved names include:
+
+* `authorization` and `x-api-key`
+* `host`, `content-type`, and `user-agent`
+* Any name starting with `anthropic-`, `x-goog-`, `x-amz-`, or `x-amzn-`
+
#### Multiple upstreams
The same provider can appear more than once with a distinct `name:`. This covers different regions, different accounts via different credential chains, provisioned throughput versus on-demand, and cross-provider fallback.
@@ -341,6 +424,12 @@ The gateway tries upstreams in order. `5xx`, `429`, `401`, `403`, `404`, timeout
`429` is per-upstream capacity, so provisioned-throughput (PT) exhaustion fails over to on-demand. If you set [`forward_user_identity: true`](#per-user-identity-headers-for-a-proxy-you-run) on an upstream, a `429` to a request that carried the developer's email is a per-user denial instead and doesn't fail over.
+Every request starts at the first upstream. A request reaches a later upstream only when every upstream ahead of it has failed or doesn't serve the requested model.
+
+The gateway keeps no record of failed upstreams, so while an upstream is down, every request that reaches it still tries it and waits for it to fail before moving on.
+
+For an Anthropic API upstream, [`timeouts.upstream_ttfb_ms`](#http-tuning) bounds the wait on a down upstream. That setting doesn't apply to the other providers, where the gateway waits up to one hour for an upstream to start responding.
+
`404` is per-upstream model availability, so an upstream that hasn't enabled a model doesn't block a later upstream that serves it. An upstream that can't resolve the requested model is skipped without a network round-trip.
This example routes a provisioned-throughput Amazon Bedrock allotment first, overflows to on-demand and a second account, and falls back to the Anthropic API last:
@@ -735,12 +824,18 @@ The CLI stamps each export with the authenticated user's identity, read from the
[Claude Desktop](#claude-desktop-overlay) and Cowork sessions signed in through the gateway stamp their telemetry with `user.email` and `user.groups` alongside `enduser.id`, so you can cover terminal, Desktop, and Cowork usage with one query on `user.email` or `user.groups`. `user.groups` is the comma-separated IdP group list.
+Desktop and Cowork telemetry also carries `enduser.sub`, the `sub` claim your identity provider issues for the user, which stays the same when a user's email changes. Terminal sessions stamp the same value under `user.id`, so a query that matches `enduser.sub` against terminal `user.id` covers one user's terminal, Desktop, and Cowork usage together. On Desktop and Cowork exports, `user.id` is an anonymous identifier, not the subject.
+
Like all OpenTelemetry data from Claude Code, these attributes go only to destinations your organization configures, never to Anthropic.
If a user's group list is longer than 255 characters once percent-encoded, or a group name contains a comma or equals sign, the gateway leaves `user.groups` off that user's Desktop and Cowork telemetry rather than truncating it. That user's terminal sessions still carry the full list.
+The gateway leaves `enduser.sub` off when the subject is longer than 255 characters once percent-encoded, or contains a space, a character outside printable ASCII, or one of `,` `;` `=` `\` `"` `%`. That user's Desktop and Cowork telemetry keeps its other attributes.
+
You need Claude Code v2.1.265 or later on the gateway server for `user.email` and `user.groups` on Desktop and Cowork telemetry, and Claude Desktop 1.24012 or later on each developer's machine for `user.groups`.
+You need Claude Code v2.1.274 or later on the gateway server for `enduser.sub`.
+
```yaml theme={null}
telemetry:
forward_to:
@@ -772,6 +867,12 @@ Each `forward_to` URL must use `https://`, with one exception for a collector on
For an in-cluster collector, expose it over HTTPS at its own internal address, or run it as a sidecar with the variable set.
+When `HTTPS_PROXY` is set, the gateway sends exports through that proxy.
+
+To reach an internal collector directly, add it to `NO_PROXY` by hostname or by a domain with a leading dot such as `.internal.example.com`, which requires Claude Code v2.1.277 or later on the gateway server. Make sure the gateway can reach the collector without the proxy. An entry without a leading dot matches only that exact name, not names under it. CIDR ranges don't match.
+
+With [proxy-only egress](#proxy-only-egress) turned on, allow the collector in the proxy instead, since any `NO_PROXY` entry keeps proxy-only egress off.
+
Telemetry is off in the CLI by default. When you set both `telemetry.forward_to` and `listen.public_url`, the gateway turns it on for connected clients by pushing six environment variables through `/managed/settings`:
* `CLAUDE_CODE_ENABLE_TELEMETRY=1`
@@ -839,9 +940,9 @@ Four optional top-level blocks, `access_control`, `limits`, `timeouts`, and `rat
| `limits` | `max_request_bytes` | 32 MiB | Max inbound request body; oversize requests get `413` before the body is buffered. Raise for large file or image requests. |
| `limits` | `max_request_header_bytes` | unset | When set, oversize headers return `431` |
| `limits` | `max_url_length` | unset | When set, an over-long URL returns `414` |
-| `timeouts` | `upstream_ttfb_ms` | 120000 | Max wait for the upstream's response headers (time to first byte). The response body then streams with no wall-clock cap. Applies to the direct Anthropic upstream path; every other provider is bounded by its provider SDK's own timeout. |
-| `rate_limits` | `device_authorization.max` / `.window_seconds` | 30 / 600 | Per-IP rate limit on the unauthenticated device-authorization endpoint. Raise for a large org behind a shared egress IP or NAT. These limits apply only to the device-grant sign-in flow, not to `/v1/messages` inference. See [User-code brute-force resistance](/docs/en/claude-apps-gateway-deploy#user-code-brute-force-resistance). |
-| `rate_limits` | `device_verify.max` / `.window_seconds` | 10 / 600 | Per-IP rate limit on `user_code` submissions at `/device` |
+| `timeouts` | `upstream_ttfb_ms` | 120000 | Max wait for the upstream's response headers (time to first byte). The response body then streams with no wall-clock cap. Applies to the direct Anthropic upstream path; on every other provider the gateway waits up to one hour for the response to start. |
+| `rate_limits` | `device_authorization.max` / `.window_seconds` | 30 / 600 | Per-IP rate limit on the unauthenticated device-authorization endpoint. Raise for a large org behind a shared egress IP or NAT. [Large rollouts](/docs/en/claude-apps-gateway-deploy#large-rollouts) shows how to size it. These limits apply only to the device-grant sign-in flow, not to `/v1/messages` inference. See [User-code brute-force resistance](/docs/en/claude-apps-gateway-deploy#user-code-brute-force-resistance). |
+| `rate_limits` | `device_verify.max` / `.window_seconds` | 10 / 600 | Per-IP rate limit on `user_code` submissions at `/device`. It is what stops someone from guessing another developer's code. [Large rollouts](/docs/en/claude-apps-gateway-deploy#large-rollouts) shows how far to raise it. |
If you leave both `access_control` lists empty, which is the default, the gateway serves any client address, so only your network restricts who can reach it. That matters because a gateway can push [managed settings](#managed) that run commands on developer machines.
@@ -903,6 +1004,7 @@ session:
store:
postgres_url: ${GATEWAY_POSTGRES_URL}
# max_connections: 5
+ # connect_timeout_seconds: 5
# Enables /v1/organizations/spend_limits (mirrors the Anthropic Admin API)
# and per-developer spend enforcement on /v1/messages. Omit to disable.
diff --git a/content/en/docs/claude-code/claude-apps-gateway-deploy.md b/content/en/docs/claude-code/claude-apps-gateway-deploy.md
index 0989063cb7..9fd99304f1 100644
--- a/content/en/docs/claude-code/claude-apps-gateway-deploy.md
+++ b/content/en/docs/claude-code/claude-apps-gateway-deploy.md
@@ -114,6 +114,29 @@ Once you deploy the keys, Claude Code stops using a leftover API key or claude.a
See [where each mechanism stores the policy](/docs/en/managed-settings#where-each-mechanism-stores-the-policy) for the file paths, and [Client-side managed settings](/docs/en/claude-apps-gateway-config#client-side-managed-settings) for the Claude Desktop `bootstrapUrl` equivalent.
+### Large rollouts
+
+Sign-in is rate limited per client IP address, and the defaults suit a small team. Each address gets 30 sign-in starts and 10 code submissions every 10 minutes. A rollout to thousands of developers can reach those limits on the first morning, for one of two reasons:
+
+* **The gateway can't see past your load balancer.** Without [`listen.trusted_proxies`](/docs/en/claude-apps-gateway-config#listen), every developer appears to come from the load balancer's address and shares one limit. Set it before anything else. The gateway logs a warning the first time it ignores an `X-Forwarded-For` header.
+* **Many developers share a few NAT or VPN egress addresses.** They share those addresses' limits even when `trusted_proxies` is right. Raise [`rate_limits`](/docs/en/claude-apps-gateway-config#http-tuning) to fit.
+
+To size `max`, divide the developers by the egress addresses they share. Estimate how many of those sign in within one `window_seconds` period, which is 10 minutes by default. Then double it to cover retries and developers who sign in to both Claude Code and Claude Desktop.
+
+For example, 10,000 developers behind 4 egress addresses sign in evenly over an hour. That is 2,500 developers per address and about 420 of them in each 10 minutes, which you double and round up to 1,000. The example below sets both limits to 1,000:
+
+```yaml theme={null}
+rate_limits:
+ device_authorization: { max: 1000, window_seconds: 600 }
+ device_verify: { max: 1000, window_seconds: 600 }
+```
+
+`device_verify` is what stops someone from guessing another developer's sign-in code, so raise it only as far as your estimate needs. Even at these limits, a code is 8 characters from a 20-character alphabet and expires after 10 minutes, so guessing stays impractical; see [User-code brute-force resistance](#user-code-brute-force-resistance).
+
+When your IdP issues refresh tokens, Claude Code renews sessions silently, so you can put the limit back after the rollout. Without refresh tokens, developers sign in again every [`session.ttl_hours`](/docs/en/claude-apps-gateway-config#session). Size both limits for that steady rate too and leave them raised.
+
+When a limit is reached, Claude Code v2.1.274 or later shows `The gateway is limiting sign-in attempts right now`. A gateway on v2.1.274 or later shows `Too many attempts came from your network address` on the verification page, with the settings to check. It also writes a `sign-in refused` log line that names the setting to change.
+
## Operations
Once the gateway is serving traffic, day-to-day operation is reading its logs, probing its health, and rotating its secrets on your schedule. The subsections cover each, plus what Postgres holds and how upgrades and rollbacks behave.
@@ -142,6 +165,27 @@ The gateway serves `GET /healthz` as a liveness probe and `GET /readyz` as a rea
The OAuth discovery document at `/.well-known/oauth-authorization-server` also returns `200` only after config load, OIDC discovery, upstream client construction, and Postgres migration all succeed, so it doubles as an end-to-end boot check.
+### Concurrent upstream requests
+
+By default, each gateway replica sends at most 256 requests upstream at the same time. A streaming response counts against the limit until the stream ends.
+
+A request that arrives while a replica is at the limit waits inside the gateway for a free slot. The developer sees a response that is slow to start or appears to hang. On a `provider: anthropic` upstream, a request that waits longer than [`timeouts.upstream_ttfb_ms`](/docs/en/claude-apps-gateway-config#http-tuning) gives up on that upstream, and fails with a 502 when no later upstream serves it.
+
+The startup log line that contains `upstream requests:` shows the limit in effect. While a replica has more requests open than the limit, it also logs a warning that contains `client requests are open`, at most once a minute.
+
+To serve more requests at once, you have two options:
+
+* Add replicas.
+* Raise the limit on each replica. Set the `BUN_CONFIG_MAX_HTTP_REQUESTS` environment variable on the gateway container to a whole number from 1 to 65535, then restart the container.
+
+A replica fills its limit at a request rate of about the limit divided by the average number of seconds a request stays open. For example, if requests stay open for 10 seconds on average, a replica at the default limit of 256 fills it at about 26 requests a second.
+
+If you autoscale on CPU, a replica at the limit queues requests without triggering a scale-out, so set the target below the CPU level your replicas show when they log the `client requests are open` warning.
+
+
+ Every open request holds memory in the gateway process while it streams and while it waits for a slot. If you keep the limit at 256, memory on an overloaded replica still grows, because waiting requests keep their request bodies. Size the container's memory for the number of requests open at peak, and watch memory when you change the limit. A replica that runs out of memory is killed and drops every stream it holds.
+
+
### Outage behavior
If Postgres goes down, the gateway itself keeps serving signed-in developers and new sign-ins fail. Whether developers actually keep working depends on how your orchestrator handles readiness:
@@ -181,7 +225,23 @@ With spend limits in use, a lost database means lost spend tracking and caps, no
### Upgrades
-Replicas are stateless, so a rolling restart is safe at any time. The gateway runs schema migrations at boot, which means deploying the new binary self-migrates the database. Concurrent replicas serialize on a Postgres advisory lock, so only one applies each migration.
+Replicas are stateless, so a rolling restart loses no gateway state. The gateway runs schema migrations at boot, which means deploying the new binary self-migrates the database. Concurrent replicas serialize on a Postgres advisory lock, so only one applies each migration.
+
+When your orchestrator stops a replica with `SIGTERM`, as in a rolling restart or a scale-in, the gateway stops accepting new connections and lets requests and streams already in flight finish before it exits. It waits up to 25 seconds, called the drain window, then closes whatever is still open. A `SIGINT`, such as Ctrl+C in a terminal, starts the same drain, and a second signal during the drain closes the open requests and exits right away. Draining requires gateway v2.1.274 or later.
+
+Long generations can stream for minutes. On Kubernetes and Amazon ECS, raise both of these together to give those streams more time:
+
+* **The drain window**: set the `CLAUDE_GATEWAY_DRAIN_TIMEOUT_MS` environment variable on the gateway container to a positive whole number of milliseconds, such as `120000`. The gateway ignores a value in any other form, such as `120s`, and keeps the 25-second default
+* **Your orchestrator's grace period**: `terminationGracePeriodSeconds` on Kubernetes, or `stopTimeout` on Amazon ECS
+
+The grace period defaults to 30 seconds on both platforms. Keep it at least 5 seconds longer than the drain window, or the orchestrator kills the gateway before the drain finishes. On Kubernetes, add the duration of any `preStop` hook as well, because the grace period starts counting before the hook runs rather than when the gateway receives `SIGTERM`.
+
+Your platform may also cap how long the drain can run:
+
+* **Amazon ECS on Fargate**: `stopTimeout` allows at most 120 seconds
+* **Cloud Run**: stops an instance 10 seconds after `SIGTERM`, so open streams get at most 10 seconds there, whatever the drain window is
+
+When the drain window ends with requests still open, the gateway logs a warning that contains `drain window over after`, counts the requests it cut, and names both settings to raise.
Migrations are append-only, so rolling back to a prior binary that knows fewer migrations is safe; it ignores the extra rows. Rollback also re-validates the YAML against the older binary's schema, so a config that adopted a key introduced by the newer release fails boot on the older one. Remove the new key before rolling back.
@@ -207,7 +267,11 @@ The gateway sits inside your network perimeter, but individual developer laptops
* Developers hold short-lived JWTs instead of raw upstream keys. The CLI-to-gateway leg uses the RFC 8628 device grant, and the gateway's authorization-code exchange with the IdP runs PKCE in the default configuration, so an intercepted IdP authorization code is useless.
* The device-verification page enforces same-origin POST and a per-IP rate limit per RFC 8628 §5.1. See [User-code brute-force resistance](#user-code-brute-force-resistance).
-* Outbound requests go through a server-side request forgery (SSRF) guard that resolves DNS, blocks link-local and cloud-metadata addresses plus loopback by default, and pins the connection to the resolved IP, so operator-influenced URLs such as the IdP and OTLP destinations can't be redirected to cloud metadata endpoints. RFC 1918 private ranges are deliberately allowed, because IdPs and OTLP collectors commonly live on private IPs. Set `CLAUDE_GATEWAY_ALLOW_LOOPBACK=1` in the gateway's environment only when something the gateway must reach legitimately lives on loopback, such as a local-development IdP or a sidecar OTLP collector on `localhost`. The variable relaxes the loopback block for every operator-configured URL and also skips the boot-time warning that checks whether the pod can reach the cloud metadata endpoint, so prefer giving the collector its own internal address.
+* The gateway's requests to your IdP, your OTLP collectors, and `provider: anthropic` upstreams go through a server-side request forgery (SSRF) guard that resolves DNS, blocks link-local and cloud-metadata addresses plus loopback by default, and pins the connection to the resolved IP, so those operator-influenced URLs can't be redirected to cloud metadata endpoints. RFC 1918 private ranges are deliberately allowed, because IdPs and OTLP collectors commonly live on private IPs. For the other providers, the gateway refuses a `base_url` that names one of those addresses or a metadata hostname when it loads the config, and the provider's SDK then connects without the DNS check.
+
+ If you turn on [proxy-only egress](/docs/en/claude-apps-gateway-config#proxy-only-egress), that address check moves to your forward proxy: the gateway hands it hostnames and the proxy's allowlist must refuse those destinations.
+
+ Set `CLAUDE_GATEWAY_ALLOW_LOOPBACK=1` in the gateway's environment only when something the gateway must reach legitimately lives on loopback, such as a local-development IdP or a sidecar OTLP collector on `localhost`. The variable relaxes the loopback block for every operator-configured URL and also skips the boot-time warning that checks whether the pod can reach the cloud metadata endpoint, so prefer giving the collector its own internal address.
If you add your own egress controls, the gateway must reach the metadata server whenever it uses instance-metadata credentials such as workload identity.
@@ -220,7 +284,7 @@ Two threats are out of scope because they are your infrastructure to secure:
The `user_code` a developer types into the `/device` verification page is 8 characters drawn from a 20-character alphabet, which yields 20⁸ or about 2.56×10¹⁰ combinations, and it expires after 10 minutes.
-The gateway applies per-IP rate limits on the device-grant endpoints, configurable via [`rate_limits`](/docs/en/claude-apps-gateway-config#http-tuning). Raise the limits if many developers sign in from a single shared corporate NAT address. The limits apply only to the sign-in flow, not to inference.
+The gateway applies per-IP rate limits on the device-grant endpoints, configurable via [`rate_limits`](/docs/en/claude-apps-gateway-config#http-tuning). Raise the limits if many developers sign in from a single shared corporate NAT address. [Large rollouts](#large-rollouts) shows how to size them. The limits apply only to the sign-in flow, not to inference.
### Compliance posture
@@ -245,40 +309,43 @@ For questions and feedback, use [Claude Code support](https://support.claude.com
The gateway's stderr includes the audit event stream, the audit log records developer identities, and the debug file records hook and MCP server output from the developer's machine. Review and redact these before posting to a public issue.
-| Symptom | Cause | Fix |
-| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
-| A developer's `/login` shows the standard account picker instead of the **Cloud gateway** screen | `forceLoginMethod` or `forceLoginGatewayUrl` isn't set in managed settings on that machine | Deploy the [managed settings file](/docs/en/claude-apps-gateway#set-the-gateway-url) to the device; `/login` reads the gateway URL from there |
-| A developer's requests fail with `Not signed in to the Cloud gateway — run /login.` | The machine's managed settings set `forceLoginMethod: "gateway"` or `forceLoginGatewayUrl`, and the session has no gateway sign-in. A leftover claude.ai login doesn't satisfy the requirement. | Have the developer run `/login` and complete the gateway sign-in. See also [Administrator policy requires a Cloud gateway sign-in](/docs/en/errors#administrator-policy-requires-a-cloud-gateway-sign-in). |
-| Claude Desktop reports that its bootstrap configuration couldn't be fetched | `/user/bootstrap` returned 404: the policy matching the user doesn't carry a `desktop` key, or no policy matched. The gateway's audit log records each rejection as `desktop_bootstrap.denied` with the reason. | Add a `desktop` block to the policy that matches the user, or to the `match: {}` base layer; an empty `desktop: {}` suffices. See [Claude Desktop overlay](/docs/en/claude-apps-gateway-config#claude-desktop-overlay). |
-| Startup shows `Gateway login is configured in managed settings, but this Claude Code build does not include Cloud gateway support.` | The installed Claude Code build predates gateway support | Have the developer update Claude Code to a release that includes Cloud gateway support |
-| Startup exits with `Administrator policy requires a Cloud gateway sign-in on this machine` | The developer's environment sets `ANTHROPIC_API_KEY` or `ANTHROPIC_AUTH_TOKEN`, their settings configure an [`apiKeyHelper`](/docs/en/settings-reference#apikeyhelper), or an API key from an earlier Claude Console login is still saved | Have the developer clear each that applies: unset the variable, remove the `apiKeyHelper` entry, or run `claude auth logout` to remove the saved key. Then have them start `claude` and sign in with `/login`. See also [Administrator policy requires a Cloud gateway sign-in](/docs/en/errors#administrator-policy-requires-a-cloud-gateway-sign-in). |
-| Startup or `/login` reports `Claude Code may not be enabled for your organization` after a 403 on the managed settings load | The gateway, or something in front of it, answered the `/managed/settings` request with 403. The gateway's own settings route never answers 403. The status comes from the [`access_control`](/docs/en/claude-apps-gateway-config#http-tuning) IP checks or from a proxy or WAF in front of the gateway. The audit log records an IP-check denial as `access.denied` with the reason. The developer stays signed in. | Check the audit log for `access.denied` at the time of the failure and fix the `access_control` lists or the front end, then have the developer start `claude` again |
-| CLI `/login`: `Gateway hosts must be on your organization's private network; resolves to the public (or unrecognized) address ` | The gateway hostname resolves to at least one public IP address. Claude Code checks each resolved address and requires every one to be private. A common cause is a dual-stack name where one family resolves to a public address, including AWS internal dual-stack load balancers, which return public-range AAAA addresses. | Have the gateway name resolve only to private addresses on developer machines. For a dual-stack name, drop the public-range record or serve a separate internal-only DNS name. See the [private-network prerequisite](/docs/en/claude-apps-gateway#prerequisites). If the address is public space your organization owns and uses internally, [declare that block](/docs/en/claude-apps-gateway#allow-a-gateway-on-public-address-space-you-own) instead. |
-| CLI `/login`: `Gateway login would go through proxy , which is not on a private network` | An `HTTPS_PROXY` or `HTTP_PROXY` applies to the gateway host and the proxy's hostname resolves to a public address. A proxy whose host resolves only to private addresses is allowed and doesn't trigger this error | Add the gateway host to `NO_PROXY` on the developer's machine so the connection is direct, or use a proxy whose hostname resolves to private addresses. The message names the exact `NO_PROXY` entry to add |
-| CLI `/login`: `Claude Code only signs in to from inside its declared network (managed settings), and this machine is connecting from , outside it` | The gateway is on a block declared in [`gatewayInternalNetworks`](/docs/en/claude-apps-gateway#allow-a-gateway-on-public-address-space-you-own), and the developer's machine reached it from an address outside that block: a VPN address pool, a container or WSL2 NAT segment, or a network that isn't yours | Have the developer run `/login` from the host OS on your network. If the address shown is also your organization's own public space, replace the gateway's entry with a block that covers both, up to `/8`; a second, overlapping entry is refused |
-| CLI `/login`: `Every address for gateway host must be inside its declared network , and it also resolves to ` | The gateway's name resolves to an address outside the block declared in [`gatewayInternalNetworks`](/docs/en/claude-apps-gateway#allow-a-gateway-on-public-address-space-you-own): a second site, or an IPv6 record on a dual-stack name. Under a declared block every record must be inside that one IPv4 block, private and IPv6 addresses included | Publish only records inside the block for the gateway name on developer machines, or serve a separate internal-only name |
-| CLI `/login`: ` is on the declared network , which Claude Code checks over a direct connection, not through an HTTP proxy` | An `HTTPS_PROXY` or `HTTP_PROXY` applies to a gateway on a declared block | On the developer's machine, add the `NO_PROXY` entry the message names |
-| CLI `/login`: a message starting `gatewayInternalNetworks in managed settings` | The value breaks one of the [validation rules](/docs/en/claude-apps-gateway#allow-a-gateway-on-public-address-space-you-own), and the message names which. Until you fix it, Claude Code refuses every new gateway `/login` on the machine, gateways on private addresses included; existing sign-ins keep working | In the managed settings source you deploy, correct the entry the message names, then rerun `/login` |
-| CLI `/login`: `Could not resolve the configured HTTP proxy` | The hostname in `HTTPS_PROXY` or `HTTP_PROXY` doesn't resolve from the developer's machine, typically because it isn't connected to the corporate network | Have the developer connect to your network or VPN and retry, or fix the proxy URL |
-| CLI `/login`: `Could not resolve gateway host ` | The machine can't resolve the gateway's internal DNS name, typically because it isn't on the corporate network | Have the developer connect to your network or VPN, then retry `/login` |
-| Boot exits with a config validation error naming `store.postgres_url` | No Postgres configured; the gateway requires Postgres | Set `store.postgres_url`. For local development, use a throwaway container: `docker run --rm -p 5432:5432 -e POSTGRES_HOST_AUTH_METHOD=trust postgres`. |
-| Boot exits: `requires the native binary` | Running under Node instead of the native binary | Install Claude Code with one of the [standalone install methods](/docs/en/setup) |
-| Boot exits with an OIDC discovery error after `config.load` | `oidc.issuer` unreachable, or TLS chain not trusted | Check the issuer is reachable from the pod and serves `/.well-known/openid-configuration`. Set `ca_cert_pem` for private PKI. If the pod reaches the IdP only through a forward proxy, set [`oidc.use_proxy: true`](/docs/en/claude-apps-gateway-config#idp-requests-through-a-forward-proxy); on versions before v2.1.227, give the pod a direct route to each of the IdP's endpoints instead. |
-| Boot exits with a Postgres permission error | The database role lacks DDL rights on its schema | Grant the role `CREATE` on the gateway's schema so it can create and alter its tables at boot |
-| `/oauth/callback` shows "Sign-in could not be completed" | Email domain rejected, id\_token validation failed, or `email_verified` is explicitly `false`, which the gateway always rejects with no override | Check `allowed_email_domains` and that the IdP returns a verified `email` claim. For `email_verified: false`, fix the IdP-side verification. If your IdP emits email under a different claim name, set `oidc.email_claim`. |
-| Log: `token exchange failed request_id=: id_token missing email claim` | The IdP isn't including `email` in the id\_token by default. This rejection fires only when `allowed_email_domains` is set; without it, a missing email mints a session with no email | Configure the IdP to emit `email` in the id\_token. Okta: add `email` to a custom authorization server's ID-token claims. Entra: add `email` as an optional claim on the app registration. PingFederate: enable an OpenID Connect Policy that emits `email`. If the IdP serves `email` from the userinfo endpoint but won't include it in the id\_token, such as the Okta org authorization server, set `oidc.userinfo_fallback: true`. |
-| Log: `refresh failed request_id=: invalid_token (…) (at userinfo_no_id_token, …)`, and developers see `Cloud gateway session expired` every `session.ttl_hours` | The IdP accepted the refresh token but returned no id\_token with it, so the gateway asked the IdP's userinfo endpoint for the user's claims. The IdP rejected the refreshed access token there. The gateway answers `temporarily_unavailable`, so Claude Code keeps the refresh token but can't renew the session. Gateway versions before v2.1.260 log the same line without the `(at …)` detail. | Set [`oidc.scope_on_refresh: true`](/docs/en/claude-apps-gateway-config#oidc), available in gateway v2.1.260 or later, so the refresh request asks for `openid` again. Some IdPs, such as Okta, return an id\_token on refresh only when asked. On PingFederate, enable **Return ID Token On Refresh Grant** under **Applications > OAuth > OpenID Connect Policy Management** instead. The key doesn't change PingFederate's behavior. For other IdPs that still omit it, check whether the userinfo endpoint accepts access tokens issued by a refresh. As a stopgap, raise [`session.ttl_hours`](/docs/en/claude-apps-gateway-config#session). See [Identity provider setup](#identity-provider-setup) for the deprovisioning tradeoff. |
-| Every Amazon Bedrock request returns 502; log shows `Could not load credentials from any providers` | On EC2, IMDSv2's default hop limit of 1 blocks the instance-metadata request from inside the container. Boot and `/readyz` pass anyway because the AWS SDK resolves instance credentials on the first request, not at client construction | Raise the hop limit with `aws ec2 modify-instance-metadata-options --instance-id --http-put-response-hop-limit 2`, or set it in the launch template. The change applies to every container on the instance. Prefer ECS task roles where available, which read credentials from the ECS container-credentials endpoint and avoid the change entirely, or apply the change on a dedicated gateway instance to limit the exposure. |
-| IdP error: unknown or unsupported scope | The IdP rejects scopes it doesn't recognize | Set `oidc.scopes` to exactly the list your IdP accepts; it must include `openid`. The default is `openid profile email offline_access`. |
-| Sessions don't silently renew after setting `oidc.scopes` | `offline_access` was dropped from the override | Add `offline_access` back if your IdP supports it. Without a refresh token, developers re-run the browser login every `session.ttl_hours`. |
-| Browser shows "This request came from another site and was blocked" | Cross-site form POST, blocked as CSRF protection. Expected for embedded or proxied pages | Open the verification link directly |
-| Chrome blocks the Approve button with "Refused to send form data … violates … Content Security Policy directive: form-action", but the same page works in Safari or Firefox | Chrome enforces `form-action` against the entire redirect chain. Your IdP redirects onward to a second host that isn't allowlisted. | Add each additional origin in the redirect chain to `oidc.form_action_origins`. Open Chrome DevTools → Console on the Approve page to see which origin was blocked. |
-| Sign-in completes at the IdP but the callback fails, with a CSP error in Chrome or "this sign-in link has expired" in Safari | The IdP returned the code via `response_mode=form_post`, which auto-submits it cross-origin via POST to `/oauth/callback`. Chrome blocks that under a strict CSP; Safari allows the submit but the callback reads only the query string. | Make sure your IdP honors `response_mode=query`, which the gateway requests explicitly so the callback is a plain redirect |
-| Login works locally but fails behind an ALB | `public_url` still names the local or inner `http://` origin, so the IdP gets the wrong `redirect_uri` | Set `listen.public_url` to the external `https://` origin and register `/oauth/callback` with the IdP |
-| Developer sees the trust prompt repeatedly | TLS cert is rotating per replica or per request | Use a stable cert at the ingress, or terminate TLS once and run replicas over plain HTTP internally |
-| CLI `/login`: "Could not verify the gateway's TLS certificate" or `SELF_SIGNED_CERT_IN_CHAIN` | Gateway's TLS chain is signed by a private CA not in the CLI host's trust store | Claude Code reads the OS trust store by default on the native binary and on Node 22.15 or later; [`CLAUDE_CODE_CERT_STORE`](/docs/en/network-config#ca-certificate-store) controls this behavior. If the CA is installed in the OS trust store, ensure developers are on a current runtime. Otherwise set `NODE_EXTRA_CA_CERTS` to the CA certificate PEM before launching. The first-connect fingerprint prompt still applies. |
-| CLI `/login` completes the browser sign-in, then the session ends with `Cloud gateway sign-in was not completed` and a TLS certificate mismatch | On the first request after sign-in, the gateway presented a certificate that doesn't match the fingerprint Claude Code pinned, so Claude Code kept no gateway credential. The usual causes are replicas behind one address that serve different certificates, or something on the network path that intercepts TLS. | Serve one certificate for the hostname, for example by terminating TLS once at the ingress, then have the developer run `/login` again. If that certificate differs from the pinned one, Claude Code shows the [trust prompt](/docs/en/claude-apps-gateway#connect-developers) again with a warning that the certificate changed. |
-| CLI `/login` stops with `The gateway's TLS certificate changed during sign-in: it no longer matches the one you trusted` | A sign-in request reached a server whose certificate doesn't match the one the developer accepted when `/login` started: replicas behind one address serving different certificates, TLS interception on the path, or a certificate rotation while the sign-in was in progress. | Serve one certificate for the hostname, then have the developer start the sign-in again and review the new certificate at the [trust prompt](/docs/en/claude-apps-gateway#connect-developers). |
+| Symptom | Cause | Fix |
+| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
+| A developer's `/login` shows the standard account picker instead of the **Cloud gateway** screen | `forceLoginMethod` or `forceLoginGatewayUrl` isn't set in managed settings on that machine | Deploy the [managed settings file](/docs/en/claude-apps-gateway#set-the-gateway-url) to the device; `/login` reads the gateway URL from there |
+| A developer's requests fail with `Not signed in to the Cloud gateway — run /login.` | The machine's managed settings set `forceLoginMethod: "gateway"` or `forceLoginGatewayUrl`, and the session has no gateway sign-in. A leftover claude.ai login doesn't satisfy the requirement. | Have the developer run `/login` and complete the gateway sign-in. See also [Administrator policy requires a Cloud gateway sign-in](/docs/en/errors#administrator-policy-requires-a-cloud-gateway-sign-in). |
+| Claude Desktop reports that its bootstrap configuration couldn't be fetched | `/user/bootstrap` returned 404: the policy matching the user doesn't carry a `desktop` key, or no policy matched. The gateway's audit log records each rejection as `desktop_bootstrap.denied` with the reason. | Add a `desktop` block to the policy that matches the user, or to the `match: {}` base layer; an empty `desktop: {}` suffices. See [Claude Desktop overlay](/docs/en/claude-apps-gateway-config#claude-desktop-overlay). |
+| Startup shows `Gateway login is configured in managed settings, but this Claude Code build does not include Cloud gateway support.` | The installed Claude Code build predates gateway support | Have the developer update Claude Code to a release that includes Cloud gateway support |
+| Startup exits with `Administrator policy requires a Cloud gateway sign-in on this machine` | The developer's environment sets `ANTHROPIC_API_KEY` or `ANTHROPIC_AUTH_TOKEN`, their settings configure an [`apiKeyHelper`](/docs/en/settings-reference#apikeyhelper), or an API key from an earlier Claude Console login is still saved | Have the developer clear each that applies: unset the variable, remove the `apiKeyHelper` entry, or run `claude auth logout` to remove the saved key. Then have them start `claude` and sign in with `/login`. See also [Administrator policy requires a Cloud gateway sign-in](/docs/en/errors#administrator-policy-requires-a-cloud-gateway-sign-in). |
+| Startup or `/login` reports `Claude Code may not be enabled for your organization` after a 403 on the managed settings load | The gateway, or something in front of it, answered the `/managed/settings` request with 403. The gateway's own settings route never answers 403. The status comes from the [`access_control`](/docs/en/claude-apps-gateway-config#http-tuning) IP checks or from a proxy or WAF in front of the gateway. The audit log records an IP-check denial as `access.denied` with the reason. The developer stays signed in. | Check the audit log for `access.denied` at the time of the failure and fix the `access_control` lists or the front end, then have the developer start `claude` again |
+| CLI `/login`: `The gateway is limiting sign-in attempts right now`, or `Request failed with status code 429` on older versions. The `/device` page may show `Too many attempts` to developers who haven't tried before | The per-IP sign-in rate limit was reached. Either `listen.trusted_proxies` doesn't cover the load balancer, so every developer shares its address, or many developers share a NAT or VPN egress address. Audit events with `result: rate_limited` show the same one or few `client_ip` values. | Set `listen.trusted_proxies` to the load balancer's source ranges first, then raise `rate_limits` if developers still share addresses. See [Large rollouts](#large-rollouts). |
+| CLI `/login`: `Gateway hosts must be on your organization's private network; resolves to the public (or unrecognized) address ` | The gateway hostname resolves to at least one public IP address. Claude Code checks each resolved address and requires every one to be private. A common cause is a dual-stack name where one family resolves to a public address, including AWS internal dual-stack load balancers, which return public-range AAAA addresses. | Have the gateway name resolve only to private addresses on developer machines. For a dual-stack name, drop the public-range record or serve a separate internal-only DNS name. See the [private-network prerequisite](/docs/en/claude-apps-gateway#prerequisites). If the address is public space your organization owns and uses internally, [declare that block](/docs/en/claude-apps-gateway#allow-a-gateway-on-public-address-space-you-own) instead. |
+| CLI `/login`: `Gateway login would go through proxy , which is not on a private network` | An `HTTPS_PROXY` or `HTTP_PROXY` applies to the gateway host and the proxy's hostname resolves to a public address. A proxy whose host resolves only to private addresses is allowed and doesn't trigger this error | Add the gateway host to `NO_PROXY` on the developer's machine so the connection is direct, or use a proxy whose hostname resolves to private addresses. The message names the exact `NO_PROXY` entry to add |
+| CLI `/login`: `Claude Code only signs in to from inside its declared network (managed settings), and this machine is connecting from , outside it` | The gateway is on a block declared in [`gatewayInternalNetworks`](/docs/en/claude-apps-gateway#allow-a-gateway-on-public-address-space-you-own), and the developer's machine reached it from an address outside that block: a VPN address pool, a container or WSL2 NAT segment, or a network that isn't yours | Have the developer run `/login` from the host OS on your network. If the address shown is also your organization's own public space, replace the gateway's entry with a block that covers both, up to `/8`; a second, overlapping entry is refused |
+| CLI `/login`: `Every address for gateway host must be inside its declared network , and it also resolves to ` | The gateway's name resolves to an address outside the block declared in [`gatewayInternalNetworks`](/docs/en/claude-apps-gateway#allow-a-gateway-on-public-address-space-you-own): a second site, or an IPv6 record on a dual-stack name. Under a declared block every record must be inside that one IPv4 block, private and IPv6 addresses included | Publish only records inside the block for the gateway name on developer machines, or serve a separate internal-only name |
+| CLI `/login`: ` is on the declared network , which Claude Code checks over a direct connection, not through an HTTP proxy` | An `HTTPS_PROXY` or `HTTP_PROXY` applies to a gateway on a declared block | On the developer's machine, add the `NO_PROXY` entry the message names |
+| CLI `/login`: a message starting `gatewayInternalNetworks in managed settings` | The value breaks one of the [validation rules](/docs/en/claude-apps-gateway#allow-a-gateway-on-public-address-space-you-own), and the message names which. Until you fix it, Claude Code refuses every new gateway `/login` on the machine, gateways on private addresses included; existing sign-ins keep working | In the managed settings source you deploy, correct the entry the message names, then rerun `/login` |
+| CLI `/login`: `Could not resolve the configured HTTP proxy` | The hostname in `HTTPS_PROXY` or `HTTP_PROXY` doesn't resolve from the developer's machine, typically because it isn't connected to the corporate network | Have the developer connect to your network or VPN and retry, or fix the proxy URL |
+| CLI `/login`: `Could not resolve gateway host ` | The machine can't resolve the gateway's internal DNS name, typically because it isn't on the corporate network | Have the developer connect to your network or VPN, then retry `/login` |
+| Boot exits with a config validation error naming `store.postgres_url` | No Postgres configured; the gateway requires Postgres | Set `store.postgres_url`. For local development, use a throwaway container: `docker run --rm -p 5432:5432 -e POSTGRES_HOST_AUTH_METHOD=trust postgres`. |
+| Boot exits: `requires the native binary` | Running under Node instead of the native binary | Install Claude Code with one of the [standalone install methods](/docs/en/setup) |
+| Boot exits with an OIDC discovery error after `config.load` | `oidc.issuer` unreachable, or TLS chain not trusted | Check the issuer is reachable from the pod and serves `/.well-known/openid-configuration`. Set `ca_cert_pem` for private PKI. If the pod reaches the IdP only through a forward proxy, set [`oidc.use_proxy: true`](/docs/en/claude-apps-gateway-config#idp-requests-through-a-forward-proxy); on versions before v2.1.227, give the pod a direct route to each of the IdP's endpoints instead. If the pod also can't resolve the IdP's hostname, or the proxy refuses `CONNECT` to an IP address, see [Proxy-only egress](/docs/en/claude-apps-gateway-config#proxy-only-egress), which requires v2.1.277 or later. |
+| Boot exits with a Postgres permission error | The database role lacks DDL rights on its schema | Grant the role `CREATE` on the gateway's schema so it can create and alter its tables at boot |
+| Log: `could not connect to Postgres at boot, attempt 1 of 3` | The database wasn't reachable yet when the gateway started, for example on a cold instance whose network is still coming up | If the gateway then finishes booting, no action is needed. When the database isn't reachable, the gateway tries the connection three times, two seconds apart, before it exits. If it exits with `could not connect to Postgres`, check `store.postgres_url` and the network path to the database. If the attempts time out rather than being refused, raise [`store.connect_timeout_seconds`](/docs/en/claude-apps-gateway-config#store) to give each one longer. |
+| `/oauth/callback` shows "Sign-in could not be completed" | Email domain rejected, id\_token validation failed, or `email_verified` is explicitly `false`, which the gateway always rejects with no override | Check `allowed_email_domains` and that the IdP returns a verified `email` claim. For `email_verified: false`, fix the IdP-side verification. If your IdP emits email under a different claim name, set `oidc.email_claim`. |
+| Log: `token exchange failed request_id=: id_token missing email claim` | The IdP isn't including `email` in the id\_token by default. This rejection fires only when `allowed_email_domains` is set; without it, a missing email mints a session with no email | Configure the IdP to emit `email` in the id\_token. Okta: add `email` to a custom authorization server's ID-token claims. Entra: add `email` as an optional claim on the app registration. PingFederate: enable an OpenID Connect Policy that emits `email`. If the IdP serves `email` from the userinfo endpoint but won't include it in the id\_token, such as the Okta org authorization server, set `oidc.userinfo_fallback: true`. |
+| Log: `refresh failed request_id=: invalid_token (…) (at userinfo_no_id_token, …)`, and developers see `Cloud gateway session expired` every `session.ttl_hours` | The IdP accepted the refresh token but returned no id\_token with it, so the gateway asked the IdP's userinfo endpoint for the user's claims. The IdP rejected the refreshed access token there. The gateway answers `temporarily_unavailable`, so Claude Code keeps the refresh token but can't renew the session. Gateway versions before v2.1.260 log the same line without the `(at …)` detail. | Set [`oidc.scope_on_refresh: true`](/docs/en/claude-apps-gateway-config#oidc), available in gateway v2.1.260 or later, so the refresh request asks for `openid` again. Some IdPs, such as Okta, return an id\_token on refresh only when asked. On PingFederate, enable **Return ID Token On Refresh Grant** under **Applications > OAuth > OpenID Connect Policy Management** instead. The key doesn't change PingFederate's behavior. For other IdPs that still omit it, check whether the userinfo endpoint accepts access tokens issued by a refresh. As a stopgap, raise [`session.ttl_hours`](/docs/en/claude-apps-gateway-config#session). See [Identity provider setup](#identity-provider-setup) for the deprovisioning tradeoff. |
+| Every Amazon Bedrock request returns 502; log shows `Could not load credentials from any providers` | On EC2, IMDSv2's default hop limit of 1 blocks the instance-metadata request from inside the container. Boot and `/readyz` pass anyway because the AWS SDK resolves instance credentials on the first request, not at client construction | Raise the hop limit with `aws ec2 modify-instance-metadata-options --instance-id --http-put-response-hop-limit 2`, or set it in the launch template. The change applies to every container on the instance. Prefer ECS task roles where available, which read credentials from the ECS container-credentials endpoint and avoid the change entirely, or apply the change on a dedicated gateway instance to limit the exposure. |
+| At peak load, responses are slow to start or appear to hang, or fail with a 502 `all upstreams failed` while the upstream is healthy | A replica has more requests open than it sends upstream at once, so the extra requests wait inside the gateway. On a `provider: anthropic` upstream, a request that waits longer than `timeouts.upstream_ttfb_ms` gives up on that upstream, which produces the 502 when no later upstream serves it. The log shows a warning that contains `client requests are open`. | Add replicas, or raise the limit on each replica. See [Concurrent upstream requests](#concurrent-upstream-requests). |
+| IdP error: unknown or unsupported scope | The IdP rejects scopes it doesn't recognize | Set `oidc.scopes` to exactly the list your IdP accepts; it must include `openid`. The default is `openid profile email offline_access`. |
+| Sessions don't silently renew after setting `oidc.scopes` | `offline_access` was dropped from the override | Add `offline_access` back if your IdP supports it. Without a refresh token, developers re-run the browser login every `session.ttl_hours`. |
+| Browser shows "This request came from another site and was blocked" | Cross-site form POST, blocked as CSRF protection. Expected for embedded or proxied pages | Open the verification link directly |
+| Chrome blocks the Approve button with "Refused to send form data … violates … Content Security Policy directive: form-action", but the same page works in Safari or Firefox | Chrome enforces `form-action` against the entire redirect chain. Your IdP redirects onward to a second host that isn't allowlisted. | Add each additional origin in the redirect chain to `oidc.form_action_origins`. Open Chrome DevTools → Console on the Approve page to see which origin was blocked. |
+| Sign-in completes at the IdP but the callback fails, with a CSP error in Chrome or "this sign-in link has expired" in Safari | The IdP returned the code via `response_mode=form_post`, which auto-submits it cross-origin via POST to `/oauth/callback`. Chrome blocks that under a strict CSP; Safari allows the submit but the callback reads only the query string. | Make sure your IdP honors `response_mode=query`, which the gateway requests explicitly so the callback is a plain redirect |
+| Login works locally but fails behind an ALB | `public_url` still names the local or inner `http://` origin, so the IdP gets the wrong `redirect_uri` | Set `listen.public_url` to the external `https://` origin and register `/oauth/callback` with the IdP |
+| Developer sees the trust prompt repeatedly | TLS cert is rotating per replica or per request | Use a stable cert at the ingress, or terminate TLS once and run replicas over plain HTTP internally |
+| CLI `/login`: "Could not verify the gateway's TLS certificate" or `SELF_SIGNED_CERT_IN_CHAIN` | Gateway's TLS chain is signed by a private CA not in the CLI host's trust store | Claude Code reads the OS trust store by default on the native binary and on Node 22.15 or later; [`CLAUDE_CODE_CERT_STORE`](/docs/en/network-config#ca-certificate-store) controls this behavior. If the CA is installed in the OS trust store, ensure developers are on a current runtime. Otherwise set `NODE_EXTRA_CA_CERTS` to the CA certificate PEM before launching. The first-connect fingerprint prompt still applies. |
+| CLI `/login` completes the browser sign-in, then the session ends with `Cloud gateway sign-in was not completed` and a TLS certificate mismatch | On the first request after sign-in, the gateway presented a certificate that doesn't match the fingerprint Claude Code pinned, so Claude Code kept no gateway credential. The usual causes are replicas behind one address that serve different certificates, or something on the network path that intercepts TLS. | Serve one certificate for the hostname, for example by terminating TLS once at the ingress, then have the developer run `/login` again. If that certificate differs from the pinned one, Claude Code shows the [trust prompt](/docs/en/claude-apps-gateway#connect-developers) again with a warning that the certificate changed. |
+| CLI `/login` stops with `The gateway's TLS certificate changed during sign-in: it no longer matches the one you trusted` | A sign-in request reached a server whose certificate doesn't match the one the developer accepted when `/login` started: replicas behind one address serving different certificates, TLS interception on the path, or a certificate rotation while the sign-in was in progress. | Serve one certificate for the hostname, then have the developer start the sign-in again and review the new certificate at the [trust prompt](/docs/en/claude-apps-gateway#connect-developers). |
The `Cloud gateway sign-in was not completed` message names the gateway hostname. When Claude Code has both the pinned fingerprint and the presented one, the message also shows the first 16 characters of each.
diff --git a/content/en/docs/claude-code/claude-apps-gateway-on-aws.md b/content/en/docs/claude-code/claude-apps-gateway-on-aws.md
index 70000410ed..162fe396e7 100644
--- a/content/en/docs/claude-code/claude-apps-gateway-on-aws.md
+++ b/content/en/docs/claude-code/claude-apps-gateway-on-aws.md
@@ -492,7 +492,7 @@ For gateway boot and login errors, see the platform-agnostic [troubleshooting ta
| Bedrock requests return `403 AccessDeniedException` | The account hasn't submitted Anthropic's one-time use case form, the automatic AWS Marketplace subscription that starts on the account's first invoke hasn't finished yet, or the task role's policy is missing the inference-profile or foundation-model ARNs | Submit the use case form from the Bedrock console's Model catalog; if it was just submitted or this is the account's first invoke, retry after a few minutes. Grant `bedrock:InvokeModel` and `bedrock:InvokeModelWithResponseStream` on both ARN families. |
| Bedrock returns a `ValidationException` saying on-demand throughput isn't supported | A custom `models:` entry maps to a bare foundation-model ID that the region serves only through inference profiles | Map the model to its cross-region inference profile ID (`us.anthropic.*`) instead; the built-in catalog already does this |
| ECS task stops with `ResourceInitializationError` before the gateway logs anything | The execution role can't read the Secrets Manager secrets, or the private subnets have no path to Secrets Manager or ECR | Grant `secretsmanager:GetSecretValue` on the three `gateway-` secrets' ARNs to the execution role, and provide egress via the NAT gateway, or, without one, interface endpoints for Secrets Manager, ECR, and CloudWatch Logs, which the `awslogs` driver needs at the same stage, plus an S3 gateway endpoint |
-| Gateway boot exits with a Postgres connection-timeout error | The database security group doesn't admit the gateway's security group on 5432, or the service runs outside the database's VPC; the store stops waiting after 5 seconds | Allow 5432 from the gateway's security group on the database's, and run the service in the same VPC as the DB subnet group |
+| Gateway boot exits with a Postgres connection-timeout error | The database security group doesn't admit the gateway's security group on 5432, or the service runs outside the database's VPC | Allow 5432 from the gateway's security group on the database's, and run the service in the same VPC as the DB subnet group |
| Gateway boot exits with a Postgres TLS certificate verification error | The connection string sets `sslmode=verify-full` but the image doesn't trust the RDS CA bundle: the bundle wasn't copied into the image, or `NODE_EXTRA_CA_CERTS` doesn't point at it | Add the build step's two Dockerfile lines that copy the bundle and set `NODE_EXTRA_CA_CERTS`, then rebuild, push under a new tag, and redeploy |
| Streaming responses drop mid-stream after a quiet period | A gateway older than v2.1.229 on a Bedrock or Claude Platform on AWS upstream sends nothing while the upstream is quiet, for example during extended thinking with no streamed output. The ALB closes a connection after 60 seconds with no data by default, so it cuts the stream at that gap. Gateways v2.1.229 and later keep a quiet stream under that timeout: on those upstreams the gateway emits an SSE `ping` event once about 15 seconds pass with no stream data, and on an Anthropic API upstream it relays the API's own pings | Update the gateway to v2.1.229 or later, or set the `idle_timeout.timeout_seconds` attribute to `3600`, via `modify-load-balancer-attributes` or the `load-balancer-attributes` Ingress annotation on EKS |
diff --git a/content/en/docs/claude-code/claude-apps-gateway-on-gcp.md b/content/en/docs/claude-code/claude-apps-gateway-on-gcp.md
index 135d127ca7..3779c21de1 100644
--- a/content/en/docs/claude-code/claude-apps-gateway-on-gcp.md
+++ b/content/en/docs/claude-code/claude-apps-gateway-on-gcp.md
@@ -308,7 +308,7 @@ For gateway boot and login errors, see the platform-agnostic [troubleshooting ta
| Cloud Run returns `403 Forbidden` before reaching the container | The invoker IAM check is still enabled | Deploy with `--no-invoker-iam-check`, or grant `allUsers` the `run.invoker` role with `--allow-unauthenticated` |
| `--no-invoker-iam-check` rejected with `invoker_iam_disabled is not currently available` | Blocked by `constraints/run.managed.requireInvokerIam` | Use `--allow-unauthenticated`. If Domain Restricted Sharing via `constraints/iam.allowedPolicyMemberDomains` blocks that too, use the GKE track, which exposes the gateway at the network layer with no `allUsers` binding. |
| `Container manifest type … must support amd64/linux` at deploy | Image was built on a non-amd64 host, or buildx emitted an OCI image index | Build with `--platform=linux/amd64 --provenance=false` |
-| Gateway boot exits with a Postgres connection-timeout error on Cloud Run | Service isn't attached to the VPC, or Cloud SQL has no private IP on that VPC; the store stops waiting after 5 seconds | Deploy with `--network` and `--subnet` for Direct VPC egress, and create the Cloud SQL instance with `--no-assign-ip` and `--network` pointing at the same VPC |
+| Gateway boot exits with a Postgres connection-timeout error on Cloud Run | Service isn't attached to the VPC, or Cloud SQL has no private IP on that VPC | Deploy with `--network` and `--subnet` for Direct VPC egress, and create the Cloud SQL instance with `--no-assign-ip` and `--network` pointing at the same VPC |
| Google Cloud's Agent Platform requests return `403 PERMISSION_DENIED` | Runtime isn't using the `claude-gateway` service account, or the model isn't enabled in Model Garden for the project | Set `--service-account` on Cloud Run or bind Workload Identity on GKE, and enable each Claude model in Model Garden for the target region |
| Streaming responses cut off after a fixed duration | Front-end request timeout: the load balancer backend service behind GKE Ingress defaults to 30 seconds and Cloud Run to 300 seconds | Attach a BackendConfig with a raised `timeoutSec` on GKE, or deploy with `--timeout=3600` on Cloud Run |
diff --git a/content/en/docs/claude-code/claude-code-on-the-web.md b/content/en/docs/claude-code/claude-code-on-the-web.md
index f48205c63c..200e43c631 100644
--- a/content/en/docs/claude-code/claude-code-on-the-web.md
+++ b/content/en/docs/claude-code/claude-code-on-the-web.md
@@ -250,6 +250,8 @@ You pick a cloud session's [permission mode](/docs/en/permission-modes) from the
Each session shows a diff indicator with lines added and removed, like `+42 -18`. Select it to open the diff view, leave inline comments on specific lines, and send them to Claude with your next message.
+The diff view compares the session's changes against its base branch by default. To compare against any other branch in the repository, select **Compare against** and pick one.
+
Claude Code computes these diffs, including the per-file diffs shown as Claude edits, from raw git blob content, so diff drivers and `textconv` filters configured in the repository don't apply. For a file in a repository that isn't one of the session's own checkouts, such as one cloned inside the workspace during the session, the per-file diff shows Claude's edit itself rather than a git comparison.
See [Review and iterate](/docs/en/web-quickstart#review-and-iterate) for the full walkthrough including PR creation. To have Claude monitor the PR for CI failures and review comments automatically, see [Auto-fix pull requests](#auto-fix-pull-requests).
diff --git a/content/en/docs/claude-code/claude-directory.md b/content/en/docs/claude-code/claude-directory.md
index 3d79b273a3..9296faa566 100644
--- a/content/en/docs/claude-code/claude-directory.md
+++ b/content/en/docs/claude-code/claude-directory.md
@@ -34,7 +34,7 @@ export const ClaudeExplorer = () => {
oneLiner: 'Project instructions Claude reads every session',
when: 'Loaded into context at the start of every session',
description: 'Project-specific instructions that shape how Claude works in this repository. Put your conventions, common commands, and architectural context here so Claude operates with the same assumptions your team does.',
- tips: ['Target under 200 lines. Longer files still load in full but may reduce adherence', <>CLAUDE.md loads into every session. If something only matters for specific tasks, move it to a skill or a path-scoped rule so it loads only when needed>, 'List the commands you run most, like build, test, and format, so Claude knows them without you spelling them out each time', <>Run /memory to open and edit CLAUDE.md from within a session>, <>Also works at .claude/CLAUDE.md if you prefer to keep the project root clean>],
+ tips: ['Target under 200 lines. Longer files still load in full but may reduce adherence', <>CLAUDE.md loads into every session. If something only matters for specific tasks, move it to a skill or a path-scoped rule so it loads only when needed>, 'List the commands you run most, like build, test, and format, so Claude knows them without you spelling them out each time', <>Run /memory to open and edit CLAUDE.md from within a session>, <>Also works at .claude/CLAUDE.md if you prefer to keep the project root clean>, <>If your repo already has an AGENTS.md for other coding agents, Claude Code can read that on its own or alongside CLAUDE.md>],
exampleIntro: 'This example is for a TypeScript and React project. It lists the build and test commands, the framework conventions Claude should follow, and project-specific rules like export style and file layout.',
example: `# Project conventions
@@ -1434,7 +1434,7 @@ Claude Code reads instructions, settings, skills, subagents, and memory from you
On Windows, `~/.claude` resolves to `%USERPROFILE%\.claude`. If you set [`CLAUDE_CONFIG_DIR`](/docs/en/env-vars), every `~/.claude` path on this page lives under that directory instead.
-Most users only edit `CLAUDE.md` and `settings.json`. The rest of the directory is optional: add skills, rules, or subagents as you need them.
+Most users only edit `CLAUDE.md` and `settings.json`. If your repository already has an `AGENTS.md` for other coding agents, Claude Code [can read that](/docs/en/memory#agents-md) on its own or alongside `CLAUDE.md`. The rest of the directory is optional: add skills, rules, or subagents as you need them.
## Explore the directory
@@ -1446,11 +1446,12 @@ Click files in the tree to see what each one does, when it loads, and an example
The explorer covers files you author and edit. A few related files live elsewhere:
-| File | Location | Purpose |
-| ----------------------- | -------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
-| `managed-settings.json` | System-level, varies by OS | Enterprise-enforced settings that you can't override, apart from [narrow exceptions](/docs/en/settings#security-keys-where-the-stricter-value-applies). See [where to save the file](/docs/en/managed-settings#deploy-a-managed-settings-file) and [which managed source Claude Code uses](/docs/en/managed-settings#precedence-within-the-managed-tier). |
-| `CLAUDE.local.md` | Project root | Your private preferences for this project, loaded alongside CLAUDE.md. Create it manually and add it to `.gitignore`. |
-| Installed plugins | `~/.claude/plugins` | Cloned marketplaces, installed plugin versions, and per-plugin data, managed by `claude plugin` commands. For a plugin installed from a marketplace [`command` source](/docs/en/plugin-marketplaces#command-sources) in link mode, Claude Code stores links here instead of a copy, and the plugin's files stay in the directory the command prints. A `command` source requires Claude Code v2.1.229 or later. A plugin listed by relative path in a local-directory marketplace also [loads in place](/docs/en/plugins-reference#plugin-caching-and-file-resolution) from its source directory rather than from a cache copy. See [plugin caching](/docs/en/plugins-reference#plugin-caching-and-file-resolution) for how orphaned versions are cleaned up. |
+| File | Location | Purpose |
+| ----------------------- | ------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
+| `managed-settings.json` | System-level, varies by OS | Enterprise-enforced settings that you can't override, apart from [narrow exceptions](/docs/en/settings#security-keys-where-the-stricter-value-applies). See [where to save the file](/docs/en/managed-settings#deploy-a-managed-settings-file) and [which managed source Claude Code uses](/docs/en/managed-settings#precedence-within-the-managed-tier). |
+| `CLAUDE.local.md` | Project root | Your private preferences for this project, loaded alongside CLAUDE.md. Create it manually and add it to `.gitignore`. |
+| `AGENTS.md` | Project root, `.claude/`, or any directory | Project instructions you write for AI coding agents. Claude Code can [load it](/docs/en/memory#agents-md) on its own or alongside `CLAUDE.md`. |
+| Installed plugins | `~/.claude/plugins` | Cloned marketplaces, installed plugin versions, and per-plugin data, managed by `claude plugin` commands. For a plugin installed from a marketplace [`command` source](/docs/en/plugin-marketplaces#command-sources) in link mode, Claude Code stores links here instead of a copy, and the plugin's files stay in the directory the command prints. A `command` source requires Claude Code v2.1.229 or later. A plugin listed by relative path in a local-directory marketplace also [loads in place](/docs/en/plugins-reference#plugin-caching-and-file-resolution) from its source directory rather than from a cache copy. See [plugin caching](/docs/en/plugins-reference#plugin-caching-and-file-resolution) for how orphaned versions are cleaned up. |
`~/.claude` also holds data Claude Code writes as you work: transcripts, prompt history, file snapshots, caches, and logs. See [application data](#application-data) below.
diff --git a/content/en/docs/claude-code/cloud-environments.md b/content/en/docs/claude-code/cloud-environments.md
index a82f9f5da5..6bbeeffa14 100644
--- a/content/en/docs/claude-code/cloud-environments.md
+++ b/content/en/docs/claude-code/cloud-environments.md
@@ -144,7 +144,7 @@ A [self-hosted environment](/docs/en/self-hosted-environments) ID, which has the
### Archive an environment
-To archive an environment, open it for editing and select **Archive**. You can't delete an environment, only archive it.
+To archive one of your own environments, open it for editing and select **Archive**. An Owner archives a [shared environment](#organization-shared-environments) from the **Cloud environments** page in admin settings. You can't delete an environment, only archive it.
Archiving affects new sessions, not running ones:
@@ -155,9 +155,16 @@ Archiving affects new sessions, not running ones:
### Organization-shared environments
-On Team and Enterprise plans, an Owner can create cloud environments that are shared with every member of the organization. The same role manages everything else on the **Cloud environments** admin page, including [self-hosted environments](/docs/en/self-hosted-environments); the Admin role can't open the page. The full list of roles that can open it is the one for [managing server-managed settings](/docs/en/server-managed-settings#access-control). Shared environments appear in each member's environment selector alongside their personal ones, so a team can standardize on one configuration instead of each member recreating it.
+On Team and Enterprise plans, an Owner can create cloud environments that are shared with every member of the organization. The same role manages everything else on the **Cloud environments** admin page, including [self-hosted environments](/docs/en/self-hosted-environments); the Admin role can't open the page. The full list of roles that can open it is the one for [managing server-managed settings](/docs/en/server-managed-settings#access-control).
-Create, edit, and archive shared environments from the **Cloud environments** page in [admin settings](https://claude.ai/admin-settings). A shared environment also opens from the [environment selector](#configure-your-environment) at [claude.ai/code](https://claude.ai/code): an Owner can edit it there. Other members see it read-only. Each shared environment has a name, a [network access level](#access-levels), [environment variables](#set-environment-variables) in `.env` format, and a [setup script](#setup-scripts). Owners choose the organization's [default environment](#the-default-environment) separately, at [claude.ai/admin-settings/claude-code](https://claude.ai/admin-settings/claude-code).
+Shared environments appear in each member's [environment selector](#configure-your-environment) under an **Organization** heading, after the member's own environments under **Personal**, so a team can standardize on one configuration instead of each member recreating it. Selecting a shared environment's settings icon there opens a read-only summary of its configuration for every member, Owners included.
+
+An Owner makes an environment available to the organization in one of two ways:
+
+* **Create a shared environment**: use the **Cloud environments** page in [admin settings](https://claude.ai/admin-settings), which is also where Owners edit and archive shared environments. Each one has a name, a [network access level](#access-levels), [environment variables](#set-environment-variables) in `.env` format, and a [setup script](#setup-scripts).
+* **Share a personal environment**: open one of your own environments for editing in the environment selector, then share it from the **Who can use it** row. The environment keeps its ID, so sessions and routines that already use it aren't affected, and every member can then see it and start sessions in it.
+
+Owners choose the organization's [default environment](#the-default-environment) separately, at [claude.ai/admin-settings/claude-code](https://claude.ai/admin-settings/claude-code).
Every member's sessions in a shared environment read its variables, so don't include secrets in them. [API credentials](#add-api-credentials), which give sessions a key they can't read, aren't available on Team or Enterprise plans yet.
@@ -172,7 +179,7 @@ In [Claude Tag](https://claude.com/docs/claude-tag/overview) channels, Claude wo
Each environment sets one network access level, which controls the outbound connections its sessions can make. The default level, **Trusted**, allows package registries and other [allowlisted domains](#default-allowed-domains); **Custom** takes your own domain list.
-To change an environment's network access, [open it for editing](#configure-your-environment) and use the **Network access** selector in the dialog. The cloud icon that opens the selector appears on the app surfaces listed under [The Default environment](#the-default-environment) and in the [routine editor](/docs/en/routines#environments-and-network-access); personal environments don't have a separate page in your claude.ai account settings.
+To change an environment's network access, [open it for editing](#configure-your-environment) and use the **Network access** selector in the dialog. A [shared environment](#organization-shared-environments) opens read-only there, so an Owner changes its network access from the **Cloud environments** page in [admin settings](https://claude.ai/admin-settings) instead. The cloud icon that opens the selector appears on the app surfaces listed under [The Default environment](#the-default-environment) and in the [routine editor](/docs/en/routines#environments-and-network-access); personal environments don't have a separate page in your claude.ai account settings.
MCP connectors you enable on a session or routine work without adding their hosts to **Allowed domains**, because connector traffic travels through Anthropic's servers rather than the session's network. This relies on the same Anthropic-bound channel noted under [Security and isolation](/docs/en/claude-code-on-the-web#security-and-isolation). Turn off any connector you don't need to limit which tools Claude can reach.
@@ -314,7 +321,7 @@ GitHub's [`gh` CLI](https://cli.github.com) is pre-installed. If you need a `gh`
Each cloud session has a transcript URL on claude.ai, and the session can read its own ID from the `CLAUDE_CODE_REMOTE_SESSION_ID` environment variable. Use this to put a traceable link in PR bodies, commit messages, Slack posts, or generated reports so a reviewer can open the run that produced them.
-Commits that Claude creates in a cloud session include a `Claude-Session: ` git trailer, and PR bodies include the session URL on its own line. To omit the trailer and the PR-body link, set [`attribution.sessionUrl`](/docs/en/settings-reference#attribution-sessionurl) to `false`. The setting requires v2.1.182 or later.
+Commits that Claude creates in a cloud session include a `Claude-Session: ` git trailer, and PR bodies include the session URL on its own line. To omit the trailer and the PR-body link, set [`attribution.sessionUrl`](/docs/en/settings-reference#attribution-sessionurl) to `false`.
To include the session link in something other than a commit or PR, such as a Slack message Claude posts or a report file it writes, have Claude run the following command and use its output. The command converts the `cse_` prefix in the environment variable's value to the `session_` prefix that the transcript URL expects:
diff --git a/content/en/docs/claude-code/commands.md b/content/en/docs/claude-code/commands.md
index 9a45eb29fc..977ef25853 100644
--- a/content/en/docs/claude-code/commands.md
+++ b/content/en/docs/claude-code/commands.md
@@ -68,7 +68,7 @@ In the table below, `` indicates a required argument and `[arg]` indicates
| `/code-review [low\|medium\|high\|xhigh\|max\|ultra] [--fix] [--comment] [pr#\|branch\|path]` | **[Skill](/docs/en/skills#bundled-skills).** Review the current diff, or a PR number, branch, or path you pass, for correctness bugs and cleanup opportunities. Pass `--fix` to apply findings, `--comment` to post them on the GitHub PR or GitLab merge request, or `ultra` to run a deep [cloud review](/docs/en/ultrareview). Posting to a GitLab merge request requires Claude Code v2.1.257 or later. With `ultra` on a `github.com` PR target, pass `--post` to preselect [posting the finished findings to the PR](/docs/en/ultrareview#post-findings-to-the-pull-request) in the launch dialog; `--post` requires Claude Code v2.1.227 or later. See [Review a diff locally](/docs/en/code-review#review-a-diff-locally) for the effort levels, targeting, and how it relates to `/simplify`. Alias: `/review` |
| `/color [color\|default]` | Set the prompt bar color for the current session. Available colors: `red`, `blue`, `green`, `yellow`, `purple`, `orange`, `pink`, `cyan`. Use `default` to reset, or run with no argument to pick a random color. When [Remote Control](/docs/en/remote-control) is connected, the color syncs to claude.ai/code. Also available in non-interactive mode (`-p`); requires Claude Code v2.1.205 or later |
| `/compact [instructions]` | Free up context by summarizing the conversation so far. Optionally pass focus instructions for the summary. See [how compaction handles rules, skills, and memory files](/docs/en/context-window#what-survives-compaction) |
-| `/config [key=value ...]` | Open the [Settings](/docs/en/settings) interface to adjust theme, model, [output style](/docs/en/output-styles), and other preferences. Pass one or more `key=value` pairs to set a setting directly without opening the interface, for example `/config thinking=false`. From v2.1.182, named shorthand keys are also accepted, such as `/config theme=dark` or `/config model=sonnet`. The `key=value` form also works in non-interactive mode (`-p`) and from the Claude mobile app via [Remote Control](/docs/en/remote-control). The `key=value` form can't turn on a setting that needs your confirmation in the panel, such as [`autoContinueAtUsageLimit`](/docs/en/interactive-mode#turn-automatic-continue-off), though it can turn one off. Run `/config --help` to list the keys it accepts. Alias: `/settings` |
+| `/config [key=value ...]` | Open the [Settings](/docs/en/settings) interface to adjust theme, model, [output style](/docs/en/output-styles), and other preferences. Pass one or more `key=value` pairs to set a setting directly without opening the interface, for example `/config thinking=false`, `/config theme=dark`, or `/config model=sonnet`. The `key=value` form also works in non-interactive mode (`-p`) and from the Claude mobile app via [Remote Control](/docs/en/remote-control). The `key=value` form can't turn on a setting that needs your confirmation in the panel, such as [`autoContinueAtUsageLimit`](/docs/en/interactive-mode#turn-automatic-continue-off), though it can turn one off. Run `/config --help` to list the keys it accepts. Alias: `/settings` |
| `/context [all]` | Visualize current context usage as a colored grid. Shows optimization suggestions for context-heavy tools, memory bloat, and capacity warnings. When the conversation exceeds the context window, the output includes a [warning](/docs/en/errors#context-exceeds-the-token-limit) showing how far over the limit you are and which command frees space. In [fullscreen mode](/docs/en/fullscreen), `/context` collapses the per-item breakdown to keep the grid visible. Pass `all` to expand it |
| `/copy [N]` | Copy the last assistant response to clipboard. Pass a number `N` to copy the Nth-latest response: `/copy 2` copies the second-to-last. When code blocks are present, shows an interactive picker to select individual blocks or the full response. Press `w` in the picker to write the selection to a file instead of the clipboard, which is useful over SSH |
| `/cost` | Alias for `/usage` |
diff --git a/content/en/docs/claude-code/context-window.md b/content/en/docs/claude-code/context-window.md
index fad79616c0..d0fd6fdcb5 100644
--- a/content/en/docs/claude-code/context-window.md
+++ b/content/en/docs/claude-code/context-window.md
@@ -1584,7 +1584,7 @@ Claude Code's context window holds everything Claude knows about your session: y
The session walks through a realistic flow with representative token counts:
-* **Before you type anything**: CLAUDE.md, auto memory, MCP tool names, and skill descriptions all load into context. Your own setup may add more here, like an [output style](/docs/en/output-styles) or text from [`--append-system-prompt`](/docs/en/cli-reference).
+* **Before you type anything**: CLAUDE.md, auto memory, MCP tool names, and skill descriptions all load into context. [AGENTS.md files](/docs/en/memory#agents-md) can load too, on their own or alongside CLAUDE.md. Your own setup may add more here, like an [output style](/docs/en/output-styles) or text from [`--append-system-prompt`](/docs/en/cli-reference).
* **As Claude works**: each file read adds to context, [path-scoped rules](/docs/en/memory#path-specific-rules) load automatically alongside matching files, and a [PostToolUse hook](/docs/en/hooks-guide) fires after each edit.
* **The follow-up prompt**: a [subagent](/docs/en/sub-agents) handles the research in its own separate context window, so the large file reads stay out of yours. Only the summary and a small metadata trailer come back.
* **At the end**: `/compact` replaces the conversation with a structured summary. Most startup content reloads automatically; the table below shows what happens to each mechanism.
diff --git a/content/en/docs/claude-code/corporate-launcher.md b/content/en/docs/claude-code/corporate-launcher.md
index 90ba5d9a11..372228bff9 100644
--- a/content/en/docs/claude-code/corporate-launcher.md
+++ b/content/en/docs/claude-code/corporate-launcher.md
@@ -10,7 +10,7 @@ Some organizations require every process on a workstation to start through a man
`CLAUDE_CODE_PROCESS_WRAPPER` starts every process Claude Code launches from its own binary through your launcher: the background service, every session it hosts in [agent view](/docs/en/agent-view), and Claude Code's relaunches after an update. Set it to your launcher's absolute path, and Claude Code runs the launcher with the Claude Code command as its arguments.
-A launcher that wraps the `claude` command on your `PATH` can't reach these processes, because they start from the binary's direct path without looking up `claude`.
+A launcher that wraps the `claude` command on your `PATH` can't reach the background service or the sessions it hosts, because they start from the binary's direct path without looking up `claude`.
`CLAUDE_CODE_PROCESS_WRAPPER` requires Claude Code v2.1.208 or later. Earlier versions ignore the variable and start every process unwrapped. The equivalent [`processWrapper` setting](/docs/en/settings-reference#processwrapper) requires v2.1.210 or later. Earlier versions ignore it as an unknown key, apply no launcher, and report no error.
@@ -36,7 +36,7 @@ On Windows, the variable is ignored: the launcher contract depends on `exec`, wh
The following processes don't start through the launcher:
* An [installed background service](/docs/en/agent-view#the-supervisor-process) whose unit was written before the launcher was configured: `launchd` or `systemd` starts that process from its unit file. `/status` and `claude daemon status` warn while the running service and the configured launcher don't match, and the sessions the service spawns still start through the launcher once the service restarts with the variable in its settings.
-* A session you start yourself in a terminal, which runs however you invoked it. To cover these sessions, put a script named `claude` in a directory earlier on `PATH` that runs your launcher with the real binary; don't replace the managed symlink. Self-spawns don't consult `PATH`, so the two launchers never stack.
+* A session you start yourself in a terminal, which runs however you invoked it. To cover these sessions, put a script named `claude` in a directory earlier on `PATH` that runs your launcher with the real binary; don't replace the managed symlink. The background service and its sessions start without a `PATH` lookup, so the two launchers don't stack there.
* The first process of a `claude-cli://` deep link, which the operating system's protocol handler starts directly. Everything that session starts in the background afterward runs through the launcher. To close this path entirely, [prevent handler registration](/docs/en/deep-links#registration-and-supported-platforms) with the `disableDeepLinkRegistration` setting.
* The relaunch that `--worktree` combined with `--tmux` performs: the terminal multiplexer starts that pane, not Claude Code's binary.
* The native-messaging host that [Claude in Chrome](/docs/en/chrome) registers: the browser starts it, not Claude Code's binary.
diff --git a/content/en/docs/claude-code/desktop-changelog.md b/content/en/docs/claude-code/desktop-changelog.md
index ca2a3c3e99..dabc47413d 100644
--- a/content/en/docs/claude-code/desktop-changelog.md
+++ b/content/en/docs/claude-code/desktop-changelog.md
@@ -206,15 +206,15 @@ Right-click any file path in the chat, diff viewer, or file pane to open a conte
### Switch view modes
-View modes control how much detail appears in the chat transcript. Switch modes from the **Transcript view** dropdown next to the send button, or press **Ctrl+O** on macOS or Windows to cycle through them.
+View modes control how much detail appears in the chat transcript. Switch modes from the **Transcript view** dropdown next to the send button, or press **Ctrl+O** on macOS or Windows to cycle through them. The Thinking mode appears in the dropdown only after Claude has produced thinking in the session you're viewing.
-| Mode | What it shows |
-| ----------- | -------------------------------------------------------------- |
-| **Normal** | Tool calls collapsed into summaries, with full text responses |
-| **Verbose** | Every tool call, file read, and intermediate step Claude takes |
-| **Summary** | Only Claude's final responses and the changes it made |
+| Mode | What it shows |
+| ------------ | -------------------------------------------------------------------------------------- |
+| **Normal** | Tool calls collapsed into summaries, with full text responses |
+| **Thinking** | Tool calls collapsed into summaries, plus Claude's thinking |
+| **Verbose** | Every tool call, file read, and intermediate step Claude takes, plus Claude's thinking |
-Use Verbose when debugging why Claude took a particular action. Use Summary when you're running multiple sessions and want to scan results quickly.
+Use Thinking to follow Claude's reasoning with tool calls still collapsed. Use Verbose when debugging why Claude took a particular action. Claude Desktop versions before 1.46388.1 also list a Summary mode, and a session still set to Summary opens in Normal once you update.
### Keyboard shortcuts
diff --git a/content/en/docs/claude-code/desktop.md b/content/en/docs/claude-code/desktop.md
index ca2a3c3e99..dabc47413d 100644
--- a/content/en/docs/claude-code/desktop.md
+++ b/content/en/docs/claude-code/desktop.md
@@ -206,15 +206,15 @@ Right-click any file path in the chat, diff viewer, or file pane to open a conte
### Switch view modes
-View modes control how much detail appears in the chat transcript. Switch modes from the **Transcript view** dropdown next to the send button, or press **Ctrl+O** on macOS or Windows to cycle through them.
+View modes control how much detail appears in the chat transcript. Switch modes from the **Transcript view** dropdown next to the send button, or press **Ctrl+O** on macOS or Windows to cycle through them. The Thinking mode appears in the dropdown only after Claude has produced thinking in the session you're viewing.
-| Mode | What it shows |
-| ----------- | -------------------------------------------------------------- |
-| **Normal** | Tool calls collapsed into summaries, with full text responses |
-| **Verbose** | Every tool call, file read, and intermediate step Claude takes |
-| **Summary** | Only Claude's final responses and the changes it made |
+| Mode | What it shows |
+| ------------ | -------------------------------------------------------------------------------------- |
+| **Normal** | Tool calls collapsed into summaries, with full text responses |
+| **Thinking** | Tool calls collapsed into summaries, plus Claude's thinking |
+| **Verbose** | Every tool call, file read, and intermediate step Claude takes, plus Claude's thinking |
-Use Verbose when debugging why Claude took a particular action. Use Summary when you're running multiple sessions and want to scan results quickly.
+Use Thinking to follow Claude's reasoning with tool calls still collapsed. Use Verbose when debugging why Claude took a particular action. Claude Desktop versions before 1.46388.1 also list a Summary mode, and a session still set to Summary opens in Normal once you update.
### Keyboard shortcuts
diff --git a/content/en/docs/claude-code/env-vars.md b/content/en/docs/claude-code/env-vars.md
index adb1dad4d5..a919fcaf96 100644
--- a/content/en/docs/claude-code/env-vars.md
+++ b/content/en/docs/claude-code/env-vars.md
@@ -213,7 +213,7 @@ Numeric variables such as timeouts, token budgets, and retry counts accept scien
| `CLAUDE_CODE_AUTO_BACKGROUND_WORKER_CHECKIN_SECONDS` | When `CLAUDE_AUTO_BACKGROUND_TASKS` is enabled, seconds between reminders to Claude to check on [background subagents](/docs/en/sub-agents#run-subagents-in-foreground-or-background) that are still running. Accepts a plain integer from `1` to `86400` only; any other value or spelling reads as unset. When unset, there are no check-in reminders. Requires Claude Code v2.1.248 or later |
| `CLAUDE_CODE_AUTO_COMPACT_WINDOW` | Set the [auto-compact window](/docs/en/model-config#set-the-auto-compact-window) in tokens, from `100000` to `1000000`. Accepts a plain integer such as `500000` only: a value like `500k` reads as `500` and clamps to the 100K minimum. The effective window is also capped at the model's context window. Takes precedence over the `/autocompact` command, the `--autocompact` flag, and the `autoCompactWindow` setting. The status line's `used_percentage` always measures against the model's full context window, so once this variable is set, that percentage no longer indicates when compaction will run |
| `CLAUDE_CODE_AUTO_CONNECT_IDE` | Override automatic [IDE connection](/docs/en/vs-code). By default, Claude Code connects automatically when launched inside a supported IDE's integrated terminal. Set to `false` to prevent this. Set to `true` to force a connection attempt when auto-detection fails, such as when tmux obscures the parent terminal. Takes precedence over the [`autoConnectIde`](/docs/en/settings-reference#autoconnectide) global config setting |
-| `CLAUDE_CODE_AUTO_MODE_SERVER` | On Amazon Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry, set to `1` to have the platform's server-side classifier review [auto mode](/docs/en/permission-modes#eliminate-prompts-with-auto-mode) actions; where the platform doesn't run the classifier, Claude Code falls back to its own classifier requests. When unset or `0`, the classifier runs through requests that Claude Code itself sends. Has no effect on other providers, including the Anthropic API. Requires Claude Code v2.1.271 or later |
+| `CLAUDE_CODE_AUTO_MODE_SERVER` | Controls whether Claude Code asks the server to [review auto mode actions](/docs/en/permission-modes#server-side-classifier-review). When unset, Claude Code asks the server on Amazon Bedrock, Google Cloud's Agent Platform, Microsoft Foundry, and Claude Platform on AWS, and when you point `ANTHROPIC_BASE_URL` at an LLM gateway or proxy. Set to `0` to use Claude Code's own classifier requests instead. Not read on a direct connection to the Anthropic API. Requires Claude Code v2.1.271 or later; asking the server by default requires v2.1.278 or later |
| `CLAUDE_CODE_AWS_CHAIN_RESOLVE_TIMEOUT_MS` | Time in milliseconds Claude Code waits for the AWS default credential provider chain to produce credentials before the request fails with [`AWS default-chain credential resolve timed out`](/docs/en/errors#aws-default-chain-credential-resolve-timed-out) (default: `60000`). Raise it when a step in your chain legitimately needs longer, such as a browser-based SSO sign-in with MFA through a wrapper like `aws-vault`. Applies wherever Claude Code signs with the default chain: [Amazon Bedrock](/docs/en/amazon-bedrock#credential-caching-and-resolution-timeout), [Claude Platform on AWS](/docs/en/claude-platform-on-aws), and the [Mantle endpoint](/docs/en/amazon-bedrock#use-the-mantle-endpoint). Requires Claude Code v2.1.207 or later |
| `CLAUDE_CODE_BASH_EDIT_DIFF` | Set to `0` to turn off the [diff of the files a Bash command changed](/docs/en/hooks#bash), or `1` to record it in every permission mode. Takes precedence over the [`bashEditDiffEnabled`](/docs/en/settings-reference#basheditdiffenabled) setting. Requires Claude Code v2.1.269 or later |
| `CLAUDE_CODE_BG_TASKS_REPORT_RUNNING` | Set to `0` to make a non-interactive session report an idle status to its host at every turn end, even while background work is still running. By default, the session keeps reporting a running status past turn end while background work such as a background agent or a [workflow](/docs/en/workflows) run is still live. This keeps a host that watches the status, such as a remote session list, from announcing that Claude is waiting for your input mid-work. Background shell commands, such as a dev server, don't hold the running status. The running-status default and the `0` opt-out require Claude Code v2.1.269 or later; on earlier versions, set `1` to hold the running status |
@@ -509,6 +509,7 @@ Claude Code turns some features on through feature flags it fetches from Anthrop
With fetching off, you can't:
+* Have Claude Code [read `AGENTS.md` files](/docs/en/memory#agents-md) as project instructions; it loads `CLAUDE.md` files only
* [Start sessions in auto mode by default](/docs/en/permission-modes#which-mode-a-session-starts-in) on Pro, Max, and Team plans
* Have the VS Code extension [read settings files for the starting permission mode](/docs/en/permission-modes#switch-permission-modes)
* Run [`/auto-mode-setup`](/docs/en/auto-mode-config#generate-environment-entries) to draft `autoMode.environment` entries
diff --git a/content/en/docs/claude-code/errors.md b/content/en/docs/claude-code/errors.md
index 510a2082aa..bca747be45 100644
--- a/content/en/docs/claude-code/errors.md
+++ b/content/en/docs/claude-code/errors.md
@@ -230,6 +230,7 @@ Match the message you see to a section below.
| `Refusing to send: connected endpoint is a different process with the expected pid` | [Tool errors](#refusing-to-send-a-cross-session-message) |
| `Refusing to read : its symlink resolution changed after permission was checked ()` / `Refusing to search : its symlink resolution changed after permission was checked` | [Tool errors](#refusing-after-a-symlink-changed) |
| `Refusing to write : its parent-directory symlink resolution changed after permission was checked` / `Refusing to write : it is a symbolic link. Write to the link's target path instead` | [Tool errors](#refusing-after-a-symlink-changed) |
+| `Refusing to write through symlink: ` / `Refusing to write into symlinked directory: ` | [Tool errors](#refusing-after-a-symlink-changed) |
| `Refusing to search : a path one of its Read deny rules is written through changed while the search was being prepared` / `Refusing to search : it could not be opened` | [Tool errors](#refusing-after-a-symlink-changed) |
| `its permission check expired before it ran (too many concurrent file operations)` / `ripgrep was found only by name on PATH` | [Tool errors](#refusing-after-a-symlink-changed) |
| `task output swap refused (tasks dir moved or linked)` | [Tool errors](#task-output-swap-refused) |
@@ -1623,6 +1624,8 @@ This is not a client-side network problem. Cloud sessions and [routines](/docs/e
**What to do:**
+These steps change one of your own environments. An [organization-shared environment](/docs/en/cloud-environments#organization-shared-environments) opens read-only in the selector, so ask an Owner to change its network access from the **Cloud environments** page in [admin settings](https://claude.ai/admin-settings).
+
* Open the routine for editing, or start a cloud session. Select the cloud icon showing your environment's name, such as **Default**, to open the selector. Hover over your environment and click the settings icon.
* In the **Update cloud environment** dialog, change **Network access** from **Trusted** to **Custom**, then add the blocked domain to **Allowed domains**. Enter one domain per line. Check **Also include default list of common package managers** to keep the [default allowlist](/docs/en/cloud-environments#default-allowed-domains) alongside your custom domains. Select **Full** instead if you want unrestricted access.
* Click **Save changes**. The next run uses the updated allowlist.
@@ -3408,11 +3411,13 @@ Claude Code checks a file path's [permission rules](/docs/en/permissions#read-an
Refusing to read /path/to/file: its symlink resolution changed after permission was checked (a link on the way now leads somewhere the check did not see). If a link in the working directory is being rewritten concurrently, stop that and retry.
```
-The text after the path names the reason:
+Each refusal names its reason:
* `its symlink resolution changed after permission was checked`: a symlink along the path, or at a Grep or Glob search root, was replaced between the permission check and the operation. In a read refusal, the parenthesized phrase names which comparison failed.
* `its parent-directory symlink resolution changed after permission was checked`: a directory the write path passes through no longer resolves to the approved location
-* `it is a symbolic link. Write to the link's target path instead`: a symbolic link sits at the approved write location itself
+* `it is a symbolic link. Write to the link's target path instead`: a symbolic link sits at the approved write location itself, for example a `CLAUDE.md` that is a symlink to `AGENTS.md`; the message directs Claude to the link's target
+* `Refusing to write through symlink: . Resolve the symlink and pass the real target path explicitly.`: the same condition caught when another writer opens the file, such as a write to a symlinked `.mcp.json`
+* `Refusing to write into symlinked directory: `: the directory that holds the file is itself a symbolic link, for example a project's `.claude/` directory linked to another location
* `a path one of its Read deny rules is written through changed while the search was being prepared. Retry.`: a `Read` deny rule for the search names a path that passes through a symlink, and that link changed while Claude Code was preparing the search
* `it could not be opened (EACCES) — it is unreadable, or is being replaced concurrently.`: the search root exists but couldn't be opened; the parenthesized code is the operating system error
* `its permission check expired before it ran (too many concurrent file operations). Retry.`: Claude Code evicted the approval record under many simultaneous file operations before the tool used it; retrying runs a fresh permission check
@@ -3426,7 +3431,7 @@ The text after the path names the reason:
* If a read refusal appears on macOS for a file that nothing is rewriting, such as a screenshot dragged into the prompt, upgrade to v2.1.273 or later
* For the ripgrep refusal, install ripgrep with your package manager so `rg` resolves to an absolute path on `PATH`, or keep searches under the working directory
-Before v2.1.251, Claude Code re-checked a path's resolution only for file writes, so a link replaced after the permission check could redirect a read or search to a different location without a message. Of these refusals, only the parent-directory write refusal appears on earlier versions.
+Before v2.1.251, Claude Code re-checked a path's resolution only for file writes, so a link replaced after the permission check could redirect a read or search to a different location without a message. Of these, only the parent-directory, through-symlink, and symlinked-directory write refusals appear on earlier versions.
Task output swap refused
diff --git a/content/en/docs/claude-code/feature-availability.md b/content/en/docs/claude-code/feature-availability.md
index 4dc3adc621..84421188a8 100644
--- a/content/en/docs/claude-code/feature-availability.md
+++ b/content/en/docs/claude-code/feature-availability.md
@@ -32,8 +32,9 @@ These work on every provider:
* [Checkpoints](/docs/en/checkpointing), [sandboxing](/docs/en/sandboxing), and [Workflows](/docs/en/workflows)
* [OpenTelemetry metrics](/docs/en/monitoring-usage) and the [managed settings file](/docs/en/managed-settings#delivery-mechanisms)
-Three of these have provider-specific differences:
+These have provider-specific differences:
+* **CLAUDE.md memory**: `CLAUDE.md` files load on every provider. Reading [`AGENTS.md` files](/docs/en/memory#agents-md) as project instructions also requires a session that [fetches feature flags](/docs/en/env-vars#features-that-need-feature-flag-fetching)
* **MCP servers**: [connectors from claude.ai](/docs/en/mcp#use-mcp-servers-from-claude-ai) load only when your claude.ai subscription is the active authentication method. [Tool search](/docs/en/mcp#configure-tool-search) is off by default when `ANTHROPIC_BASE_URL` points to a non-first-party host, and isn't supported on Google Cloud's Agent Platform models earlier than the Claude 4.5 generation or on Microsoft Foundry [deployments hosted on Azure](https://platform.claude.com/docs/en/build-with-claude/claude-in-microsoft-foundry#hosting-options)
* **Subagents**: the built-in [Explore subagent](/docs/en/sub-agents#built-in-subagents) caps its inherited model at Opus on the Claude API, and inherits the main conversation's model directly on any other provider, including Claude Platform on AWS
* **[Commands](/docs/en/commands#all-commands)**:
@@ -216,6 +217,8 @@ Organization-level controls and usage visibility.
If you authenticate through an [LLM gateway](/docs/en/llm-gateway), feature availability matches the underlying provider the gateway forwards to, except for the features Claude Code itself turns off. Whenever `ANTHROPIC_BASE_URL` points at a host other than `api.anthropic.com`, Claude Code turns off features such as [Remote Control](/docs/en/remote-control#requirements) and [server-managed settings](/docs/en/server-managed-settings#platform-availability), whatever the gateway forwards. Some Anthropic-only features such as the [Advisor](/docs/en/advisor) work only if the gateway forwards requests intact to the Anthropic API.
+
+ For how the requests Claude Code sends differ between an Amazon Bedrock- or Agent Platform-format gateway, an `ANTHROPIC_BASE_URL` gateway, and a Claude apps gateway sign-in, see [client behavior by connection method](/docs/en/llm-gateway-protocol#how-the-connection-method-changes-client-behavior).
### Summary by provider
diff --git a/content/en/docs/claude-code/glossary.md b/content/en/docs/claude-code/glossary.md
index e1bba56734..3315078360 100644
--- a/content/en/docs/claude-code/glossary.md
+++ b/content/en/docs/claude-code/glossary.md
@@ -10,6 +10,12 @@ This glossary defines Claude Code terminology. Each entry links to the page wher
## A
+### AGENTS.md
+
+A markdown file of project instructions you write for AI coding agents. If your repository has one and no [CLAUDE.md](#claude-md), Claude reads it as your project instructions without you adding a second file. You can change the **Project instructions** setting in `/config` to have Claude read both files or only `CLAUDE.md`. Reading `AGENTS.md` directly requires Claude Code v2.1.277 or later in a session that fetches feature flags; on other versions, import it from a CLAUDE.md.
+
+Learn more: [AGENTS.md](/docs/en/memory#agents-md)
+
### Agent teams
Multiple independent Claude Code sessions coordinated by a team lead, with a shared task list and peer-to-peer messaging. Unlike [subagents](#subagent), which run within a single session and report only to the parent, teammates each have their own context window and you can interact with any of them directly. Agent teams are experimental and disabled by default; see [Enable agent teams](/docs/en/agent-teams#enable-agent-teams).
@@ -90,7 +96,7 @@ Learn more: [The `.claude` directory](/docs/en/claude-directory)
A markdown file of persistent instructions you write for Claude, loaded at the start of every session as a user message after the system prompt. Put project conventions, architecture notes, and "always do X" rules here. Project-root CLAUDE.md survives [compaction](#compaction) and is re-read fresh from disk afterward.
-You can place CLAUDE.md at project scope in `./CLAUDE.md` or `./.claude/CLAUDE.md`, at user scope in `~/.claude/CLAUDE.md`, or as [managed policy](#managed-settings) for your organization. All discovered files are concatenated into context rather than overriding each other, ordered from broadest scope to most specific.
+You can place CLAUDE.md at project scope in `./CLAUDE.md` or `./.claude/CLAUDE.md`, at user scope in `~/.claude/CLAUDE.md`, or as [managed policy](#managed-settings) for your organization. All discovered files are concatenated into context rather than overriding each other, ordered from broadest scope to most specific. Claude Code can also load a project's [AGENTS.md](#agents-md) files, on their own or alongside CLAUDE.md.
Learn more: [CLAUDE.md files](/docs/en/memory#claude-md-files)
diff --git a/content/en/docs/claude-code/headless.md b/content/en/docs/claude-code/headless.md
index 3212ef1106..b5df24c5c6 100644
--- a/content/en/docs/claude-code/headless.md
+++ b/content/en/docs/claude-code/headless.md
@@ -314,7 +314,7 @@ The `--allowedTools` flag uses [permission rule syntax](/docs/en/settings-refere
* User-invoked [skills](/docs/en/skills) and custom commands work. Include `/skill-name` in the prompt string and Claude Code expands it before running.
* Built-in commands that only run in the terminal interface, such as `/login`, aren't available.
* `/model`, `/effort`, `/fast`, `/color`, and `/rename` accept the value as an argument, for example `/model sonnet`, and `/mcp` with no argument prints a text summary of server status. These forms require Claude Code v2.1.205 or later and follow each command's [availability notes](/docs/en/commands#all-commands).
- * To change a setting, pass `key=value` to `/config`, for example `/config thinking=false`. Requires Claude Code v2.1.181 or later.
+ * To change a setting, pass `key=value` to `/config`, for example `/config thinking=false`.
* `/output-style