diff --git a/content/.metadata.json b/content/.metadata.json index 6b4859c18..a34c46a16 100644 --- a/content/.metadata.json +++ b/content/.metadata.json @@ -1,7 +1,7 @@ { "metadata": { "version": "2.0", - "fetch_date": "2026-09-04T18:39:53.285419Z", + "fetch_date": "2026-09-05T05:01:20.213203Z", "section": "all" }, "items": [ @@ -835,8 +835,8 @@ "url": "https://platform.claude.com/docs/en/manage-claude/workload-identity-federation", "status": "success", "path": "en/manage-claude/workload-identity-federation.md", - "sha256": "ea5b1da2e7bb2d8c11315f5d29c947af3ccdddcabcb6bf3f094bbe69e05af8ad", - "size": 25683 + "sha256": "6b4af6c6d56a3511216e74e9f009bdd3caa54acc2efda228019c980f660523b2", + "size": 25696 }, { "url": "https://platform.claude.com/docs/en/manage-claude/wif-admin-api", @@ -856,36 +856,36 @@ "url": "https://platform.claude.com/docs/en/manage-claude/wif-providers/aws", "status": "success", "path": "en/manage-claude/wif-providers/aws.md", - "sha256": "9c097b02cadeff891d46fda2a9a43d637df60fc30e06bb2c17423c911dc54db1", - "size": 32388 + "sha256": "9d18c12a63196297f85c2e25dc7007d82d0b5c6465c6f1838f68ec529e34ba77", + "size": 32578 }, { "url": "https://platform.claude.com/docs/en/manage-claude/wif-providers/gcp", "status": "success", "path": "en/manage-claude/wif-providers/gcp.md", - "sha256": "5c104d2f5bb7f6bbd30606196c878ee8156bd422525f64fb87af274da72a5f36", - "size": 20282 + "sha256": "ad5bd2da6d8f745f51dfc88ab53a172d43b22fba007f71212a55ffa80ab5dd2c", + "size": 20355 }, { "url": "https://platform.claude.com/docs/en/manage-claude/wif-providers/azure", "status": "success", "path": "en/manage-claude/wif-providers/azure.md", - "sha256": "2c6cf9d6a7a7dc3e05755c700ef2c39dfd3c7079206e0b2b51e59873fad3727e", - "size": 64832 + "sha256": "952202dd6887403d9a88e6fd385834a36f495c73cd33536fe2d20c2acfccfa6a", + "size": 64978 }, { "url": "https://platform.claude.com/docs/en/manage-claude/wif-providers/github-actions", "status": "success", "path": "en/manage-claude/wif-providers/github-actions.md", - "sha256": "0013cf9776f628177eb67ee7c1999fbe581715ed76b3078b38b6c7fe630e62e9", - "size": 14448 + "sha256": "1740710960061c0a3ab53bcb5a6ddd2dc3bd4b62787d3ed27f7db16a18c54e4a", + "size": 14488 }, { "url": "https://platform.claude.com/docs/en/manage-claude/wif-providers/kubernetes", "status": "success", "path": "en/manage-claude/wif-providers/kubernetes.md", - "sha256": "8b13fb2a457db389eab5e11bbd9879b50735bf7d8f54de0e556b554c90b1beed", - "size": 14353 + "sha256": "3d9cf3406a76ef9771429eed7669dc7e5672323d53fa9de62be75661ac45aa2e", + "size": 14395 }, { "url": "https://platform.claude.com/docs/en/manage-claude/wif-providers/spiffe", @@ -898,8 +898,8 @@ "url": "https://platform.claude.com/docs/en/manage-claude/wif-providers/okta", "status": "success", "path": "en/manage-claude/wif-providers/okta.md", - "sha256": "f8d7bd9a6c68149366b1e89c8a3a86d6a96dd705441a157c161a58681378fcda", - "size": 21913 + "sha256": "98559fe1ee99ef5651d6e7da3e8d0d88d5f96ba3115d1c824a8d0ce35bbecf53", + "size": 21986 }, { "url": "https://platform.claude.com/docs/en/manage-claude/usage-cost-api", @@ -1549,7 +1549,7 @@ "url": "https://platform.claude.com/docs/en/cli-sdks-libraries/cli/quickstart", "status": "success", "path": "en/cli-sdks-libraries/cli/quickstart.md", - "sha256": "d04b90d6b800143c45b9198e0423682b9aedf6f5776ea2ff48f907226dc3ba49", + "sha256": "f0fe6e6518dd197ca413412ba1e641d6a9ccad40eb79fdc8886b0dab2cbae2b1", "size": 5120 }, { @@ -1570,8 +1570,15 @@ "url": "https://platform.claude.com/docs/en/cli-sdks-libraries/cli/scripting", "status": "success", "path": "en/cli-sdks-libraries/cli/scripting.md", - "sha256": "39724fb843c1de0abcd6d4c2f137eb9b006d691f89a62790044b16c951ffe3f6", - "size": 6172 + "sha256": "4a18b2a0ef0a9f588bbb9c2446c3894a625b266c28e12870e4550c1687efa2f5", + "size": 6188 + }, + { + "url": "https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply", + "status": "success", + "path": "en/cli-sdks-libraries/cli/apply.md", + "sha256": "1855adfa5f9c039e8bccb4d87653476a331009ed27f5b543c4efd17be62ea3e9", + "size": 14451 }, { "url": "https://platform.claude.com/docs/en/cli-sdks-libraries/middleware", @@ -3509,456 +3516,456 @@ "url": "https://platform.claude.com/docs/en/api/admin", "status": "success", "path": "en/api/admin.md", - "sha256": "76f171d88a85f8a21b6a9c13e8f6580b69fa4ba1ed1623232e04fe28160777c3", - "size": 440422 + "sha256": "728563acd5ef991fb8ed8da6f11964e380cc1656a83258f2cf6f444bcc363caf", + "size": 462793 }, { "url": "https://platform.claude.com/docs/en/api/admin/organizations", "status": "success", "path": "en/api/admin/organizations.md", - "sha256": "9dca9db9ff59abf54a235db29990e2dff6fd208bea603e06adaa4252cb47ac16", - "size": 1071 + "sha256": "1b3788ea9c4d51e4d6a4f24d71c7c6e5af449024caa0a87acedcb5679c970bf1", + "size": 1070 }, { "url": "https://platform.claude.com/docs/en/api/admin/organizations/me", "status": "success", "path": "en/api/admin/organizations/me.md", - "sha256": "fe63c8e8bf27c1b7b1e1bec480af25e9d5e957793915126c519e8a3d905b4d29", - "size": 744 + "sha256": "6db1f265b9e61966da4039c25cab98b02f7e7a7982b33633c2259024907b4c70", + "size": 743 }, { "url": "https://platform.claude.com/docs/en/api/admin/invites", "status": "success", "path": "en/api/admin/invites.md", - "sha256": "fd1840fe052b21e3a33849dca68553469619bb391560f2032532d67df4d6c004", - "size": 10952 + "sha256": "6c31d342cc758067c9fd6eb8dcb741f1814b5a5635de28e103649d27a5255c3a", + "size": 10948 }, { "url": "https://platform.claude.com/docs/en/api/admin/invites/create", "status": "success", "path": "en/api/admin/invites/create.md", - "sha256": "9f5cb83fa2bbeb564b3790d4767493f9a4aba9d6217c0a7b6e10e1e219ba8c3c", - "size": 3102 + "sha256": "949cea9302db2da26977c42657349615d46926a9f1bf70d0eaa34fe68db2e848", + "size": 3101 }, { "url": "https://platform.claude.com/docs/en/api/admin/invites/retrieve", "status": "success", "path": "en/api/admin/invites/retrieve.md", - "sha256": "06460848a15187835966262bc4786099d14941c773d0e5185d30b58050234fd2", - "size": 1955 + "sha256": "fcbda00e60ad1084b916f2f57d7d0cd004fc9985fa141878cb0ed31bc1fc9c1d", + "size": 1954 }, { "url": "https://platform.claude.com/docs/en/api/admin/invites/list", "status": "success", "path": "en/api/admin/invites/list.md", - "sha256": "496a4ca9479989414a64499b45398a66fc1539363d5e47395e00895a812ddfb6", - "size": 3696 + "sha256": "77cc627cd39092ef6d20ee594e2a0c111eee29caa8e981f6bda2d09a411f4e52", + "size": 3695 }, { "url": "https://platform.claude.com/docs/en/api/admin/invites/delete", "status": "success", "path": "en/api/admin/invites/delete.md", - "sha256": "34db94567024d0992e7cccd843d6565189bc3c273a33f441d917e438126e9b0a", - "size": 649 + "sha256": "3677fa15d0f496bc540167dc61c5f59b7f37634939126bdbcf700dd1706dad73", + "size": 648 }, { "url": "https://platform.claude.com/docs/en/api/admin/users", "status": "success", "path": "en/api/admin/users.md", - "sha256": "a87505069c2b387e6dd5e5b7aa5739b6bc6775654d7b66995573bde962e7ffb1", - "size": 7175 + "sha256": "2bf3868e56384e3a51151c8ef4dcc23a8a586817bb7b0848c87257077cde9944", + "size": 7171 }, { "url": "https://platform.claude.com/docs/en/api/admin/users/retrieve", "status": "success", "path": "en/api/admin/users/retrieve.md", - "sha256": "70d9e64512d2ae288695f06f00b04bd6e1579fd9b591f59b995b437c6cb741a0", - "size": 1240 + "sha256": "ff6ba6c0515c6127202ef30cc9cd1a9eddbc60f649bf274e1b0d173c1e11af10", + "size": 1239 }, { "url": "https://platform.claude.com/docs/en/api/admin/users/list", "status": "success", "path": "en/api/admin/users/list.md", - "sha256": "1dc355493c06842820fb2723a8b30d41f652aa18cea9c7fbb77e775cf4d0ee37", - "size": 2571 + "sha256": "550234fe98ecdb3acf196647f0e380f2d404693606e8d728abaa92c302eb25e0", + "size": 2570 }, { "url": "https://platform.claude.com/docs/en/api/admin/users/update", "status": "success", "path": "en/api/admin/users/update.md", - "sha256": "dcb03c8eb54474aebdf1b6a7238b90d31edb23f330f1d018eb11e4097a45ab76", - "size": 1782 + "sha256": "9ca29eb386a8c6999eb3edb743ffb452c2dfea03cae5214cddf4b661ddb886bf", + "size": 1781 }, { "url": "https://platform.claude.com/docs/en/api/admin/users/delete", "status": "success", "path": "en/api/admin/users/delete.md", - "sha256": "acdcc79e1d4507ec838128510b5026cff953aac68a73f10c7865673b4d341e2e", - "size": 635 + "sha256": "d137f70f3d4dd55a9cb3321a407ff9b11933d9fe5ffd3a15b7301e10f88c4a82", + "size": 634 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_groups", "status": "success", "path": "en/api/admin/rbac_groups.md", - "sha256": "d7557e0d317b93655c3dc042da7a8711d7d4fafd62a2475760f4faa63b442910", - "size": 14868 + "sha256": "6139e39bfedeaf2e8789af8987642abba89bd9327c02c06477013e08c1048062", + "size": 15096 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_groups/list", "status": "success", "path": "en/api/admin/rbac_groups/list.md", - "sha256": "e34bc484ff49b6bd346762e187627c6d30c522131c05f23cbbd023c47dfb70af", - "size": 2343 + "sha256": "fa765c22ff73ab3b5afe24c83eddd3be7463595bcc95eb7bda3fc0bf63eefd3d", + "size": 2342 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_groups/retrieve", "status": "success", "path": "en/api/admin/rbac_groups/retrieve.md", - "sha256": "dd3a294a9f0e65b16a337401d302f924d89e274b230fbe7333683e52b4161c3c", - "size": 1765 + "sha256": "de22d38f1c10fd670c0fe2d813b2d380b74aa739135467fc16185f2af6e3ffc4", + "size": 1764 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_groups/create", "status": "success", "path": "en/api/admin/rbac_groups/create.md", - "sha256": "8461ee0c25418d98d726dcb3d92a32d0a19444b8ebb03c99d00032741d2002bb", - "size": 1980 + "sha256": "8c3d857e342ffc18eadf142d6d7c611f19a489f22da594a2a1b9a83f8b41d183", + "size": 1979 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_groups/update", "status": "success", "path": "en/api/admin/rbac_groups/update.md", - "sha256": "04ab8d1fd9c94c09c43133f63b106a5a1ed70ba04ef3d915ee698e5ce646483b", - "size": 2102 + "sha256": "934a2ceaca8306c7d089e91b67adbcba5d64968593a15955127607b7d8827e89", + "size": 2160 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_groups/delete", "status": "success", "path": "en/api/admin/rbac_groups/delete.md", - "sha256": "e49509ec23a4e376d492294baaba9575524de7f1ed185c04421f9e1b4adac6e6", - "size": 900 + "sha256": "c4384420cb7ab2a26c02a86f9a36784c3d5b40c8c1e427920b15646f0455ac26", + "size": 958 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_groups/members", "status": "success", "path": "en/api/admin/rbac_groups/members.md", - "sha256": "bb01a6aa552fb46a494d628202d2f4d4eab5993e883c40f735a7d56f8ed66e05", - "size": 5221 + "sha256": "edc22e94fe3df3a2c066c41b9b3c697c08364b3e8f624959b8e70b1c6f5cb121", + "size": 5336 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_groups/members/list", "status": "success", "path": "en/api/admin/rbac_groups/members/list.md", - "sha256": "d60516dac4bb2e5d1117607507e4502c8a174faab86b31014da785969c809fa0", - "size": 1785 + "sha256": "7b9e4ab59c4e55895b06e9390e8e5ba8e479fee8103d8c4f6e71a10ac7c87827", + "size": 1784 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_groups/members/create", "status": "success", "path": "en/api/admin/rbac_groups/members/create.md", - "sha256": "406266b61c60dc8ea00da44f8bc589cf9573d20bf7113f48ecd51c908eecf22f", - "size": 1444 + "sha256": "d3f1db0c9212f899ed044c1d7bf0ddb75748f17125853e1c5fe5bffd1c13eb7e", + "size": 1502 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_groups/members/delete", "status": "success", "path": "en/api/admin/rbac_groups/members/delete.md", - "sha256": "8b74b0ed04f3b797800997efc1def6866f5db93696623a36f1f6a516bf22672d", - "size": 1147 + "sha256": "844f52b8448ede6d895accbbc9a87cee1f087ac6ca67e68116472534870f1b78", + "size": 1205 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_roles", "status": "success", "path": "en/api/admin/rbac_roles.md", - "sha256": "dcc23b5f16de1d3bba42dd9376c7ecd0ed66ea7daf2663f79e954edece2d4fc0", - "size": 8193 + "sha256": "dd8bdf22c83948b699cb14685687c13fea1905354a725ad5d15e8d2c6290edef", + "size": 8190 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_roles/list", "status": "success", "path": "en/api/admin/rbac_roles/list.md", - "sha256": "a29bba3f8ca5cd204d95bfaf290c6eb330d9f0ada75e42542451dff8564b1f37", - "size": 1680 + "sha256": "27d6d4e5b6c85f549eea165c3e77b94e0622c0ee6525575342060f78e81fdc7d", + "size": 1679 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_roles/retrieve", "status": "success", "path": "en/api/admin/rbac_roles/retrieve.md", - "sha256": "f929630840957454b33cbf980d7a41d8d7e146e47d79ffd410f4d2bd16fc064f", - "size": 1144 + "sha256": "506a384a5451f2993ea7b25406caca509dd62591c75e676e8577b20438226678", + "size": 1143 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_roles/permissions", "status": "success", "path": "en/api/admin/rbac_roles/permissions.md", - "sha256": "282e921d57d7567a5016690a88cdda5a58078c65d49e2479017e4c36aa960c84", - "size": 8339 + "sha256": "e829b751391b8e1230187bc2660dcc275b9311dd8ffd9dbf4b969a2084ecd18c", + "size": 8338 }, { "url": "https://platform.claude.com/docs/en/api/admin/rbac_roles/permissions/list", "status": "success", "path": "en/api/admin/rbac_roles/permissions/list.md", - "sha256": "084ca6146dac5f704e4717e964e882bea50666b507e5a652ec9f46c97f7761d7", - "size": 4788 + "sha256": "79c1f239b2f9133dd0d8869c8b8fc60c0373c540f3851f2d56e7dff0b36f6c86", + "size": 4787 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces", "status": "success", "path": "en/api/admin/workspaces.md", - "sha256": "862f9ffa68e407d25fbf6295089de5babd5881af7138b3acbd0e8d1532aef0f7", - "size": 45049 + "sha256": "e2956569bd953461035fbcd5e5a2ac6d55e4f465dadd4b1ffc2d02967269b773", + "size": 50673 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/create", "status": "success", "path": "en/api/admin/workspaces/create.md", - "sha256": "997c615511a9c9cc7aa4c7b0665ee651dae03c6d24100cb04c953ed91cd352de", - "size": 5498 + "sha256": "30753707053d3624b61c452db4067052814c9706cb68522818b0a61b53b12742", + "size": 6645 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/retrieve", "status": "success", "path": "en/api/admin/workspaces/retrieve.md", - "sha256": "59e61bcda4c3c1439e1fbf59f7ba5261eb723c57e47bb78612c97518d4bdc20b", - "size": 3286 + "sha256": "59948a067af09c900ee88a624e85c8ca863de7b8becf2a26769bc786cc1875e7", + "size": 3928 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/list", "status": "success", "path": "en/api/admin/workspaces/list.md", - "sha256": "b8fcaf1ce93a5e3b3dc3fa73c46831b92b613faf215968fed0d5995d0c2a611b", - "size": 4316 + "sha256": "2f610afe352bb4c982bfcae36ecbc3e5db8ecd2f45b27f434e9598531bf36e1b", + "size": 4958 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/update", "status": "success", "path": "en/api/admin/workspaces/update.md", - "sha256": "c0fa63038fbac3900bb3ad3a0d0d9b9fe648f632743bf52ef7a6490ca52e7ed2", - "size": 4916 + "sha256": "08dc239097dd017918909f1f2308c3ad8b936c7b1328887cf005cd4d375877eb", + "size": 6055 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/archive", "status": "success", "path": "en/api/admin/workspaces/archive.md", - "sha256": "c9a7f904653f7f05e40c50b75d274fc1162f05e85b6f0fe6ecdde23cf76b4b9f", - "size": 3301 + "sha256": "e9b6a718c9b59a1723768574fb6c96976f159ff27f6b1f81143b0986696d1f2a", + "size": 3943 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/members", "status": "success", "path": "en/api/admin/workspaces/members.md", - "sha256": "bbc0cdcf34e958a24851ede75ca718ee0ac0389a3f774b4152b1d3f4d0fb5052", - "size": 8536 + "sha256": "6f7b0af0b744bdb290ffb7cf619697fadb3f8af09887966898a356b250e0256e", + "size": 8531 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/members/create", "status": "success", "path": "en/api/admin/workspaces/members/create.md", - "sha256": "d87862015ab0066541b5e253151dfe2154e2693ff6df16d927a523b0e8cfd0ae", - "size": 1695 + "sha256": "69c9a5e8c3094a30d370f45f58dec050a48311216f5053156f28217fcbbf8149", + "size": 1694 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/members/retrieve", "status": "success", "path": "en/api/admin/workspaces/members/retrieve.md", - "sha256": "cb9ecdae7396b4e32ce1a12b25f6c216a946aa0b2f3bb235468155234936e461", - "size": 1216 + "sha256": "c90388a3d858e05309cf6a39074615200b2c978010473e3dad12dc3057a0ac1e", + "size": 1215 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/members/list", "status": "success", "path": "en/api/admin/workspaces/members/list.md", - "sha256": "b221184d421fe94c3b1a2ea58ac3657e65472fb950606f26f6a765bf66bab252", - "size": 2103 + "sha256": "958e7c76bbada07affee279043d3fe1110c250fc17f51f4c8b8b68f6e11731c4", + "size": 2102 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/members/update", "status": "success", "path": "en/api/admin/workspaces/members/update.md", - "sha256": "72bbc7cd62cbad4296f7576d4703d23c006f3235275d1a42df0c80283eac0733", - "size": 1632 + "sha256": "6b9e0d430d36d156d23c5f8c8367c37b2d713ebfc20c5cb4dfbebc0edfbbd1cf", + "size": 1631 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/members/delete", "status": "success", "path": "en/api/admin/workspaces/members/delete.md", - "sha256": "152bd2c4b16c521571e6b50a1c814c4c2a750e0e732b199d94538c07cfccc757", - "size": 910 + "sha256": "9066753e8ecc4532245f25ce6be7a345d08ecc923fb15396fe828d4d1536f8c5", + "size": 909 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/rate_limits", "status": "success", "path": "en/api/admin/workspaces/rate_limits.md", - "sha256": "84b90610b081b5802722b584c64d1e8c65c3a053caf1c3a1a30c8cc02cf04730", - "size": 4909 + "sha256": "3fc904d87e7059ed0ea1806e8c7ed340323996a94c96ccee58bed15952cfd738", + "size": 5008 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/rate_limits/list", "status": "success", "path": "en/api/admin/workspaces/rate_limits/list.md", - "sha256": "18bd5799fd277da3acdeca840dfae36052bd0c57f092373873951d8252a60edb", - "size": 3058 + "sha256": "e77266e0aeaa1a1784a6d476f5e95cdf2954bb10942cfe86d07d3556ff90be51", + "size": 3454 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/service_accounts", "status": "success", "path": "en/api/admin/workspaces/service_accounts.md", - "sha256": "c4ef444381b08be9ff86f8453bc61ddc294744f0027914c7070cfc4866fef4d3", - "size": 17552 + "sha256": "59c84386bf18f3f6c0fee224af7d7a1b2de83f02d3cd998afb698cac4be2f599", + "size": 18573 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/service_accounts/create", "status": "success", "path": "en/api/admin/workspaces/service_accounts/create.md", - "sha256": "ae03a1efc6b4a4c1249805edf59214b04592b47ae339903de8bf98a4aabb171f", - "size": 3091 + "sha256": "064973362508cc183daf9965dfdbe7c429183e92c96195aa9e7fa3c768c55efe", + "size": 3264 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/service_accounts/retrieve", "status": "success", "path": "en/api/admin/workspaces/service_accounts/retrieve.md", - "sha256": "425862729a66e4645a64d8cafb243288038b6e13d42128d9c5967fc3d1cb28bb", - "size": 2368 + "sha256": "c48651bb01f30e24c210a4afe66ff69d692525f676de4ec38dcf004ea6916c31", + "size": 2619 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/service_accounts/list", "status": "success", "path": "en/api/admin/workspaces/service_accounts/list.md", - "sha256": "3a818852f352551df5a9152ef9cafe857a0fd9c6fe90590653ddb583ff5910c7", - "size": 2736 + "sha256": "07f7f56082ce2012c38121be9ca93efd89e55ce3a1341ccc8ddb6cd4f95f4638", + "size": 2987 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/service_accounts/update", "status": "success", "path": "en/api/admin/workspaces/service_accounts/update.md", - "sha256": "86a20be088572f4cac24109e4d1e80466050f2b150cf48d163466a40d53811ee", - "size": 2852 + "sha256": "c9af79c4634e9c504d62d18948cebf980d51dbc7e52d380297dc699f8c154b58", + "size": 3025 }, { "url": "https://platform.claude.com/docs/en/api/admin/workspaces/service_accounts/delete", "status": "success", "path": "en/api/admin/workspaces/service_accounts/delete.md", - "sha256": "28dca54c67133301ea7ababe88641f55b05aaf15d749e0fd74981cdb70e69649", - "size": 1787 + "sha256": "0c4995f1fe9fd1991eb0ac70c2459c519a9c1ed52163f37fbd14a8ac8046dc62", + "size": 1960 }, { "url": "https://platform.claude.com/docs/en/api/admin/api_keys", "status": "success", "path": "en/api/admin/api_keys.md", - "sha256": "c9881f706da40b10d73502fd92faf44127da72dfabeb3c4ca92ed531398cf6da", - "size": 14451 + "sha256": "73f048a823c4df0917b572a95040a31c8ffa6b1eec630c541c9a6d6857383773", + "size": 14448 }, { "url": "https://platform.claude.com/docs/en/api/admin/api_keys/retrieve", "status": "success", "path": "en/api/admin/api_keys/retrieve.md", - "sha256": "6e449319cdced98a781da85aaa5377644582991257d7c446f2dbffe0f99acd2f", - "size": 4518 + "sha256": "183d17804a3215aade5acff2f76c8bc8525136d8cd779080c3fac30db3ddd71a", + "size": 4517 }, { "url": "https://platform.claude.com/docs/en/api/admin/api_keys/list", "status": "success", "path": "en/api/admin/api_keys/list.md", - "sha256": "27196c85fe2c0907c018c03e7e994407015be2222914798766d2e7b71f2d82b7", - "size": 5416 + "sha256": "16fe9821ecee94c2f4618e906d8da6385488cfa21e54531a342d42a9a48276fd", + "size": 5415 }, { "url": "https://platform.claude.com/docs/en/api/admin/api_keys/update", "status": "success", "path": "en/api/admin/api_keys/update.md", - "sha256": "e455babba68a8b86c67b5cb6abfbe175a4685a9996793c605e041cbc7e51659b", - "size": 4487 + "sha256": "56152bb87f6df6c436859bdec21397fca466c62fb7f229b8d8f43419efae9632", + "size": 4486 }, { "url": "https://platform.claude.com/docs/en/api/admin/external_keys", "status": "success", "path": "en/api/admin/external_keys.md", - "sha256": "a7a0d8ce08a26f532d2f9528b3dfc6ec924920cd13ebffc26b7a6ec3308ea6ab", - "size": 29374 + "sha256": "9393b8a946a84a43f9e275dcec0f0d5f7a4f2202cf531c996e00b6650f2a23d5", + "size": 31878 }, { "url": "https://platform.claude.com/docs/en/api/admin/external_keys/create", "status": "success", "path": "en/api/admin/external_keys/create.md", - "sha256": "962b59fcddc9154a4df80bd4f2df1eb503c48be28bf5ac8c1288ad0347b26250", - "size": 4611 + "sha256": "f66ac3d172a38ab653e0ce11e29f16ee6f2e1ef44528260813a552f20087fbc5", + "size": 5112 }, { "url": "https://platform.claude.com/docs/en/api/admin/external_keys/list", "status": "success", "path": "en/api/admin/external_keys/list.md", - "sha256": "1391f1196886d3d8225200d1c056bfa46f672cba235a78391d6008c9e873ffe8", - "size": 3686 + "sha256": "a9097a080091f6b63e90a70a888ce31b6f1a717dd50c67907dd3667290bb3519", + "size": 3936 }, { "url": "https://platform.claude.com/docs/en/api/admin/external_keys/retrieve", "status": "success", "path": "en/api/admin/external_keys/retrieve.md", - "sha256": "842317b76fbdaadd1f24b1972d45eb6f4f5243f719bd733019a0248f60c5c267", - "size": 3130 + "sha256": "5a78b620cb194af346aeb09f1306d44273fac781865cc6c8ee3934507eab4ffb", + "size": 3380 }, { "url": "https://platform.claude.com/docs/en/api/admin/external_keys/update", "status": "success", "path": "en/api/admin/external_keys/update.md", - "sha256": "77696a6a9ccf40031c07c055b536082bc7506101bd64835ce7903562f2bb4031", - "size": 4802 + "sha256": "d33ce9f7719948c0feba0674e5713f74c51ac37cce8393b207da2c1721feb818", + "size": 5303 }, { "url": "https://platform.claude.com/docs/en/api/admin/external_keys/delete", "status": "success", "path": "en/api/admin/external_keys/delete.md", - "sha256": "b42af66453b6cc472bb39e6d17bc44367f82fb371af5599f6c456bc31e0bea5a", - "size": 743 + "sha256": "40623cd695cfb86a62e5ae6e9c03967a4111c0dec8df9c15bdaf289fa85eeb3d", + "size": 742 }, { "url": "https://platform.claude.com/docs/en/api/admin/external_keys/validate", "status": "success", "path": "en/api/admin/external_keys/validate.md", - "sha256": "70c8134ec41ec83e26878d5c2b79fc9781a1cbf7bb8cac361260e7f8d577c6d4", - "size": 1191 + "sha256": "f976b573b8ec49c8340e8737894a48210a60ce8c8df5f53a998dbbadff012d96", + "size": 1190 }, { "url": "https://platform.claude.com/docs/en/api/admin/usage_report", "status": "success", "path": "en/api/admin/usage_report.md", - "sha256": "986fa23c6652f7c1d5b7bfd325973d7733d97dca02a8ec2b06e071b11d011fc9", - "size": 21127 + "sha256": "c837ffb7dc445f595b99a9db37abc17b8fc1f2b970c032d569d2e4612605e613", + "size": 21125 }, { "url": "https://platform.claude.com/docs/en/api/admin/usage_report/retrieve_messages", "status": "success", "path": "en/api/admin/usage_report/retrieve_messages.md", - "sha256": "799e030c3d3851097c6ae1e906451187b2086ea7d1266c549866ed4accb7a0c7", - "size": 7558 + "sha256": "f8cb702f77a64996a070925437ccd55512fad16466328eca2c96233f4b3f619f", + "size": 7557 }, { "url": "https://platform.claude.com/docs/en/api/admin/usage_report/retrieve_claude_code", "status": "success", "path": "en/api/admin/usage_report/retrieve_claude_code.md", - "sha256": "54b629bf7077b8ed15f9b84adf1fd5bd1fb1e6d0e4efa41b46a81611e8ae372f", - "size": 6390 + "sha256": "66add758fdd4682c4e385cbe85f1dd79d5a11328656bffe49dbc70eb3db885fc", + "size": 6389 }, { "url": "https://platform.claude.com/docs/en/api/admin/cost_report", "status": "success", "path": "en/api/admin/cost_report.md", - "sha256": "3252d5458afd5b0871a481a0c0425685d8b4090108adc000efed5fc0d3ee0e25", - "size": 8215 + "sha256": "66a454b5300bdae26431a21c35434b64bad84a42f6686f0dded7fe6d9bf16cc4", + "size": 8214 }, { "url": "https://platform.claude.com/docs/en/api/admin/cost_report/retrieve", "status": "success", "path": "en/api/admin/cost_report/retrieve.md", - "sha256": "724317afc175b1e68279bf970715232a2a7c642e67eab11a2ccea27dca3d74e7", - "size": 5098 + "sha256": "d55159fd559816eb5a11f4f4162125d095b8e3d23b3f2245d00c0b6ebbc4f142", + "size": 5097 }, { "url": "https://platform.claude.com/docs/en/api/admin/analytics", "status": "success", "path": "en/api/admin/analytics.md", - "sha256": "c17634502d01e6ae9405db3ea735b989718966cab056517ce7821e3842993dd9", - "size": 145381 + "sha256": "732e4b4d7e809e1249012c14359b1dce49492f294d8f250c2bfc575cd4db6923", + "size": 155272 }, { "url": "https://platform.claude.com/docs/en/api/admin/analytics/retrieve_summaries", @@ -3971,43 +3978,43 @@ "url": "https://platform.claude.com/docs/en/api/admin/analytics/usage", "status": "success", "path": "en/api/admin/analytics/usage.md", - "sha256": "322ae4fe105d98ec3a73cd041b0e3f79435df5838502eecbeaf31d39198df3c3", - "size": 35611 + "sha256": "ed0700842b32eb6bb3f211cda14d7d29085bed5132404a0a67b042a9dcbf8e6e", + "size": 43099 }, { "url": "https://platform.claude.com/docs/en/api/admin/analytics/usage/list", "status": "success", "path": "en/api/admin/analytics/usage/list.md", - "sha256": "efea73756aa255d932d6d7e619c12be5eaa4bd74fe7748db41a361c0cb1f18bd", - "size": 10096 + "sha256": "51d53c1efe79e6a245853f5ecf3c1533ddd44a838e38f53d840f4eb8a14361de", + "size": 12514 }, { "url": "https://platform.claude.com/docs/en/api/admin/analytics/usage/list_by_user", "status": "success", "path": "en/api/admin/analytics/usage/list_by_user.md", - "sha256": "83495e4f13b5f2ceb61ba5105e824309416354a9b04b752a6af359f61d676412", - "size": 13167 + "sha256": "27763cb27c78855eb7f13ef5dd9c728eae1c20c508e2ffc2dc5cf8dee33f844d", + "size": 15559 }, { "url": "https://platform.claude.com/docs/en/api/admin/analytics/cost", "status": "success", "path": "en/api/admin/analytics/cost.md", - "sha256": "61e429642ad931693aa3d6955fd16e8a4f58e8da4e6d25ea1a6c59945ab77515", - "size": 36845 + "sha256": "f1089c877e7877f050369c8f7ffce8182cb14f5959deafbcffa80673a4010502", + "size": 44325 }, { "url": "https://platform.claude.com/docs/en/api/admin/analytics/cost/list", "status": "success", "path": "en/api/admin/analytics/cost/list.md", - "sha256": "d5120e77905352cf31633cd996b18af59c1d24eaac08a0ae6d7b4b31d4cb762a", - "size": 10405 + "sha256": "a2e6dd1651be57bf471b28e6ee92b9dfa1e48af46bcf4e6065159c60925f9764", + "size": 12819 }, { "url": "https://platform.claude.com/docs/en/api/admin/analytics/cost/list_by_user", "status": "success", "path": "en/api/admin/analytics/cost/list_by_user.md", - "sha256": "cfa10fec1c425115c4b622550af11955550f3bc17b71138992f9fb08b187f8a4", - "size": 13530 + "sha256": "d3d01e1ab2df1f8397ff4f871ce2882a26a39b571cc7351a588fe494ed9f1fda", + "size": 15918 }, { "url": "https://platform.claude.com/docs/en/api/admin/analytics/users", @@ -4027,15 +4034,15 @@ "url": "https://platform.claude.com/docs/en/api/admin/analytics/skills", "status": "success", "path": "en/api/admin/analytics/skills.md", - "sha256": "85ee29f636212a38ce0fd75383e485e34d8bacc6e53f6d98960d01d7e6d78aba", - "size": 29625 + "sha256": "abb57902a39e79ea195cd3c9ced5067a5b9d859bdf5c6e27b8e1216e41ef5ce2", + "size": 30183 }, { "url": "https://platform.claude.com/docs/en/api/admin/analytics/skills/list", "status": "success", "path": "en/api/admin/analytics/skills/list.md", - "sha256": "a665d188035d7a6b69c675ec7807991cc107b3d04d1b4ad83669ad241f2cd8ef", - "size": 17693 + "sha256": "0083e2ade8d1bfeaf7eb4c938871e24a65bbdee0681de8fb5e054d854fa3a29e", + "size": 17972 }, { "url": "https://platform.claude.com/docs/en/api/admin/analytics/connectors", @@ -4097,344 +4104,344 @@ "url": "https://platform.claude.com/docs/en/api/admin/spend_limits", "status": "success", "path": "en/api/admin/spend_limits.md", - "sha256": "830d4893c7f424d5e4721badc81aad6c410aad65e2c81ccd07a9cffafa025e33", - "size": 49479 + "sha256": "9924a924ee077ac4813e1ef173ef516719ba7f84754fa1ea2fae52fb00282501", + "size": 49471 }, { "url": "https://platform.claude.com/docs/en/api/admin/spend_limits/create", "status": "success", "path": "en/api/admin/spend_limits/create.md", - "sha256": "4f8000e22585f47dcb0ade62746bacd2a914faf6bd686cb4f4be106969b9c393", - "size": 3708 + "sha256": "b76baa52873e16814a69e3d27a070db2c1a67aa2a0a641acc779347971c35f79", + "size": 3707 }, { "url": "https://platform.claude.com/docs/en/api/admin/spend_limits/retrieve", "status": "success", "path": "en/api/admin/spend_limits/retrieve.md", - "sha256": "69a429d346a51bdc2f591800a88629b6c4470680c27d3326f5aca5b38fe6b670", - "size": 2657 + "sha256": "39dbfe55e910e26355a51a7c59fd42f396f2c93f634d2e1d235a9275ac71af14", + "size": 2656 }, { "url": "https://platform.claude.com/docs/en/api/admin/spend_limits/delete", "status": "success", "path": "en/api/admin/spend_limits/delete.md", - "sha256": "814344a69e4eb38d9f43747272f063504a653734a8e0a88adb1b4ace482acc89", - "size": 740 + "sha256": "c3ef3bc72303d75e109fef456d14ee22902e42e97977251fe5e0c7e0b329c4b4", + "size": 739 }, { "url": "https://platform.claude.com/docs/en/api/admin/spend_limits/list_effective", "status": "success", "path": "en/api/admin/spend_limits/list_effective.md", - "sha256": "510206f147c5ed6940b2be9487f6813623a98920f34908fa290b6d91e086edcb", - "size": 4833 + "sha256": "dfa4eb7ce467c6ef09f05ecdd829fb9b869f1ff370b1a8ce5803f4ffedf41f98", + "size": 4832 }, { "url": "https://platform.claude.com/docs/en/api/admin/spend_limits/increase_requests", "status": "success", "path": "en/api/admin/spend_limits/increase_requests.md", - "sha256": "9ab7f78145f5e22c418c667706306ab60ad8c6391980a20a4a3e862639518123", - "size": 45535 + "sha256": "0ba9ddd4586f707e8a01316ddc997246df8866f9ec82b4e9b1b9b3815ae1e16a", + "size": 45531 }, { "url": "https://platform.claude.com/docs/en/api/admin/spend_limits/increase_requests/list", "status": "success", "path": "en/api/admin/spend_limits/increase_requests/list.md", - "sha256": "432185074d7643efd94e8c78aa13284c47436c109a6711ec09276c5402f01e81", - "size": 7810 + "sha256": "36bdba7c0fd400600eff439ef5dc4d2076bc17e03ddb02ff788ed3347437fd5d", + "size": 7809 }, { "url": "https://platform.claude.com/docs/en/api/admin/spend_limits/increase_requests/retrieve", "status": "success", "path": "en/api/admin/spend_limits/increase_requests/retrieve.md", - "sha256": "d01baa888a339b8059f35e2e2ea68fed93b19d950c2c85853ed06986bfcd042f", - "size": 7258 + "sha256": "cff765d6071191ab2b0306de4296eac5ac82f7f6d69be3862bd4ff29d0d9f129", + "size": 7257 }, { "url": "https://platform.claude.com/docs/en/api/admin/spend_limits/increase_requests/approve", "status": "success", "path": "en/api/admin/spend_limits/increase_requests/approve.md", - "sha256": "c5b4fdeca81c0b4a1322ced4c7b3cf6438889a31c5de2702d80813540b781c95", - "size": 9824 + "sha256": "a76102e2099c3eb73b9f2a693deaeaf57dcb78f3706365421026a84207649085", + "size": 9823 }, { "url": "https://platform.claude.com/docs/en/api/admin/spend_limits/increase_requests/deny", "status": "success", "path": "en/api/admin/spend_limits/increase_requests/deny.md", - "sha256": "ee9b9a70fe18b94d61a51428ef00cdafa205e0285428f59610c937f86d5185ea", - "size": 7435 + "sha256": "33936a655cfac197775cb8ea4291964dce93e1b0c66e7f2b8d42171cdd9b1bd1", + "size": 7434 }, { "url": "https://platform.claude.com/docs/en/api/admin/rate_limits", "status": "success", "path": "en/api/admin/rate_limits.md", - "sha256": "43279b02bee924f67de0947348b722a8611ddb34671a3b2e612505c673be957e", - "size": 3986 + "sha256": "f5091a72621d784f9e68605b0413abe3e16a3d8a32c5cb0bcb1e63f345e216d3", + "size": 4121 }, { "url": "https://platform.claude.com/docs/en/api/admin/rate_limits/list", "status": "success", "path": "en/api/admin/rate_limits/list.md", - "sha256": "a0fa715e4834fb0a74cf7e5a7061ad453543806b779f00be85107c8e982acf88", - "size": 2585 + "sha256": "418889826223e95457bec1979e65c147d098bce4bd1bd56c6c960dae76c03574", + "size": 2981 }, { "url": "https://platform.claude.com/docs/en/api/admin/service_accounts", "status": "success", "path": "en/api/admin/service_accounts.md", - "sha256": "cb21f48cbe29c4f58a1e2a9793b6bcc1ea77434315c717e664da9fc00a02bf29", - "size": 25244 + "sha256": "c87f23931ef51b9b3e3c4d8c2853dec50ad90f99dd6bae028fc397406d175bb1", + "size": 27149 }, { "url": "https://platform.claude.com/docs/en/api/admin/service_accounts/create", "status": "success", "path": "en/api/admin/service_accounts/create.md", - "sha256": "00294a5066b9fab7cab542598feb2fd6d0e7240f320e53ae52cf19e8a661e2b2", - "size": 3599 + "sha256": "0dadb618f4dc543ce288e3d73b3cf75fbad12568ea1e1c11d5a7fe6543f9f3c9", + "size": 3727 }, { "url": "https://platform.claude.com/docs/en/api/admin/service_accounts/retrieve", "status": "success", "path": "en/api/admin/service_accounts/retrieve.md", - "sha256": "a590a2ff799726324344f639aa09255c49ac45afbba536dd0eb296f3309efaa5", - "size": 2673 + "sha256": "5ce148221068f4edca796a5e7af778770b68573adeae36f108e23366d8c13560", + "size": 2924 }, { "url": "https://platform.claude.com/docs/en/api/admin/service_accounts/list", "status": "success", "path": "en/api/admin/service_accounts/list.md", - "sha256": "2154b9a5858996c853509213768a7be637c348cbe65e06847fe9ba288773cee8", - "size": 3057 + "sha256": "4b60b803aadbc778f72f3ae7c846f373a3fd849d2aac8c2b796962e17fde5694", + "size": 3308 }, { "url": "https://platform.claude.com/docs/en/api/admin/service_accounts/update", "status": "success", "path": "en/api/admin/service_accounts/update.md", - "sha256": "76bf745bf32a2455089d9510b8447d0a7201e8d95b096c0f88cba30e59b524bc", - "size": 3404 + "sha256": "e99dc2c76aa602c877c4dd4602820789bcff491e1122f4ea9e1e8909760dce4b", + "size": 3622 }, { "url": "https://platform.claude.com/docs/en/api/admin/service_accounts/archive", "status": "success", "path": "en/api/admin/service_accounts/archive.md", - "sha256": "e2d0907e5fae5cb5238607ef8cf6f3e4a6b265a294a1fdd253e1b70f6b77b1e0", - "size": 3060 + "sha256": "918f1bd6ff4b641d38959ace487dee1f4c0016147dfee8deb2378a44f79ed5b5", + "size": 3232 }, { "url": "https://platform.claude.com/docs/en/api/admin/service_accounts/workspaces", "status": "success", "path": "en/api/admin/service_accounts/workspaces.md", - "sha256": "6674daa92578701e7f74d8454f4cd483456c54180713b5b5d4d81755cec15ee0", - "size": 10359 + "sha256": "881bd40ca1e10694ea7a121afd01bdb91d756da67f34baf52fb7999e22394760", + "size": 11244 }, { "url": "https://platform.claude.com/docs/en/api/admin/service_accounts/workspaces/create", "status": "success", "path": "en/api/admin/service_accounts/workspaces/create.md", - "sha256": "e81821f25d4e21a00487fafdda86023556981520ac25883b1d985cfb16d304fe", - "size": 2938 + "sha256": "97a4afcff904a8a5539fc77115964f41e4d9600382e53560ec1dcb667920a155", + "size": 3111 }, { "url": "https://platform.claude.com/docs/en/api/admin/service_accounts/workspaces/list", "status": "success", "path": "en/api/admin/service_accounts/workspaces/list.md", - "sha256": "9e272f2378c18410207985e6d15c036f3dcf0134649f414d32d49581e9da5032", - "size": 2932 + "sha256": "27b0c87e92d7fece70588379c069e78af97172b319767b760d9db6fef0a62dfa", + "size": 3471 }, { "url": "https://platform.claude.com/docs/en/api/admin/service_accounts/workspaces/delete", "status": "success", "path": "en/api/admin/service_accounts/workspaces/delete.md", - "sha256": "5af01f217b5ed1dc556303bad95ee6bde5ae62ab6a124133cf1d042809ab0c67", - "size": 1911 + "sha256": "88ab72ae6eff4606a6128ca74973abc69a38cb868030143885b541b1ee3fbcdb", + "size": 2084 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_issuers", "status": "success", "path": "en/api/admin/federation_issuers.md", - "sha256": "0c891c70c79c3ea39abc503101ed1324ca1a371eb6ba57efc23dc7b02ac96bb9", - "size": 35821 + "sha256": "9913f853f7044473f6b3b0afdc46a8ff7af0a4e320a80af55e585feffafe9594", + "size": 36840 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_issuers/create", "status": "success", "path": "en/api/admin/federation_issuers/create.md", - "sha256": "c3fa9534f9129994c75fef13695f6b2b88682c4d2be5bdbe876a5bb546831075", - "size": 7686 + "sha256": "d91d26edc99489865643320c9f5ba5069da54b7be8f9793d207441e38b6d7739", + "size": 7858 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_issuers/retrieve", "status": "success", "path": "en/api/admin/federation_issuers/retrieve.md", - "sha256": "e3889d0c3b34f62f4e2827f0efaa9f00727f50caf9742a7f9d8fbccf4614fede", - "size": 5246 + "sha256": "0564f646b50045afbc80ba9c78b8bf6992ee08ef2ebe965574cc743cd94bc3d6", + "size": 5497 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_issuers/list", "status": "success", "path": "en/api/admin/federation_issuers/list.md", - "sha256": "20ed8bbae508c6029cc9a66870f05da56947335360a3e493407194759058d921", - "size": 5545 + "sha256": "30dfd39f5fd2f2d789ef9a92fcf3d19baf863f80bec6842306e830cfdd265515", + "size": 5796 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_issuers/update", "status": "success", "path": "en/api/admin/federation_issuers/update.md", - "sha256": "26786eb2d747da4a71454005fb95be60d7ee6bd409a34e6dd200e2b0964d0816", - "size": 7955 + "sha256": "89bdfc262778bc40cbbe529f673fb01e552b6757762b127d54d386b27094a2d0", + "size": 8128 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_issuers/archive", "status": "success", "path": "en/api/admin/federation_issuers/archive.md", - "sha256": "0b8c371fa84c1f7f4330b74f674fc13ba26b32ec784904e1c500c222ccd1bea0", - "size": 5619 + "sha256": "bf501428e9574776baa1e7c99187a226e5039552aaabe2c54fed39af814bb7f9", + "size": 5791 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_rules", "status": "success", "path": "en/api/admin/federation_rules.md", - "sha256": "cac8c9607aa8c7669d58fd0b8253e6396e18b7bf5c297c6f19a6e26b37d2f04e", - "size": 49756 + "sha256": "de0f6bf9b47cf253f1ac53c0456420c3a471a21334a149a3b5537be0e8109a43", + "size": 51599 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_rules/create", "status": "success", "path": "en/api/admin/federation_rules/create.md", - "sha256": "6ddd046cb593454a2959e34ceefd1599ad1bed13cd762a2de28b4a951b3c1628", - "size": 10103 + "sha256": "1d9832ec7e49627951ed6b9ff7007ecc25d86f0c6fd5c2c80b1a6935aa4097be", + "size": 10321 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_rules/retrieve", "status": "success", "path": "en/api/admin/federation_rules/retrieve.md", - "sha256": "414a0ae92e1188ab23dfa60e908357e930b309bb35700e27e57d1d503a9733fd", - "size": 5997 + "sha256": "4e86778244e94a670e21cc6d1e917b6fed77f23a10e98ea6301e2a1ea163f275", + "size": 6248 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_rules/list", "status": "success", "path": "en/api/admin/federation_rules/list.md", - "sha256": "362890eadf2b19371b5a876334aadf6328c40ee8351533ec7e27de6aaa90028e", - "size": 6100 + "sha256": "be2d875d1e7a402ec5f963807e937c56d959498caa67c58d44181570216c9e9c", + "size": 6351 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_rules/update", "status": "success", "path": "en/api/admin/federation_rules/update.md", - "sha256": "8af487e967bda2e06d66572cc751a689a2a4a62823b09ba46168643c3f72369d", - "size": 10397 + "sha256": "2fc552122d7a19a8d602d47edfea6586e2e0b2ece53c0b7cdc23dbd9eab73af4", + "size": 10615 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_rules/archive", "status": "success", "path": "en/api/admin/federation_rules/archive.md", - "sha256": "60e6d5fadfc03b7ebc701ea2053e232889b6471737d6dc558f4dff7cb9227543", - "size": 6494 + "sha256": "7406c4a66cfc33de0c97071fd0648d80e16cd6adf3ff171e219d7c4678c4bce9", + "size": 6712 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_rules/workspaces", "status": "success", "path": "en/api/admin/federation_rules/workspaces.md", - "sha256": "fc3da4a1a57c907bf98240e55a0de2c448884efc8a410532942056e6a02de768", - "size": 7994 + "sha256": "c1019311838d5931d30c23da1d87fdfe59a298c4addaa11f8e7dca652bfbfd8b", + "size": 8681 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_rules/workspaces/list", "status": "success", "path": "en/api/admin/federation_rules/workspaces/list.md", - "sha256": "dd982da3f606b1eb586b1124d75f33e827f3c355a28dc289b184956c91f11e58", - "size": 2369 + "sha256": "d3ef6f2e0d1659486243d00ff1f004eca1b9e41fcb3c660b16bc07403244f9bf", + "size": 2620 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_rules/workspaces/create", "status": "success", "path": "en/api/admin/federation_rules/workspaces/create.md", - "sha256": "857a52b7a3c88e78affe9ff38473cdb99423eab2c1f09b4a4ca03f364a9094ab", - "size": 2361 + "sha256": "404a2067ae8eede78f95bb24543b5dec1689bdd1f79c181bf9545afa12d412a4", + "size": 2579 }, { "url": "https://platform.claude.com/docs/en/api/admin/federation_rules/workspaces/delete", "status": "success", "path": "en/api/admin/federation_rules/workspaces/delete.md", - "sha256": "e880368a36b142f519b722f1ba5056b7e76ba689ea9e0f57486ec277107339c9", - "size": 1512 + "sha256": "a8b92a8aa2815bc2cccda175f1984ad3c7037aeb3f864aa0fa00643264aa0e24", + "size": 1730 }, { "url": "https://platform.claude.com/docs/en/api/admin/mcp_tunnels", "status": "success", "path": "en/api/admin/mcp_tunnels.md", - "sha256": "06a9e92e3fcafcf4b6572a02dd4139911271d85fa7d2e19d6ceea82b582f1ecf", - "size": 25843 + "sha256": "4ad1959a43d991370c1c82f608cc69b5a2eb31ae51fd0be00e416786915ebe43", + "size": 25834 }, { "url": "https://platform.claude.com/docs/en/api/admin/mcp_tunnels/retrieve", "status": "success", "path": "en/api/admin/mcp_tunnels/retrieve.md", - "sha256": "ee62e3ee828eb0d8bb007036af32df9d4825b22e5cb4e67b583eb73bb18ce905", - "size": 2179 + "sha256": "d64fed7a85d3e28eb21ba2a6c4291039373f800aac18b4eea77619d86251547e", + "size": 2178 }, { "url": "https://platform.claude.com/docs/en/api/admin/mcp_tunnels/list", "status": "success", "path": "en/api/admin/mcp_tunnels/list.md", - "sha256": "c1d7f9904b7da90f6f9704e816abc44a3f0626eafc6094e4eff51c005bfe92e4", - "size": 3135 + "sha256": "5b710d881f03a93a2b9b46c9f3b974ec3b58e7540399dddb13ebd2d4486880e6", + "size": 3134 }, { "url": "https://platform.claude.com/docs/en/api/admin/mcp_tunnels/reveal_token", "status": "success", "path": "en/api/admin/mcp_tunnels/reveal_token.md", - "sha256": "a7ec6a348d4f8055d6a3251923758d092c1be53e3a8cf7daef74dacda798d0f8", - "size": 1721 + "sha256": "f6df0f37da3728467d8dde4743dc2b0800b8c117c0c91f096a1318c6525c1fc1", + "size": 1720 }, { "url": "https://platform.claude.com/docs/en/api/admin/mcp_tunnels/rotate_token", "status": "success", "path": "en/api/admin/mcp_tunnels/rotate_token.md", - "sha256": "23b9db00eb5dd0da9bc03809d0c2c9ceb093adeb3022f27db3df2f1dcf51f61f", - "size": 1864 + "sha256": "e35269d3231176a541f00288981e81051ded1367e573fdaee8d90afb202cd1c1", + "size": 1863 }, { "url": "https://platform.claude.com/docs/en/api/admin/mcp_tunnels/archive", "status": "success", "path": "en/api/admin/mcp_tunnels/archive.md", - "sha256": "7508a1f7abb713bafed2c5ba1a8ca64babb2f3aa07889a5cccf8b75169351442", - "size": 2446 + "sha256": "9df813716ad15abf023df5133a6b359db28c058e0d67960acc9fdafe4798942b", + "size": 2445 }, { "url": "https://platform.claude.com/docs/en/api/admin/mcp_tunnels/tunnel_certificates", "status": "success", "path": "en/api/admin/mcp_tunnels/tunnel_certificates.md", - "sha256": "a4d37aabbe76bf53a4d0208566c8d1c1b80ec37f56877360c3b601f788ee4f38", - "size": 14397 + "sha256": "4074bd388afd3954c9283b3fc868372c7a70a8d2ac2c05b24b5f9958bd0ecdcd", + "size": 14393 }, { "url": "https://platform.claude.com/docs/en/api/admin/mcp_tunnels/tunnel_certificates/create", "status": "success", "path": "en/api/admin/mcp_tunnels/tunnel_certificates/create.md", - "sha256": "ef833fabc99e1b3a635c35031c908a78a52d6b8996750387fa8d6e65b38d40ea", - "size": 2894 + "sha256": "565a9a31e12f6c4c20621b32b04ed3cdb988be6676670b44a4809f557ae99e4d", + "size": 2893 }, { "url": "https://platform.claude.com/docs/en/api/admin/mcp_tunnels/tunnel_certificates/retrieve", "status": "success", "path": "en/api/admin/mcp_tunnels/tunnel_certificates/retrieve.md", - "sha256": "651e7970da5ddb0d97b5148ebce4b0bf95a1fd70d88e8200b4da416395fc4bff", - "size": 2292 + "sha256": "2155debed0727d629be69aa736b29efb8f6d012d3a3d9d4f7af9e8f3830c9030", + "size": 2291 }, { "url": "https://platform.claude.com/docs/en/api/admin/mcp_tunnels/tunnel_certificates/list", "status": "success", "path": "en/api/admin/mcp_tunnels/tunnel_certificates/list.md", - "sha256": "f3b79d16d1c0f94740612f297f4a983f7f72741b3e16da1d762e143d91540f17", - "size": 2939 + "sha256": "784b4cf0bdcdc13396cab026f1a4c9e3ce86aa8adbbf62ab80f16886e6bdf478", + "size": 2938 }, { "url": "https://platform.claude.com/docs/en/api/admin/mcp_tunnels/tunnel_certificates/archive", "status": "success", "path": "en/api/admin/mcp_tunnels/tunnel_certificates/archive.md", - "sha256": "6f0fc57611290fdc93d84858d48c2c8433f65dc7900e8a1f3d51a2bcc506f01d", - "size": 2509 + "sha256": "dc2cdf11deb41a84a0890652f9d9988504e7e7b4fd08ac4904d443ff182549da", + "size": 2508 }, { "url": "https://platform.claude.com/docs/en/api/compliance", @@ -4909,8 +4916,8 @@ "url": "https://code.claude.com/docs/en/changelog", "status": "success", "path": "en/docs/claude-code/changelog.md", - "sha256": "18c01d355f59c820372529f238672546e687f7a2ab098b581a28240bd07c42cc", - "size": 652730 + "sha256": "a2e4be7b8a0ce48af14cdb9160664bcc29d910045bf084630b7274f2b89e3a85", + "size": 663233 }, { "url": "https://code.claude.com/docs/en/how-claude-code-works", @@ -4930,8 +4937,8 @@ "url": "https://code.claude.com/docs/en/claude-directory", "status": "success", "path": "en/docs/claude-code/claude-directory.md", - "sha256": "af1b349852f70db8c53612ea00822961b63c17e45641b4b5dc73e56a608e533e", - "size": 98955 + "sha256": "74ee4a33d8f2703a04aa0946290f8aac58b92aa928a2217bdedb2a56dce0db00", + "size": 99280 }, { "url": "https://code.claude.com/docs/en/context-window", @@ -4944,15 +4951,15 @@ "url": "https://code.claude.com/docs/en/prompt-caching", "status": "success", "path": "en/docs/claude-code/prompt-caching.md", - "sha256": "48ee5a6a708bda2e719212220962ca03ec6098e226b937d6d72eda6420df1631", - "size": 38383 + "sha256": "aa25c32ab52a7525dd756a72107fbf3aebe223adae06aa1500a3ea6cc987fc3d", + "size": 38611 }, { "url": "https://code.claude.com/docs/en/memory", "status": "success", "path": "en/docs/claude-code/memory.md", - "sha256": "3651ab935d3ba8a0cc3eb9e3343ad52928375410271f697bae6b7d3ca1db1323", - "size": 37361 + "sha256": "20fc80cfc8a59ed983f36887690e609bda37db74692ff8fff5ea57b0ddb8e69d", + "size": 37368 }, { "url": "https://code.claude.com/docs/en/sessions", @@ -4993,8 +5000,8 @@ "url": "https://code.claude.com/docs/en/remote-control", "status": "success", "path": "en/docs/claude-code/remote-control.md", - "sha256": "65ab2d74650dbb3781c3c7f8ef2ffded84e2eba977b4cea6213a321649a3ab06", - "size": 59598 + "sha256": "5333792306d267243372ffe95f4939e4160da3bf57c94df82520d40a1c49a9a5", + "size": 60238 }, { "url": "https://code.claude.com/docs/en/mobile", @@ -5175,8 +5182,8 @@ "url": "https://code.claude.com/docs/en/sub-agents", "status": "success", "path": "en/docs/claude-code/sub-agents.md", - "sha256": "fb6189075b5811bcf91a7191c8c573c7867282c2b4f3c3ed93dac3db549105bb", - "size": 112244 + "sha256": "6418a5f9bc399f080b19eedb7c785a5bc522d0d948cb11edd1479dc651f927b0", + "size": 112290 }, { "url": "https://code.claude.com/docs/en/agent-view", @@ -5210,8 +5217,8 @@ "url": "https://code.claude.com/docs/en/worktrees", "status": "success", "path": "en/docs/claude-code/worktrees.md", - "sha256": "70ee9e037f68b6b8e953acee7605a39e38895fb8f65f404bb8ee42768e67ce33", - "size": 34978 + "sha256": "a493696802443745ca0af8412e7a7b36ef4f9193139d80079205d5936556ba74", + "size": 34944 }, { "url": "https://code.claude.com/docs/en/mcp-quickstart", @@ -5224,22 +5231,22 @@ "url": "https://code.claude.com/docs/en/mcp", "status": "success", "path": "en/docs/claude-code/mcp.md", - "sha256": "6fcd70146a05d0ca779e2b48accf9ba38f6c8db6ea32f4b7b2ab3b3f4a2b3e3b", - "size": 111094 + "sha256": "d6e9c343f0e9f2ec03ad71da16a810a39e578c04768cbad189317f86018ce84a", + "size": 111221 }, { "url": "https://code.claude.com/docs/en/skills", "status": "success", "path": "en/docs/claude-code/skills.md", - "sha256": "b7a030ad40a8e613349dbc56b7f951d54b720c8b6616b96c97d6b116178e1d89", - "size": 99094 + "sha256": "db1889b7202f027251ffaceef80e889941f6bf6110d1d80a75f89d6cb39f13fa", + "size": 100582 }, { "url": "https://code.claude.com/docs/en/discover-plugins", "status": "success", "path": "en/docs/claude-code/discover-plugins.md", - "sha256": "c7ea4bd3d8cea143f8cb533e1c9ee0c9c4c99194c79c63e4b651343c586fddf5", - "size": 33054 + "sha256": "493071cde81906763a2e98ffe0af04fdde39f13f2418c8eeee44ed213e6e18e4", + "size": 33215 }, { "url": "https://code.claude.com/docs/en/plugins", @@ -5287,22 +5294,22 @@ "url": "https://code.claude.com/docs/en/headless", "status": "success", "path": "en/docs/claude-code/headless.md", - "sha256": "6c8a31d658eb31c9611e18cb10f58638bc51b4a94afe379aedd0cdbf5728ab7c", - "size": 32728 + "sha256": "ac28df4a37449c955768b62e78b59ea5995d0eb404a31e822e3dd488b715a12e", + "size": 35101 }, { "url": "https://code.claude.com/docs/en/deep-links", "status": "success", "path": "en/docs/claude-code/deep-links.md", - "sha256": "d20562bb5b5d199e84e3dbf6adad50addd8baa8a4ae13d2bb17fc348e8bc51a5", + "sha256": "e1d6a53e3e9acdb2b0b485adb3502d395a4e43be53ab0f62099e5815f67a00f8", "size": 14624 }, { "url": "https://code.claude.com/docs/en/large-codebases", "status": "success", "path": "en/docs/claude-code/large-codebases.md", - "sha256": "5ed38d7ce8bcba9653bc3ffbb487fa348d480f7581ed5279c4ffc5c412149a11", - "size": 35293 + "sha256": "2119e2a0200fa627d151b6bfc5567b9f2339c7b7cb9ca47ab02a2f93423ddecd", + "size": 35434 }, { "url": "https://code.claude.com/docs/en/troubleshoot-install", @@ -5315,8 +5322,8 @@ "url": "https://code.claude.com/docs/en/troubleshooting", "status": "success", "path": "en/docs/claude-code/troubleshooting.md", - "sha256": "f1426c4b36894db28ef285f7dc2c7654d7d33c1f89e77f93caeb5f13a41b681b", - "size": 11953 + "sha256": "8c42670f513efbb5b1f402ac1873a4b94462aa16e58dad79866ee88ab6792d1a", + "size": 13819 }, { "url": "https://code.claude.com/docs/en/debug-your-config", @@ -5329,8 +5336,8 @@ "url": "https://code.claude.com/docs/en/errors", "status": "success", "path": "en/docs/claude-code/errors.md", - "sha256": "017cb8d9d6139df4d4fb29bc0fc4f43331ea65b044fa06c0474d74eeb5664d62", - "size": 353912 + "sha256": "3bda71ad8731093c31c3f6946dc6a37aefabb99abece7945bfe7c96de189c501", + "size": 363082 }, { "url": "https://code.claude.com/docs/en/admin-setup", @@ -5357,8 +5364,8 @@ "url": "https://code.claude.com/docs/en/managed-settings", "status": "success", "path": "en/docs/claude-code/managed-settings.md", - "sha256": "02b0ca48cea4a13c48cc0263d93066860b27b2bb80419fba2e3bca0dd14dc521", - "size": 59146 + "sha256": "bfb922a16b2617a7c8dc60ae7813386b59bb4d87f669d4fe2001e7c14b7ec256", + "size": 59482 }, { "url": "https://code.claude.com/docs/en/server-managed-settings", @@ -5371,8 +5378,8 @@ "url": "https://code.claude.com/docs/en/managed-mcp", "status": "success", "path": "en/docs/claude-code/managed-mcp.md", - "sha256": "6c2e03441287feb80fc955b9ff315ddeeb9e279de399cfce5aae4ff3f446c693", - "size": 37305 + "sha256": "15704aff54b67594209e70a54c7666f499fe27652ce87f5d07ff13e4c193cf8c", + "size": 38047 }, { "url": "https://code.claude.com/docs/en/auto-mode-config", @@ -5427,8 +5434,8 @@ "url": "https://code.claude.com/docs/en/network-config", "status": "success", "path": "en/docs/claude-code/network-config.md", - "sha256": "6a892c56d6fc49f1a2e561d2110ab52d4f9c94ff1aeee7ffc188b12dc0486c32", - "size": 39083 + "sha256": "1341f34b5517901b1983764068cc14c0cf2c3a6db216cdbc60a3e107daafb741", + "size": 39059 }, { "url": "https://code.claude.com/docs/en/corporate-launcher", @@ -5504,8 +5511,8 @@ "url": "https://code.claude.com/docs/en/llm-gateway-connect", "status": "success", "path": "en/docs/claude-code/llm-gateway-connect.md", - "sha256": "6a51a2d4355632bfec26d2eaa9051cd416c41e24e1c506b559c78ca78b29f5fa", - "size": 54052 + "sha256": "43aea4f62db5ed1b5685c08daff6321d6b9186ffc99434449cc47f6a762f4c4f", + "size": 54157 }, { "url": "https://code.claude.com/docs/en/llm-gateway-rollout", @@ -5518,22 +5525,22 @@ "url": "https://code.claude.com/docs/en/llm-gateway-protocol", "status": "success", "path": "en/docs/claude-code/llm-gateway-protocol.md", - "sha256": "5188b617694a9e0e5b332720fe9c8e21b0c01fbfe3b0941ad0590c86d775e965", - "size": 33686 + "sha256": "797e7e754afd37bd650550c9f1e19ffd7b3ec84e021d6a12de12c89e8e9f9e70", + "size": 34328 }, { "url": "https://code.claude.com/docs/en/monitoring-usage", "status": "success", "path": "en/docs/claude-code/monitoring-usage.md", - "sha256": "69e9994e75d2a26b5c51ce8dc0a8173535a0089970edb41499e3d0d6b66fed4c", - "size": 139802 + "sha256": "03ae53b71fc0d8adb3264e0376942037557201d4a2fe0be1c7a8df2d12c74e98", + "size": 139839 }, { "url": "https://code.claude.com/docs/en/costs", "status": "success", "path": "en/docs/claude-code/costs.md", - "sha256": "722eed3905efa13579b4ff0c00095157ebe9db8019efd38ac44d38df3b25746e", - "size": 41408 + "sha256": "644ff6b0d4a75844ca626be566909dfd437f9785ef376179d73ebfa1aa8a92d9", + "size": 41611 }, { "url": "https://code.claude.com/docs/en/analytics", @@ -5616,22 +5623,22 @@ "url": "https://code.claude.com/docs/en/settings-reference", "status": "success", "path": "en/docs/claude-code/settings-reference.md", - "sha256": "c3a0e2339cc7dcc65df32847ce6f06f933f55686c9468ada1db60e7b3916559e", - "size": 421997 + "sha256": "0d3a37b6943ff330672adf963887f1d31e76963cc552782bcfe5c7511af87076", + "size": 424748 }, { "url": "https://code.claude.com/docs/en/settings-example", "status": "success", "path": "en/docs/claude-code/settings-example.md", - "sha256": "4579259dbe45daf19115e51189575ebdedbb266f7ad3dc8634de288d49930672", - "size": 14971 + "sha256": "24c2b90e030b07c174ffd3be56539b0303a5468d46a5db2bac60cd3d0a02aa6c", + "size": 14983 }, { "url": "https://code.claude.com/docs/en/permissions", "status": "success", "path": "en/docs/claude-code/permissions.md", - "sha256": "af3a8eef415798b09e6a6ef1e18ae26eba3092d39d5a10ef175f264a2d8474aa", - "size": 75839 + "sha256": "f647cdef89d1714a92d57517808e9a0e1cb1b933be9ab6bd204c986e18f50c4b", + "size": 78013 }, { "url": "https://code.claude.com/docs/en/permission-modes", @@ -5644,8 +5651,8 @@ "url": "https://code.claude.com/docs/en/sandboxing", "status": "success", "path": "en/docs/claude-code/sandboxing.md", - "sha256": "0dbdf0540fae8203446dad7047f724ba695ee785573f729403fa02601e8b7340", - "size": 72488 + "sha256": "5c28e9a9c0bc1b9cc9f906851f326e6800acec2197d94ef085ac84a95889f0bd", + "size": 74089 }, { "url": "https://code.claude.com/docs/en/sandbox-environments", @@ -5658,8 +5665,8 @@ "url": "https://code.claude.com/docs/en/cloud-environments", "status": "success", "path": "en/docs/claude-code/cloud-environments.md", - "sha256": "638802e5204ab2f469fe3fe949a6e62eba21d00343dd4fbd0732617c0ef1a23a", - "size": 64804 + "sha256": "26cc5b7ae4dd0e6e88ebf4c88ef25b2448022fbc67dadb5da184a20874814cf5", + "size": 65313 }, { "url": "https://code.claude.com/docs/en/self-hosted-environments", @@ -5742,8 +5749,8 @@ "url": "https://code.claude.com/docs/en/terminal-config", "status": "success", "path": "en/docs/claude-code/terminal-config.md", - "sha256": "c92b71c5f9d2b12f3c2d6f0182784f61b9540774c7c624668da2f6c4015df246", - "size": 26532 + "sha256": "0ba2eef26b85eb12e87058e524f9ef94b4117f5fe2cc3f3626793635378036ae", + "size": 26524 }, { "url": "https://code.claude.com/docs/en/fullscreen", @@ -5756,8 +5763,8 @@ "url": "https://code.claude.com/docs/en/accessibility", "status": "success", "path": "en/docs/claude-code/accessibility.md", - "sha256": "264f9685a3c6ead0b48241015b5a4103addf62413c07055a9dddeac9587720f2", - "size": 14587 + "sha256": "62728ac7ccaa16f72f2c53bc2dcd418ac3b56331bab27bd0c067b906b6da1cd9", + "size": 14604 }, { "url": "https://code.claude.com/docs/en/voice-dictation", @@ -5770,8 +5777,8 @@ "url": "https://code.claude.com/docs/en/statusline", "status": "success", "path": "en/docs/claude-code/statusline.md", - "sha256": "bb8d2c7fa1dd48372ca1c382f3d02ded9f7220530c979e8be65c9bf1ce79c4f4", - "size": 77683 + "sha256": "20379f8f1b7922c3088faadb0755214837883abd5ad33aba473190f65769e640", + "size": 79133 }, { "url": "https://code.claude.com/docs/en/keybindings", @@ -5784,57 +5791,57 @@ "url": "https://code.claude.com/docs/en/cli-reference", "status": "success", "path": "en/docs/claude-code/cli-reference.md", - "sha256": "a5d0107ecdc1b96e5dc187fdd8f2b2d3c595e8a1cad2dcb624fe66bed63f4d07", - "size": 108577 + "sha256": "faef134806631e663899af18056cd85002516b3cdb23bea1b3a3d559855f3439", + "size": 108582 }, { "url": "https://code.claude.com/docs/en/commands", "status": "success", "path": "en/docs/claude-code/commands.md", - "sha256": "76db0c765dfb242aa55259f6d8c149e9f9e4fdc3ca277126f503745c3167fd48", - "size": 162984 + "sha256": "78170eb226de8159d1d328240c17595c29601bfa4ab32274150c71751aa570fc", + "size": 164375 }, { "url": "https://code.claude.com/docs/en/env-vars", "status": "success", "path": "en/docs/claude-code/env-vars.md", - "sha256": "bd52ea171dd23ae9b34f5e10960fe8937cad6ae92be0d7c677425a8feb66b1d0", - "size": 480621 + "sha256": "898553bf13af63f0deacd1479f7bd5b0dfc5475c0a68f1219a98212b70c87e22", + "size": 481449 }, { "url": "https://code.claude.com/docs/en/tools-reference", "status": "success", "path": "en/docs/claude-code/tools-reference.md", - "sha256": "ca7dc8d5b32b50b038690ce35ef1b40adbf9c5dccd46786579e75fadff2fe24f", - "size": 105833 + "sha256": "00e6bfdf1ff5e1155a0161cac52b9f079b86dc0a97c68d92aa118b2959d1c74f", + "size": 106086 }, { "url": "https://code.claude.com/docs/en/interactive-mode", "status": "success", "path": "en/docs/claude-code/interactive-mode.md", - "sha256": "00468b887bd49dc5553750ef3a927cdbd785d65420711b9c170ff0aca0983fd2", - "size": 87227 + "sha256": "60638aaa711cc211364996f14248da5d5c301d25043efeb2b3151ac2190c27cf", + "size": 86701 }, { "url": "https://code.claude.com/docs/en/checkpointing", "status": "success", "path": "en/docs/claude-code/checkpointing.md", - "sha256": "52246fb2b8661534d935b5bf884de95bf93a11738d28e8bb56655a3f39136481", - "size": 7754 + "sha256": "800b186125a039986b885b8d3bdde95a0185a6eb1451723fcc2ff8657c463ef6", + "size": 7921 }, { "url": "https://code.claude.com/docs/en/hooks", "status": "success", "path": "en/docs/claude-code/hooks.md", - "sha256": "1c1b1218cb5238252758674be528898de67be1863dfc699ef0a3efde1812a9f3", - "size": 317647 + "sha256": "c30a50b8192dadf4e6ba016e451685f57a6d1d2c360d268887a9a94022d29f3e", + "size": 317632 }, { "url": "https://code.claude.com/docs/en/plugins-reference", "status": "success", "path": "en/docs/claude-code/plugins-reference.md", - "sha256": "64a15a9564ccd97851fdb1d0a1e27c923de2057a5cd637f597269a0c74a73875", - "size": 117596 + "sha256": "3c017b65b48b6884b47882ffcf931dc77dead2048c624ffd76b039de8082bac8", + "size": 117820 }, { "url": "https://code.claude.com/docs/en/channels-reference", @@ -5924,8 +5931,8 @@ "url": "https://code.claude.com/docs/en/agent-sdk/user-input", "status": "success", "path": "en/docs/claude-code/agent-sdk/user-input.md", - "sha256": "8134ebc71fff4698e6b52303fa61551ea603ef302d2a0124fdf20744e706ea11", - "size": 39474 + "sha256": "59d839a8526a2cbbad4e4537a86af6564f1d382511f32ce560d491da4c9fa439", + "size": 39717 }, { "url": "https://code.claude.com/docs/en/agent-sdk/streaming-output", @@ -5994,8 +6001,8 @@ "url": "https://code.claude.com/docs/en/agent-sdk/permissions", "status": "success", "path": "en/docs/claude-code/agent-sdk/permissions.md", - "sha256": "aee5bbf5552f1d665efbad2ee59bd0cdcb7cee371930c61cab144d9ce6195ebf", - "size": 24220 + "sha256": "b41a6eff7975d594c0945f91bea9bdbda265cd8496b8ae0070b384ac364d33b9", + "size": 24563 }, { "url": "https://code.claude.com/docs/en/agent-sdk/hooks", @@ -6050,8 +6057,8 @@ "url": "https://code.claude.com/docs/en/agent-sdk/typescript", "status": "success", "path": "en/docs/claude-code/agent-sdk/typescript.md", - "sha256": "4ae37f56971ecfb1680a1996aa87ea80fdc794ac5af09fd7b8b567d9acad7d53", - "size": 331975 + "sha256": "9296d3ad1b7719850fd50c291ae09ea49d2bf6cfe121db22e77b523cdb6f0da0", + "size": 336397 }, { "url": "https://code.claude.com/docs/en/agent-sdk/typescript-v2-preview", @@ -8717,8 +8724,8 @@ "url": "https://support.claude.com/en/articles/8114491-get-started-with-claude", "status": "success", "path": "support/8114491-get-started-with-claude.md", - "sha256": "05f3c1f8e173ad1cf7b5cb303835c85c10ae781894dd950c5d894de711b7bbbf", - "size": 5300 + "sha256": "d4ad38c77c55804efc606ef8e523519495999a9a654005bba070b61d182dd4f1", + "size": 5302 }, { "url": "https://support.claude.com/en/articles/8114494-how-up-to-date-is-claude-s-training-data", @@ -8794,8 +8801,8 @@ "url": "https://support.claude.com/en/articles/8230524-delete-or-rename-a-conversation", "status": "success", "path": "support/8230524-delete-or-rename-a-conversation.md", - "sha256": "223dcec407ae1be51891b3b9bc2d29c0c5e773cc0e1b65afae202ac11e626ef6", - "size": 5881 + "sha256": "4e7d4d3ca1b398ac57e4cf460ea111419781cc9c29fe345185bcb07a0a7d2a64", + "size": 5883 }, { "url": "https://support.claude.com/en/articles/8241126-upload-files-to-claude", @@ -8864,8 +8871,8 @@ "url": "https://support.claude.com/en/articles/8325618-paid-plan-billing-faqs", "status": "success", "path": "support/8325618-paid-plan-billing-faqs.md", - "sha256": "200f67e29a8ed6a8b152b4bb855c3157353640033d698714bc229bddcb13233f", - "size": 4553 + "sha256": "36b3eb4d17e1ae9dfcc388a40d748f1220139d5b8228d63c5032fdf059c67aa7", + "size": 4555 }, { "url": "https://support.claude.com/en/articles/8325621-i-would-like-to-input-sensitive-data-into-my-chats-with-claude-who-can-view-my-conversations", @@ -8927,8 +8934,8 @@ "url": "https://support.claude.com/en/articles/8887527-customizing-your-appearance-settings", "status": "success", "path": "support/8887527-customizing-your-appearance-settings.md", - "sha256": "4731cff0299f56189021c9295e7c26b7e86cf0243a64fc45439f97cf521a66eb", - "size": 1872 + "sha256": "6d0b355ce06ae8f98370f34f325ae451c7c1d65885ca569b541d18b60b1f818b", + "size": 1878 }, { "url": "https://support.claude.com/en/articles/8896518-does-anthropic-crawl-data-from-the-web-and-how-can-site-owners-block-the-crawler", @@ -9102,8 +9109,8 @@ "url": "https://support.claude.com/en/articles/9267400-move-your-personal-claude-account-to-a-team-or-enterprise-organization", "status": "success", "path": "support/9267400-move-your-personal-claude-account-to-a-team-or-enterprise-organization.md", - "sha256": "9e51b6c235c959365c4b97c38b99c2c03207d2f0f725d741eb71f76f1b120d48", - "size": 9727 + "sha256": "63db52b4cb3f8af471b4bf30913c511b837a7162fb663195d2f183bb73be419e", + "size": 9729 }, { "url": "https://support.claude.com/en/articles/9301722-updates-to-our-acceptable-use-policy-now-usage-policy-consumer-terms-of-service-and-privacy-policy", @@ -9158,8 +9165,8 @@ "url": "https://support.claude.com/en/articles/9519189-manage-project-visibility-and-sharing", "status": "success", "path": "support/9519189-manage-project-visibility-and-sharing.md", - "sha256": "b9cf5c73c606e4b975d502f3014270738cfdffe43583a331e9e32a7ba79b711b", - "size": 8569 + "sha256": "5acde81b01829b6d8df8aad77260c0f477ff0945a9869fce8ce4cf45be04334c", + "size": 8557 }, { "url": "https://support.claude.com/en/articles/9519291-what-is-anthropic-s-policy-for-handling-governmental-requests-for-user-information", @@ -9179,15 +9186,15 @@ "url": "https://support.claude.com/en/articles/9534590-cost-and-usage-reporting-in-the-claude-console", "status": "success", "path": "support/9534590-cost-and-usage-reporting-in-the-claude-console.md", - "sha256": "a9917ff42aa5c39d6bf885ea21607a3d1b2a831ff49589653ab6446c4b9c8134", - "size": 5094 + "sha256": "a8f3b38c638575386606a35e81ac9bd3583b5e9c056d7c0fb28ee8a508299ba3", + "size": 5100 }, { "url": "https://support.claude.com/en/articles/9547008-publish-and-share-artifacts", "status": "success", "path": "support/9547008-publish-and-share-artifacts.md", - "sha256": "a826c558d3e8b69e024a3b476d236b44f7f4733c195b09ccd09b66a82a82487f", - "size": 7195 + "sha256": "a703bf1b89621ef15c2ba5c7ece0c5bcd768b2ef3ecc319b7364912654d83253", + "size": 7201 }, { "url": "https://support.claude.com/en/articles/9612887-install-claude-for-android", @@ -9263,8 +9270,8 @@ "url": "https://support.claude.com/en/articles/9927533-disable-public-projects-for-your-organization", "status": "success", "path": "support/9927533-disable-public-projects-for-your-organization.md", - "sha256": "77dd54b03677de40a5367de41998783a311ce9edbc7e7e6f712e1b83fa01e1b8", - "size": 2580 + "sha256": "c417fe50aa4cc8eba2b15a20bbf383f751d94b24c5003e360f6de1f6ae3756cf", + "size": 2582 }, { "url": "https://support.claude.com/en/articles/9927624-add-or-update-your-team-plan-s-tax-or-vat-id", @@ -9403,15 +9410,15 @@ "url": "https://support.claude.com/en/articles/10310342-how-do-i-log-out-of-all-active-sessions", "status": "success", "path": "support/10310342-how-do-i-log-out-of-all-active-sessions.md", - "sha256": "07cac0e3fe5676b251198f6338b469733cbf62a4438590bbea667309e1e53888", - "size": 2498 + "sha256": "d7c7f712c6acfb6402a504b9bcfb4d486fabdee1ac2916e96c09602aa3ac3c05", + "size": 2494 }, { "url": "https://support.claude.com/en/articles/10366376-how-can-i-delete-my-claude-console-account", "status": "success", "path": "support/10366376-how-can-i-delete-my-claude-console-account.md", - "sha256": "aaebebfa19e20966a36a376c3117e8268f3a8e1ef806f34ac04b72420e91c066", - "size": 3163 + "sha256": "b882eac70f4c57c0538f9d8fc1e5bec8cc8dcf3d1912c490e6fd64fb95b6a3c5", + "size": 3161 }, { "url": "https://support.claude.com/en/articles/10366389-how-can-i-get-higher-rate-limits-on-the-claude-api", @@ -9452,15 +9459,15 @@ "url": "https://support.claude.com/en/articles/10504844-manage-user-feedback-settings-on-team-and-enterprise-plans", "status": "success", "path": "support/10504844-manage-user-feedback-settings-on-team-and-enterprise-plans.md", - "sha256": "5f265db6e2e6397c183dd6a608ffd9140f963227c315c79f440c29b81d6a40c0", - "size": 1038 + "sha256": "44908645d67b44039316c7d10284c56c75014d50852dae903efb9b54c9b20f72", + "size": 1036 }, { "url": "https://support.claude.com/en/articles/10504853-manage-user-feedback-settings-on-claude-console", "status": "success", "path": "support/10504853-manage-user-feedback-settings-on-claude-console.md", - "sha256": "51fe1ccc4c19e2e95fc5d758db1870e7f17278f6a0355333812eab575353634f", - "size": 997 + "sha256": "55a359556390968e6ed8903102c40006dfe0a8b19be22d5cba8fc629757e5e16", + "size": 999 }, { "url": "https://support.claude.com/en/articles/10534883-use-the-claude-widget-on-android", @@ -9473,7 +9480,7 @@ "url": "https://support.claude.com/en/articles/10593882-share-and-unshare-chats", "status": "success", "path": "support/10593882-share-and-unshare-chats.md", - "sha256": "aaef2df3570f8972bed67c2c4780964bf86313394f0ddbd036c57fb8ff7c352e", + "sha256": "30b4e9cabc157faedcce9ad19ad80e86ee95f98e75bdf546318fc6e928eeb773", "size": 4012 }, { @@ -9501,8 +9508,8 @@ "url": "https://support.claude.com/en/articles/10949351-getting-started-with-local-mcp-servers-on-claude-desktop", "status": "success", "path": "support/10949351-getting-started-with-local-mcp-servers-on-claude-desktop.md", - "sha256": "b5a665d0f555eeb69da6c4c00bd0d5271fc938fc7cae541ffb98a9a5dd2e5aa8", - "size": 8267 + "sha256": "06ddd17925a76379874831a28efbb62ddab8d1a50564aad4a0fc1ffbb787784d", + "size": 8269 }, { "url": "https://support.claude.com/en/articles/11049741-what-is-the-max-plan", @@ -9543,7 +9550,7 @@ "url": "https://support.claude.com/en/articles/11101966-use-voice-mode", "status": "success", "path": "support/11101966-use-voice-mode.md", - "sha256": "f21442351014d8cfade6dd32d76cffb820dbaaa75e5a7a35abb6bebca0d54d91", + "sha256": "4f9e78703c6d7cf6f2ec892fdb483283dda12936ef0782ff3405174d0668d3c4", "size": 10552 }, { @@ -9676,8 +9683,8 @@ "url": "https://support.claude.com/en/articles/11725453-set-up-the-claude-lti-in-canvas-by-instructure", "status": "success", "path": "support/11725453-set-up-the-claude-lti-in-canvas-by-instructure.md", - "sha256": "a27fb8cb1bb4dd98dd714cdb6f1a45e2648244978ac19a06f69fa20102b6a52f", - "size": 2754 + "sha256": "7200932a1a77e7c61018e878c39e1ce53d3df95eb58b717e05ea0b6cb1c544a0", + "size": 2750 }, { "url": "https://support.claude.com/en/articles/11732894-who-owns-and-manages-the-data-of-my-claude-for-education-account", @@ -9690,15 +9697,15 @@ "url": "https://support.claude.com/en/articles/11817273-use-claude-s-chat-search-and-memory-to-build-on-previous-context", "status": "success", "path": "support/11817273-use-claude-s-chat-search-and-memory-to-build-on-previous-context.md", - "sha256": "53403a4a040b5666f487a513726709c28fc673c3485cf98b858135df17dd62d0", - "size": 25708 + "sha256": "c17d16b7618cee92df66d2e567f941587002fdcc25821df81b2a51d5740cffa3", + "size": 25696 }, { "url": "https://support.claude.com/en/articles/11818288-why-am-i-being-asked-to-verify-my-payment-method", "status": "success", "path": "support/11818288-why-am-i-being-asked-to-verify-my-payment-method.md", - "sha256": "6690362ceec430e5983f9a7ee1cb04142dca07a68c9669c8dfe623825a766b91", - "size": 814 + "sha256": "9245aa7f2e62d49c05a54be83481a394c5121f4219ed9b690d5f79f28348981b", + "size": 816 }, { "url": "https://support.claude.com/en/articles/11825384-how-to-update-claude-for-ios", @@ -9732,7 +9739,7 @@ "url": "https://support.claude.com/en/articles/11869629-use-claude-with-android-apps", "status": "success", "path": "support/11869629-use-claude-with-android-apps.md", - "sha256": "c2870bf459c110b17f8d0fd20ed0bdea81bfaf0cba9d3368683767555d35cc8c", + "sha256": "c3a44e7cd51c61bb31c772e33cdbf84be0890611ea75b0a71fe47b49ec5b12c8", "size": 13991 }, { @@ -9767,14 +9774,14 @@ "url": "https://support.claude.com/en/articles/12005970-manage-usage-credits-for-team-and-seat-based-enterprise-plans", "status": "success", "path": "support/12005970-manage-usage-credits-for-team-and-seat-based-enterprise-plans.md", - "sha256": "370ecd2183dffda5ffcdc780187e92e3f446f3baab61f1bd1d2aa2db528e317f", - "size": 9638 + "sha256": "98ace39c0ed9c00cf504686f9c92658faaa83d292795084768b7f7338b842d8a", + "size": 9773 }, { "url": "https://support.claude.com/en/articles/12012173-get-started-with-claude-in-chrome", "status": "success", "path": "support/12012173-get-started-with-claude-in-chrome.md", - "sha256": "3b99d20cdd7cb54eb4b393dabdc1dc09abca1ed1677e65b0aad2b5eee6583720", + "sha256": "c6df10e23c1c1a5a476559fbab189b2c01e7e311b3e5ecb817d87a6c1969a8c3", "size": 14855 }, { @@ -9788,7 +9795,7 @@ "url": "https://support.claude.com/en/articles/12083917-change-your-team-plan-from-monthly-to-annual-billing", "status": "success", "path": "support/12083917-change-your-team-plan-from-monthly-to-annual-billing.md", - "sha256": "393c4b08d9b3029bc7cda6baa6407a545166887ae1ad06be65e1ead0d09b7305", + "sha256": "6a08bbeba222a75122c997aab281546c9cbafe1fffd4e03bab2ea979bb45ff96", "size": 1394 }, { @@ -9802,8 +9809,8 @@ "url": "https://support.claude.com/en/articles/12111783-create-and-edit-files-with-claude", "status": "success", "path": "support/12111783-create-and-edit-files-with-claude.md", - "sha256": "98c75ccc8b7d8e922ad144ff2517a8d4003f7f990f1325963907f74fa8570c2e", - "size": 17958 + "sha256": "63a9db9b1a2261acde53b3b2047bab9e4081ac27cbbd6d36706f55349cc8c08b", + "size": 17964 }, { "url": "https://support.claude.com/en/articles/12119250-model-safety-bug-bounty-program", @@ -9830,22 +9837,22 @@ "url": "https://support.claude.com/en/articles/12157520-claude-code-usage-analytics", "status": "success", "path": "support/12157520-claude-code-usage-analytics.md", - "sha256": "c0a082f39410ef0225be2a969b1688d24789859fd10460efa24515e6e7767946", - "size": 6429 + "sha256": "03b4a489c14523a9645a78e60631f8d3d26acbc8c200e9d0a82ff33feeb941ba", + "size": 6427 }, { "url": "https://support.claude.com/en/articles/12260368-use-incognito-chats", "status": "success", "path": "support/12260368-use-incognito-chats.md", - "sha256": "abd0d5b38d38a815f18ccef95d6f933fe62e88e310ee30cc3965855da16b1d35", + "sha256": "467554a09febf045a3f9bbc322765f5c70e1eac775ffa8949f06cc68cfc95664", "size": 3596 }, { "url": "https://support.claude.com/en/articles/12293051-use-claude-in-xcode", "status": "success", "path": "support/12293051-use-claude-in-xcode.md", - "sha256": "05dc8c04c525083da389a6a18b57e6c047df174227aaeeda333519c7b1e157e4", - "size": 1907 + "sha256": "b28d69763e44a7af94199cb4f4d08e8f7201e01be201858f624c001502b24179", + "size": 1905 }, { "url": "https://support.claude.com/en/articles/12304248-manage-api-key-environment-variables-in-claude-code", @@ -9886,15 +9893,15 @@ "url": "https://support.claude.com/en/articles/12429409-manage-usage-credits-for-paid-claude-plans", "status": "success", "path": "support/12429409-manage-usage-credits-for-paid-claude-plans.md", - "sha256": "a6c48237219a5aee5a539805af8cde8ce4730f930f52fb571d995827b8240d64", - "size": 6416 + "sha256": "1b8e91c0731156f31cbdf2ed2a3a9cc176a4fb96dd837f7b783b16cf3b0876cb", + "size": 6410 }, { "url": "https://support.claude.com/en/articles/12466728-troubleshoot-claude-error-messages", "status": "success", "path": "support/12466728-troubleshoot-claude-error-messages.md", - "sha256": "341a9afe0f8d139bc4a5ed8114fbf0819301c6b6748be8d8917ac385d3761eba", - "size": 4234 + "sha256": "c7cf09dabf83acc3ae8b2b297a12e1aa3da1aacafd383b38d9e7da6d725e2235", + "size": 4232 }, { "url": "https://support.claude.com/en/articles/12489464-use-enterprise-search", @@ -9935,8 +9942,8 @@ "url": "https://support.claude.com/en/articles/12592343-enabling-and-using-the-desktop-extension-allowlist", "status": "success", "path": "support/12592343-enabling-and-using-the-desktop-extension-allowlist.md", - "sha256": "ff635cc803f153f196824c734189bc24556b0acd8a087690f12fb7e1c6655da8", - "size": 5720 + "sha256": "43b5b148bd9a58537cda8a14e9164520e0dcc72352f901eee36f6dc82c08a2f4", + "size": 5716 }, { "url": "https://support.claude.com/en/articles/12611117-deploy-claude-desktop-for-macos", @@ -9949,8 +9956,8 @@ "url": "https://support.claude.com/en/articles/12618689-claude-code-on-the-web", "status": "success", "path": "support/12618689-claude-code-on-the-web.md", - "sha256": "74af95efacf3337952b8f6e4be377bf17297a12e68784a96e2ad6755de6d5988", - "size": 10966 + "sha256": "2d4a39612f519aeed2dab57ed3fc5b3d5e3a8c278b8f154326e132067316e45d", + "size": 10968 }, { "url": "https://support.claude.com/en/articles/12622667-enterprise-configuration-for-claude-desktop", @@ -9970,8 +9977,8 @@ "url": "https://support.claude.com/en/articles/12626668-use-quick-entry-with-claude-desktop-on-mac", "status": "success", "path": "support/12626668-use-quick-entry-with-claude-desktop-on-mac.md", - "sha256": "2c83d465daf4348696993c3c98302c50fb7146bcdbe28a74b5131a318cd337a7", - "size": 5972 + "sha256": "8d2c6e47d2074645938e177df5c047704485e137239b88d1b8327d5bc14b17c4", + "size": 5974 }, { "url": "https://support.claude.com/en/articles/12684923-microsoft-365-connector-security-guide", @@ -10005,8 +10012,8 @@ "url": "https://support.claude.com/en/articles/12883420-view-usage-analytics-for-team-and-enterprise-plans", "status": "success", "path": "support/12883420-view-usage-analytics-for-team-and-enterprise-plans.md", - "sha256": "d6bdeee93063701fff78adeef69d42b138c36fa4ada9422a7eb8942e6f3159b9", - "size": 13931 + "sha256": "df182c59f45f087fa761c49942191ba395d68c6aa8d2654ccd3f5221aac7fef2", + "size": 13941 }, { "url": "https://support.claude.com/en/articles/12902405-claude-in-chrome-troubleshooting", @@ -10026,7 +10033,7 @@ "url": "https://support.claude.com/en/articles/12902446-claude-in-chrome-permissions-guide", "status": "success", "path": "support/12902446-claude-in-chrome-permissions-guide.md", - "sha256": "98fb26434b1e03318ba185bab372a8b10f0b1ed4a909b53659e0cd9e1e3ba4f1", + "sha256": "1a67ea964924613dcf670db8c85e81cc9dcf02dd15f86d9b6d17ed8233230f6f", "size": 9567 }, { @@ -10103,15 +10110,15 @@ "url": "https://support.claude.com/en/articles/13132885-set-up-single-sign-on-sso", "status": "success", "path": "support/13132885-set-up-single-sign-on-sso.md", - "sha256": "2087afcca21839e07f6cba14fd8995c9e6aa3bd6a397ad63b7526415de193f77", - "size": 13331 + "sha256": "6c8849e94e6b732bdedfea431ba79e9ecaa61f3f401832cbb119094b9b2baffe", + "size": 13319 }, { "url": "https://support.claude.com/en/articles/13133195-set-up-jit-or-scim-provisioning", "status": "success", "path": "support/13133195-set-up-jit-or-scim-provisioning.md", - "sha256": "c23e9dd52b8fc7943dd81408e2741d69a6a23831be02abaf8198fd8061b42d3e", - "size": 19699 + "sha256": "b386c31a9bc102038db670b53e347f816d0740b065b59b7ebce818380f8e45cf", + "size": 19705 }, { "url": "https://support.claude.com/en/articles/13133750-manage-members-on-team-and-enterprise-plans", @@ -10138,16 +10145,9 @@ "url": "https://support.claude.com/en/articles/13163631-configuring-session-security-settings", "status": "success", "path": "support/13163631-configuring-session-security-settings.md", - "sha256": "b8b265e94b51bc5ea348702b3c2d479892ff1032db92a81295729ab84784984f", + "sha256": "081f8632fec39efc74368cca8907be5f945b7286bf5ea0ac081fcf5a24314293", "size": 3696 }, - { - "url": "https://support.claude.com/en/articles/13163666-holiday-2025-usage-promotion", - "status": "success", - "path": "support/13163666-holiday-2025-usage-promotion.md", - "sha256": "bd31024f8c54a647c279602b04d7cf2f3a76a799c2eea7dffe4394d1670b9f11", - "size": 1919 - }, { "url": "https://support.claude.com/en/articles/13171706-crisis-helpline-support-in-claude", "status": "success", @@ -10159,8 +10159,8 @@ "url": "https://support.claude.com/en/articles/13189465-log-in-to-your-claude-account", "status": "success", "path": "support/13189465-log-in-to-your-claude-account.md", - "sha256": "07f6f9a47edc0989c388c2c4594b872d2b0db713667145b7d8076472a7eb6624", - "size": 7042 + "sha256": "fff4bbda9f1818d30968c184e5af09eeee1fc3b46452948fe556abfeae2d9942", + "size": 7040 }, { "url": "https://support.claude.com/en/articles/13198485-enforce-network-level-access-control-with-tenant-restrictions", @@ -10187,22 +10187,22 @@ "url": "https://support.claude.com/en/articles/13325567-account-management-faqs", "status": "success", "path": "support/13325567-account-management-faqs.md", - "sha256": "ddc90ce6c37e4f85d62b113eb2caabcfc04250619507f0018467ada8116926e0", - "size": 2634 + "sha256": "be7238c01eae9362170c3294c186ae9458b114fcfd3aac3900b9331de957a0c4", + "size": 2632 }, { "url": "https://support.claude.com/en/articles/13345190-get-started-with-claude-cowork", "status": "success", "path": "support/13345190-get-started-with-claude-cowork.md", - "sha256": "33f17c962b9e281678fa10594e43352767f9ca16b295beeb6c56c1baace48d29", - "size": 21514 + "sha256": "03650d8da63e8837e49d459d2304fbae28a24a93c6925f4ea5f2930f04a8e60a", + "size": 21518 }, { "url": "https://support.claude.com/en/articles/13346458-customizing-your-console-appearance-settings", "status": "success", "path": "support/13346458-customizing-your-console-appearance-settings.md", - "sha256": "835ec0d392d981d36018ab3ad6013924f858a167c415ffde8c305ee2f02a5bdb", - "size": 605 + "sha256": "d74a910293981af37a799be7989583528ff2692cc68ac53224814bafaa0feb54", + "size": 607 }, { "url": "https://support.claude.com/en/articles/13346720-export-your-organization-s-data", @@ -10222,8 +10222,8 @@ "url": "https://support.claude.com/en/articles/13371040-log-in-to-your-console-account", "status": "success", "path": "support/13371040-log-in-to-your-console-account.md", - "sha256": "95136423beace614c9c836ae7d70963531ec9eb8fe1d745c42088b2bd0ebcc29", - "size": 4613 + "sha256": "178131f7db654374d64506bbbcc7d19039379dc6b4fd94ae08bd3e710246fc06", + "size": 4609 }, { "url": "https://support.claude.com/en/articles/13393991-purchase-and-manage-seats-on-enterprise-plans", @@ -10278,8 +10278,8 @@ "url": "https://support.claude.com/en/articles/13641943-visual-and-interactive-content", "status": "success", "path": "support/13641943-visual-and-interactive-content.md", - "sha256": "9349f50176f5ece34b3a105220c0a4791a224ddbdcde61c62bee3c984639148b", - "size": 6517 + "sha256": "d9434d845d3c417bfb50c3fca0cd4d472c5b8ee9c2dee357c419322bb1e927d3", + "size": 6515 }, { "url": "https://support.claude.com/en/articles/13663666-use-visual-and-interactive-content-on-team-and-enterprise-plans", @@ -10306,7 +10306,7 @@ "url": "https://support.claude.com/en/articles/13756069-public-sector-faqs", "status": "success", "path": "support/13756069-public-sector-faqs.md", - "sha256": "88266cf618d0e33af83f9d7aeed2d9bf7ea00adf70d7d341a141f86845e576c2", + "sha256": "946d3d80baf660f3c327b8007279fed627ae332f69b4fe4ac34951006659506c", "size": 8380 }, { @@ -10341,14 +10341,14 @@ "url": "https://support.claude.com/en/articles/13837440-use-plugins-in-claude", "status": "success", "path": "support/13837440-use-plugins-in-claude.md", - "sha256": "1798a473f9e7fcbee1f6b1f27dd6352b0313a19b90a566eba1ebacb5f56f0df5", - "size": 6718 + "sha256": "75effc136bea59c962e799dabe0d34ff4aabbdfb436817f41b61d56d47dab9cd", + "size": 10776 }, { "url": "https://support.claude.com/en/articles/13854387-schedule-recurring-tasks-in-claude-cowork", "status": "success", "path": "support/13854387-schedule-recurring-tasks-in-claude-cowork.md", - "sha256": "c3b7ab69c5c59b8e95d966608dbd815c374f4ca453f8e54d07d68f6f31b9f49c", + "sha256": "85320d5f4eef9dafb2da80eca35baff01345626fac33c926c4182fae4100fc25", "size": 4747 }, { @@ -10439,8 +10439,8 @@ "url": "https://support.claude.com/en/articles/13947068-assign-tasks-from-anywhere-in-claude-cowork", "status": "success", "path": "support/13947068-assign-tasks-from-anywhere-in-claude-cowork.md", - "sha256": "68bf7314a35d30ad73b179c66a1948bc8b9b36baf831e05b1f4b0b5f6ffe5da3", - "size": 8520 + "sha256": "327044e72d87c977f9ffce6913b27d4d0ea2afe918d9d29cec35264d781b0f15", + "size": 8522 }, { "url": "https://support.claude.com/en/articles/13979539-custom-visuals-in-chat-and-cowork", @@ -10530,8 +10530,8 @@ "url": "https://support.claude.com/en/articles/14499648-how-scim-sync-works-for-enterprise-organizations", "status": "success", "path": "support/14499648-how-scim-sync-works-for-enterprise-organizations.md", - "sha256": "8d81c71fd222da9e5998682a5258df387fbe03a79fc6cec49a532b6b8f43e703", - "size": 7674 + "sha256": "bf5f6cb5fd3676fd6a01c2cc61eea5c2a4c854089620bb62bfc0f5f3aed32e2e", + "size": 7672 }, { "url": "https://support.claude.com/en/articles/14503520-available-beta-and-research-preview-features", @@ -10551,15 +10551,15 @@ "url": "https://support.claude.com/en/articles/14503613-sso-login", "status": "success", "path": "support/14503613-sso-login.md", - "sha256": "689e7c1b9d518bf7dc572df1e4f85da77336b068b198eb6d87697a431dde6692", - "size": 6688 + "sha256": "7d5043d7579601f176a621b2653b5b82aec6a2790bb96ed6d40c833bce58debf", + "size": 6690 }, { "url": "https://support.claude.com/en/articles/14503643-set-up-scim-in-claude-for-government", "status": "success", "path": "support/14503643-set-up-scim-in-claude-for-government.md", - "sha256": "8ff45e4c251b1272456c7a852b2d0e4afe4597eb80d32af4020feda6e48d32ea", - "size": 6419 + "sha256": "cfec48b960fee4a82ba941d7fb32d6aeda9da9bb084188b85bf76555712005fa", + "size": 6423 }, { "url": "https://support.claude.com/en/articles/14503675-organization-instructions-in-claude-for-government", @@ -10586,8 +10586,8 @@ "url": "https://support.claude.com/en/articles/14503775-mcp-web-search", "status": "success", "path": "support/14503775-mcp-web-search.md", - "sha256": "95e0ba788fb19757bdfeb74208cde34b365f69956a1e330c367b511e069b1b96", - "size": 4679 + "sha256": "82ea17370afb464aab803b7210947275531670b78640f562c8cf0b51bb043d66", + "size": 4677 }, { "url": "https://support.claude.com/en/articles/14503794-model-availability-in-claude-for-government", @@ -10684,21 +10684,21 @@ "url": "https://support.claude.com/en/articles/14604397-set-up-your-design-system-in-claude-design", "status": "success", "path": "support/14604397-set-up-your-design-system-in-claude-design.md", - "sha256": "6ebd17eafb9f3240a95cdda98b95bd9451bb5f9dc1e151e39b9f89d00af0d46d", - "size": 4400 + "sha256": "207de8404bcccdbfe9e9ae4bada98f2415f859e1554b683dd3b8da064566c9e8", + "size": 4396 }, { "url": "https://support.claude.com/en/articles/14604406-claude-design-admin-guide-for-team-and-enterprise-plans", "status": "success", "path": "support/14604406-claude-design-admin-guide-for-team-and-enterprise-plans.md", - "sha256": "4162ab794f8a14de802f37f061107db5d4216068f238b0d56e4db85363fb6b96", - "size": 12731 + "sha256": "0e6cc1390be20153ecb9d9213de9c35fa86c05bf0edcae63c7db1b8af58c0814", + "size": 12735 }, { "url": "https://support.claude.com/en/articles/14604416-get-started-with-claude-design", "status": "success", "path": "support/14604416-get-started-with-claude-design.md", - "sha256": "70814a7ca89eec1304943b8651118c13338db048527955b30e3ab3e685dc49bf", + "sha256": "6680c28c1d37d0c2683087192ab37182eb98515aa7c7c3b7539a86321deb26a5", "size": 11134 }, { @@ -10824,8 +10824,8 @@ "url": "https://support.claude.com/en/articles/15330088-set-a-default-model-for-your-organization", "status": "success", "path": "support/15330088-set-a-default-model-for-your-organization.md", - "sha256": "2d931a4a2b1b125c84bd25abb886dfb4e886361e67d4f8fd397f8daf2ddd01cc", - "size": 7774 + "sha256": "b239a5816f4593dfc1d35b46f479db4eb4ad65a2581e01798b2174b28f474864", + "size": 7770 }, { "url": "https://support.claude.com/en/articles/15330651-claude-enterprise-admin-api-reference-guide", @@ -10873,8 +10873,8 @@ "url": "https://support.claude.com/en/articles/15425996-data-retention-practices-for-covered-models", "status": "success", "path": "support/15425996-data-retention-practices-for-covered-models.md", - "sha256": "f05879cac55a2ee6b88a96882f947193e6e22b5fd6b922ea2f9680344199cade", - "size": 7253 + "sha256": "1dd57e3aa5d836a0226f040aa14237f67baf75252f29846fc958189c0a2ddb5d", + "size": 7490 }, { "url": "https://support.claude.com/en/articles/15455031-covered-models-under-a-business-associate-agreement-baa", @@ -10936,8 +10936,8 @@ "url": "https://support.claude.com/en/articles/15694740-manage-model-access-for-your-organization", "status": "success", "path": "support/15694740-manage-model-access-for-your-organization.md", - "sha256": "fd859101900b789eaa836b33d0403f6470923ebc9f61f3997af3f65f4893d112", - "size": 10141 + "sha256": "62f449432063fae10fca597fff777082d3aff73a310d49d6f52b1c6f49c59547", + "size": 10151 }, { "url": "https://support.claude.com/en/articles/15707726-using-claude-for-legal-work-privilege-confidentiality-and-how-to-think-about-configuration", @@ -10971,8 +10971,8 @@ "url": "https://support.claude.com/en/articles/15936181-get-started-with-1password-for-claude", "status": "success", "path": "support/15936181-get-started-with-1password-for-claude.md", - "sha256": "ec6afd71701e8805ac3ecf197cda46593e351160e73e7e714c863443c5d4a2d1", - "size": 5058 + "sha256": "1ead2d11ec46c9c32e5615bab9f006448a33d94c5ea968d773b18fbe89771b3f", + "size": 5056 }, { "url": "https://support.claude.com/en/articles/16049681-why-claude-switched-models-in-your-conversation-with-opus-5", @@ -11020,8 +11020,8 @@ "url": "https://support.claude.com/en/articles/16607638-understanding-your-pro-or-max-plan-invoices", "status": "success", "path": "support/16607638-understanding-your-pro-or-max-plan-invoices.md", - "sha256": "ac3f7a9209b554e876972d5297753b100a3ee80974c88d0bce9d9135084127c5", - "size": 5443 + "sha256": "c87be3458aac6c73cb66288e32b3184b369c0236718920f0babd64955252ce99", + "size": 5437 }, { "url": "https://support.claude.com/en/articles/16607668-understanding-your-team-plan-invoices", @@ -11083,7 +11083,7 @@ "url": "https://support.claude.com/en/articles/16764810-assign-a-program-to-workspaces-in-claude-console", "status": "success", "path": "support/16764810-assign-a-program-to-workspaces-in-claude-console.md", - "sha256": "a8706fbccc37c382ea834b5983c35b79b3a8bcc6fe3a45af7556b33aeeacd53c", + "sha256": "a29dfdf184a8bab73ca6225d0316721881b9c0787ad78bb19431d29e3c39e553", "size": 5103 }, { @@ -12000,8 +12000,8 @@ "url": "https://claude.com/docs/cowork/changelog", "status": "success", "path": "claude/cowork/changelog.md", - "sha256": "9400d3868acf175a96b9e5cc8f85a78fcedaedf136c6764aad17ae58b17e6f52", - "size": 125882 + "sha256": "0957d3ae86ffd8fbc80538087b9c0b2662d9e2d1152ca177b2e97490187c614a", + "size": 126112 }, { "url": "https://claude.com/docs/cowork/guide/dispatch", @@ -12091,8 +12091,8 @@ "url": "https://claude.com/docs/government/config/settings", "status": "success", "path": "claude/government/config/settings.md", - "sha256": "eaf1692a7f84f470a9412ae722e248cc45b22ecbf3416e86c3b980bf46125d1e", - "size": 27839 + "sha256": "5cac865c54fcd2adfa91528d6c8f8f272f2f308712814532427f6199054ed038", + "size": 28008 }, { "url": "https://claude.com/docs/government/connectors/microsoft-365", @@ -12238,8 +12238,8 @@ "url": "https://claude.com/docs/government/security/security-and-data-handling", "status": "success", "path": "claude/government/security/security-and-data-handling.md", - "sha256": "97a3cc9bf92841da57179abf457221f0a0211a224a5564ffbfe01dbd6869c38a", - "size": 32646 + "sha256": "d2ba620480e46b6d2cef856f7c29fb56175bc883782fd580c6c97095c32645d8", + "size": 33096 }, { "url": "https://claude.com/docs/government/tenant-admin/admins", @@ -12469,8 +12469,8 @@ "url": "https://claude.com/docs/third-party/claude-desktop/code", "status": "success", "path": "claude/third-party/claude-desktop/code.md", - "sha256": "f3b8a7315c6df7a4022044c25c8bdb91e2469baa2627b6f884d7d6509199ba62", - "size": 15739 + "sha256": "24a271faa14078e4cb0aa9aafc048bd34994d6e117ad59fce742457dfc1a1fd9", + "size": 23328 }, { "url": "https://claude.com/docs/third-party/claude-desktop/configuration", @@ -12483,8 +12483,8 @@ "url": "https://claude.com/docs/third-party/claude-desktop/configuration-changelog", "status": "success", "path": "claude/third-party/claude-desktop/configuration-changelog.md", - "sha256": "66cddf9364d2a162efbcbf7abe39382f9770751a1f12131a49df712aade7521c", - "size": 57630 + "sha256": "c3d21ff5fbd76be2d9f00c0d6352672371939b7d127a519d43b18a6a6f7c1dd9", + "size": 57738 }, { "url": "https://claude.com/docs/third-party/claude-desktop/connectors-github", @@ -12581,8 +12581,8 @@ "url": "https://claude.com/docs/third-party/claude-desktop/local-access", "status": "success", "path": "claude/third-party/claude-desktop/local-access.md", - "sha256": "a5986fda59f07dfcdbae8d432ed612d15331162edd4a2d636e848f21d616c7a3", - "size": 6995 + "sha256": "fbfd7494f9c906c4075db938590336f9d62d5e816187e7a85d25252cf8c26322", + "size": 7643 }, { "url": "https://claude.com/docs/third-party/claude-desktop/mantle", @@ -12616,8 +12616,8 @@ "url": "https://claude.com/docs/third-party/claude-desktop/ssh-remote-sessions", "status": "success", "path": "claude/third-party/claude-desktop/ssh-remote-sessions.md", - "sha256": "089e2b3d750eede3e61dd6ac669be48751b549ad176a474a837e80eb0a01ed0b", - "size": 21411 + "sha256": "946836100101c993a0513a0365b0c482de5b9ef239772b5d8916aff5aca39f69", + "size": 22128 }, { "url": "https://claude.com/docs/third-party/claude-desktop/telemetry", @@ -12651,8 +12651,8 @@ "url": "https://code.claude.com/docs/en/slash-commands", "status": "success", "path": "en/docs/claude-code/slash-commands.md", - "sha256": "b7a030ad40a8e613349dbc56b7f951d54b720c8b6616b96c97d6b116178e1d89", - "size": 99094 + "sha256": "db1889b7202f027251ffaceef80e889941f6bf6110d1d80a75f89d6cb39f13fa", + "size": 100582 }, { "url": "https://code.claude.com/docs/en/web-scheduled-tasks", @@ -23711,7 +23711,7 @@ "url": "https://raw.githubusercontent.com/anthropics/claude-plugins-official/main/.claude-plugin/marketplace.json", "status": "success", "path": "github/claude-plugins-official/.claude-plugin/marketplace.json", - "sha256": "8879f40238dac8f9eaa08ede7463b1c36de4a996704cda9f92acb402c159e907", + "sha256": "25fe90148b78d0378203861229c3e5d6f699ef0fbf583ce9985ffb9ead84a65f", "size": 172012 }, { @@ -27239,8 +27239,8 @@ "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-python/main/CHANGELOG.md", "status": "success", "path": "github/anthropic-sdk-python/CHANGELOG.md", - "sha256": "1e30777923554e1fc3ce3be1a7a6efd1aed38ff9f680a54f037c8703b7cc5f3b", - "size": 235861 + "sha256": "7b65a9db1755552301cdf54aec4216dabec7bd122b98dc603e99e4cc7a24c209", + "size": 238654 }, { "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-python/main/CONTRIBUTING.md", @@ -27274,8 +27274,8 @@ "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-python/main/api.md", "status": "success", "path": "github/anthropic-sdk-python/api.md", - "sha256": "0c90176f1cc03ca0f32c7a997c2709cf7b48095368be560b26153d7eb470562c", - "size": 109160 + "sha256": "b15b3ba82fb7e21eb60b95365d65ac8f5da26bb2f3519f1444a97f4a254fa90a", + "size": 109231 }, { "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-python/main/examples/greeting-SKILL.md", @@ -27323,8 +27323,8 @@ "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/CHANGELOG.md", "status": "success", "path": "github/anthropic-sdk-typescript/CHANGELOG.md", - "sha256": "418e5b0b81963bc31661768a492818226a34321862d9e825b67764c69699a65e", - "size": 213572 + "sha256": "b2a1bbda5d80387db8298244dacf4979e96468110466dca6ec169ad5d1766a43", + "size": 215553 }, { "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/CLAUDE.md", @@ -27365,8 +27365,8 @@ "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/api.md", "status": "success", "path": "github/anthropic-sdk-typescript/api.md", - "sha256": "dabac8b31d6498d686bc3360a4d4ac08fa78221d94d25cc816ed15e47b9ab2a5", - "size": 149180 + "sha256": "9e0ee644d126eff779dcd5873b6dac5ae1aff217428b4d9cccdc23551cb63379", + "size": 149548 }, { "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/ecosystem-tests/README.md", @@ -27386,15 +27386,15 @@ "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/helpers.md", "status": "success", "path": "github/anthropic-sdk-typescript/helpers.md", - "sha256": "b3e014929a8e11e156699612f610f8f320c0cbbdcfa4096c5968c038a3f4d389", - "size": 24222 + "sha256": "6515cd8358cd841f01657d0569d5861abea1110537f678fcf59b49bbc41ea155", + "size": 24449 }, { "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/aws-sdk/CHANGELOG.md", "status": "success", "path": "github/anthropic-sdk-typescript/packages/aws-sdk/CHANGELOG.md", - "sha256": "e237186698722cdad0a1496c880697558cdda258122647b79472b440c002d86a", - "size": 9964 + "sha256": "b6a2c6ae7b6ffec89750bd03aa2de4ab34269a91e1d1a804c12b24862dd3a020", + "size": 10333 }, { "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/aws-sdk/README.md", @@ -27407,29 +27407,29 @@ "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/bedrock-sdk/CHANGELOG.md", "status": "success", "path": "github/anthropic-sdk-typescript/packages/bedrock-sdk/CHANGELOG.md", - "sha256": "a7c1536f8dc0a1ab65211c9dc0ba4d8d77a6215def5bbcd2cd4902ed49f43a34", - "size": 48392 + "sha256": "814e10eb5c8a4a89e8e65c09c67bf81d183b296b852ee20b9bbc381aaaf41b32", + "size": 48831 }, { "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/bedrock-sdk/README.md", "status": "success", "path": "github/anthropic-sdk-typescript/packages/bedrock-sdk/README.md", - "sha256": "30ef71d2b709db75aa5ed745825d5cd4b98bb754657a87218fb026e2d1bd46c5", - "size": 2940 + "sha256": "a2c5375d5c0079722674d68a572283ac427a00cfd600c3cff11c356f40b5b592", + "size": 2931 }, { "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/foundry-sdk/CHANGELOG.md", "status": "success", "path": "github/anthropic-sdk-typescript/packages/foundry-sdk/CHANGELOG.md", - "sha256": "2c576c46d217bad3556ebbb7d4d8d2d3c2682e61219db6adee2ec513448cadc8", - "size": 6104 + "sha256": "ae6829dcb6cd38145d5f89b27ed42609e4ba227faa7e7f18d043ceb3c1d3f9d4", + "size": 6538 }, { "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/foundry-sdk/README.md", "status": "success", "path": "github/anthropic-sdk-typescript/packages/foundry-sdk/README.md", - "sha256": "14d44cf994ffd805f19aa3583069f217faf4b099981aef3778b1f449b163ec53", - "size": 2524 + "sha256": "6732227c349a64c14d4dcccc82a0b1080cad6e62fbb7594e925e44f287b507ef", + "size": 2491 }, { "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/google-cloud-sdk/CHANGELOG.md", @@ -27449,15 +27449,15 @@ "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/vertex-sdk/CHANGELOG.md", "status": "success", "path": "github/anthropic-sdk-typescript/packages/vertex-sdk/CHANGELOG.md", - "sha256": "3358f8fae9cfe1d5ea46cf2060b53ab1880c7a6bccc4117be525dba7389c555a", - "size": 27788 + "sha256": "491142a96ca4a185d1fdecf5e70ca0d87697220c5cc428833ae1f78500dfbc09", + "size": 28223 }, { "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/packages/vertex-sdk/README.md", "status": "success", "path": "github/anthropic-sdk-typescript/packages/vertex-sdk/README.md", - "sha256": "177e2c04f006b6211a00f17c38f7a0ca42c3c1ae584c66c63c5aa48d55e12f64", - "size": 3686 + "sha256": "b795ab5ec4b6c045a8fdab19409d336051beb19b0f5991303d70b7d5b8fa7592", + "size": 3672 }, { "url": "https://raw.githubusercontent.com/anthropics/anthropic-sdk-typescript/main/src/_vendor/partial-json-parser/README.md", @@ -27495,7 +27495,12 @@ "size": 170 } ], - "failures": [], + "failures": [ + { + "url": "https://support.claude.com/en/articles/13163666-holiday-2025-usage-promotion", + "error": "HTTP 404" + } + ], "dead": [ { "url": "https://support.claude.com/en/articles/12650343-use-claude-for-excel", @@ -27875,11 +27880,11 @@ } ], "summary": { - "total": 4021, + "total": 4022, "downloaded": 3927, "skipped": 0, "failed": 0, - "dead": 94, + "dead": 95, "success_rate": 100.0 } } \ No newline at end of file diff --git a/content/CHANGELOG.md b/content/CHANGELOG.md index 3bd361564..8d3f6a0e8 100644 --- a/content/CHANGELOG.md +++ b/content/CHANGELOG.md @@ -1,5 +1,75 @@ # Changelog +## 2.1.261 + +- Added an "Organization policy" line to `/status` and `claude doctor` that says why your organization's policy could not be loaded, such as a proxy not passing the endpoint through +- Added `bashOutputMaxChars` and `taskOutputMaxChars` settings to raise how much command and background-task output Claude receives inline before it is saved to a file, up to 128K characters +- Added `--append-subagent-system-prompt-file` to read the subagent system prompt from a file, for prompts too large to pass on the command line +- Added `/skill-doctor` to show which loaded skills go unused and what they cost in context, so you can prune them +- Fixed typed or pasted characters occasionally landing out of order or being dropped during fast input or key repeat +- Fixed `/add-dir ` printing a false "couldn't be resolved" error when the working directory is on a `/net` automount +- Fixed the Bedrock setup wizard hanging when AWS or an AWS credential helper never responds (it now times out with a clear error), and its model checks failing behind a TLS-inspecting proxy +- Fixed cloud sessions discarding a plugin synced from claude.ai when managed settings force-enable it in `enabledPlugins`, then falling back to a marketplace clone that could fail +- Fixed being unable to delete the character immediately before an inline `[Image #N]` chip in the prompt input +- Fixed resuming a session losing hook output and other context around parallel tool calls, which changed the resumed request +- Fixed Remote Control showing a stale permission mode when a phone, browser, or claude.ai app attaches to a terminal session or after the mode changes in the terminal +- Fixed Remote Control sessions showing as still working (stuck spinner and Stop button) after stopping a turn from a connected phone or browser, or after a local slash command like `/clear` +- Fixed SDK and cloud sessions ignoring a Stop or interrupt sent just after the first prompt, before the turn had started; the turn now stops instead of running to completion +- Fixed Remote Control uploading a session pulled with `/teleport` into the connected session, which appeared appended to the original on phone and web +- Fixed Remote Control's inbound event stream failing behind TLS-inspecting corporate proxies on native Windows +- Fixed Remote Control sessions showing the default effort level on claude.ai when the effort comes from settings +- Fixed `gcpAuthRefresh` opening a browser at startup when the Google credential check was slow, even though the credential was still valid +- Fixed claude.ai connectors staying absent for the whole session when the startup connector fetch timed out — the CLI now retries in the background +- Fixed sustained high CPU usage when a background agent could not be resumed and its wake-up was retried in a tight loop +- Fixed feature flags gated to a newer version occasionally applying to an older Claude Code version running on the same machine +- Fixed `/usage` and the VS Code usage panel dropping a model-specific weekly limit row when the usage endpoint is rate limited or when opened right after startup +- Fixed `claude -p --resume ` adopting a malformed session ID recorded in the transcript; it now resumes under a fresh session ID instead +- Fixed the terminal progress indicator (iTerm2, Ghostty, ConEmu) showing the session as finished while a background workflow or agent was still running +- Fixed a rare layout glitch where a box could render with the wrong height after its container switched between row and column direction +- Fixed Claude apps gateway client IP when a trusted proxy appends a port to `X-Forwarded-For`; with an access list set, an unreadable entry now gets 403 +- Fixed Claude apps gateway telling Claude Desktop to export OpenTelemetry as JSON even when the terminal CLI uses protobuf, so protobuf-only collectors rejected Desktop's data +- Fixed Desktop and web showing a session as busy while it only watches an artifact for updates +- Fixed Claude in Chrome `file_upload` failing with "paths: expected array, received undefined" in local Cowork sessions run from the Claude Desktop app +- Fixed `SendMessage` to an offline Remote Control session on another machine reading as delivered; the result now says delivery is queued until that machine reconnects +- Fixed plugin install hints from CLIs run in background Bash commands: they are now detected, and the raw `` tag no longer leaks into the conversation +- Fixed in-process agent-team teammates re-sending their first-turn tool and skill announcements on the second turn, which changed the request prefix and missed the prompt cache +- Improved the `/model` picker and the VS Code model pill to show a model's name instead of its raw Bedrock, Vertex AI, or LLM gateway ID when Claude Code recognizes it +- Improved startup on Google Vertex AI when `GOOGLE_APPLICATION_CREDENTIALS` is set: API client creation no longer re-runs Google Cloud project discovery or spawns extra `gcloud` processes +- Improved streaming performance: already-rendered blocks are no longer re-checked by layout on each update +- Improved the dangerous-`rm` safety prompt to also catch `rm -rf` on positional parameters and inside double-quoted `sh -c` scripts +- Improved handling when the API sends no response headers: the retry now waits up to `API_TIMEOUT_MS` (10 minutes by default) instead of another 3 minutes, and the messages say what to change +- Changed a Claude apps gateway 403 on the managed settings load (at startup or after `/login`) to say Claude Code may not be enabled for the organization, instead of advising a new sign-in +- Changed machines whose managed settings pin `forceLoginMethod: "gateway"` to ignore a leftover API key or claude.ai login and ask for `/login`; Bedrock, Vertex AI, and Foundry sessions are unaffected +- Changed auto mode to treat a link that packs content into a public diagram renderer's URL as an upload to that site: no longer auto-approved unless you asked for it +- Changed the prompt's word-editing keys to match Bash: Ctrl+W deletes back to whitespace, Alt+F and Alt+D stop at word end, punctuation separates words; `keybindingFlavor` no longer has any effect +- Changed `/context` token counting to use a local estimate when the token-counting API is unavailable, instead of extra small-model requests +- [VSCode] Added a "Build a custom style" walkthrough to the Output styles menu that writes a custom output style file and lists it right away +- [VSCode] Added an Add server form and a Remove action to the MCP servers dialog, so MCP servers can be added and removed without leaving the IDE +- [VSCode] Added a hollow ring in the session list for sessions open in a terminal, another VS Code window, or Claude Desktop, so they no longer look closed +- [VSCode] Added a fold button to permission and question prompts so the conversation behind them can be read without dismissing them; the space beside the prompt now scrolls the conversation +- [VSCode] Added "Archive session" to the session list's right-click menu and gave Unarchive its own icon +- [VSCode] Fixed a session teleported from Claude Code on the web treating a question that was cut off when the cloud session shut down as declined +- [VSCode] Fixed the session tab's Rename box opening empty for a tab restored with the window; it now starts with the current name +- [VSCode] Fixed collapsed sections in the session list panel briefly showing expanded each time the panel loaded +- [VSCode] Fixed Focus view showing a tool call as still running after Claude had moved on, such as while a question waited for your answer +- [VSCode] Fixed the session list's active-row highlight going stale when an unfocused Claude tab's session ID is corrected +- [VSCode] Fixed Cmd/Ctrl+Shift+T reopen and deep-link opens placing the Claude tab outside the Claude editor group when a Claude tab has focus +- [VSCode] Fixed the session tab's "Add to group" putting a session opened from Claude Code on the Web in two groups; it now moves the entry the session list shows +- [VSCode] Fixed the model picker showing models an organization has since disabled until the window was reloaded twice +- [VSCode] Fixed a tab opened from the session list jumping back to that session, and a tab opened from a Web session restarting its teleport or staying empty, after VS Code reloads the tab's view +- [VSCode] Fixed `/btw` side-question history from earlier sessions being overwritten when a question is asked right after a window reload or while a settings file has errors +- [VSCode] Fixed the pending question card not reappearing after the Claude panel reloads when signed in with a Claude.ai or Console account +- [VSCode] Fixed claude.ai-only features staying visible in a window's other Claude panels after one panel picked up a third-party provider from a settings file +- [VSCode] Fixed the sign-in screen appearing despite the Disable Login Prompt setting when Claude Code reports no login or a request fails for lack of one +- [VSCode] Fixed the next queued permission prompt keeping text typed on the previous prompt and accepting an immediate second click +- [VSCode] Fixed install-plugin links opening the Claude sidebar without the install dialog in a window where only the session list had been shown +- [VSCode] Fixed the sidebar usage meter staying empty on a new window until the Account & usage dialog was opened, and a 0% usage limit being left out of the meter +- [VSCode] Fixed "Start new session in this group" losing the group after New conversation, and a missing unread dot for a session that finished before the sidebar's unread list loaded +- [VSCode] Fixed the editor tab badge showing unread during a running turn or missing on a tab opened from the session list, and "Add Session Tab to Group" doing nothing for an archived session +- [VSCode] Fixed "Enable Remote Control for all sessions" so flipping it also applies right away to sessions open in other VS Code windows +- [VSCode] Fixed the session list's Open filter for sessions continued from claude.ai whose tab was still recorded under the web session, and labeled the filter menu's sections for screen readers +- [VSCode] Changed the model picker to one flat list of every model, with rows kept for older model spellings listed last + ## 2.1.260 - Added a diff panel that opens beside the conversation in fullscreen mode and shows your uncommitted changes as Claude edits; toggle it with `/diff` diff --git a/content/claude-code-manifest.json b/content/claude-code-manifest.json index f6bf2cfb0..220acf10e 100644 --- a/content/claude-code-manifest.json +++ b/content/claude-code-manifest.json @@ -6,17 +6,17 @@ "url": "https://github.com/anthropics/claude-code/issues" }, "dist": { - "shasum": "50a77d223c3bd945455abd35ac757a7c57324ee6", - "tarball": "https://registry.npmjs.org/@anthropic-ai/claude-code/-/claude-code-2.1.260.tgz", + "shasum": "9506177b40c5ccaf2ccbebecf2e133758299cd89", + "tarball": "https://registry.npmjs.org/@anthropic-ai/claude-code/-/claude-code-2.1.261.tgz", "fileCount": 7, - "integrity": "sha512-Arqg8BvlOehmC3QdACN2WKshqqWQVMo+5NwG22aiJbw7M6S1LM7E2pA2MjD8BS5P5EwZVkh2eKUmC6k7pVUqSQ==", + "integrity": "sha512-j6+AkfCl6/UJBcx66nlZUmWc4XGK3TscvW19Tiat+oDwkz3WqQfKzjvHO5FhR+shXTtktqs6vqSBrJmeSWpU3Q==", "signatures": [ { - "sig": "MEUCIBvIArzkMvHRlthhAPxUm6bApApdSivf8NtPSHUTCpM6AiEApWn7bkGYH1Rs/f5HZG0vlmz+avfcwqK53lYTbhTgMAc=", + "sig": "MEYCIQD0lpq7pVlzMEV3GhMWTYwLU22vaay+prUy/CJvBNSrKwIhALq457koMp/H/5HadfuYjhRA5kSkzwyZ9cPCTr1roy7v", "keyid": "SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U" }, { - "sig": "MEQCIFxY1+CcMaS/XFS2qpY1Cgp6ZmizMvnpS6pl7+9PcWDbAiBVFMQVvGFlphNXjQW1XWpo41UW9n+8+w5uMK3sS2vNBQ==", + "sig": "MEUCIQDp3v9TMPuwWyNY57wceXchk1pCYXPHUDfysibYFw8ZUQIgar6KLnlFnD80fntKSNmI0Jav1AG9+7WIsJNDT39NDhs=", "keyid": "SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U" } ], @@ -24,7 +24,7 @@ }, "name": "@anthropic-ai/claude-code", "type": "module", - "_from": "file:staged-npm/anthropic-ai-claude-code-2.1.260.tgz", + "_from": "file:staged-npm/anthropic-ai-claude-code-2.1.261.tgz", "author": { "name": "Anthropic", "email": "support@anthropic.com" @@ -42,9 +42,9 @@ "email": "wolffiex@anthropic.com" }, "homepage": "https://github.com/anthropics/claude-code", - "_resolved": "/home/runner/work/claude-cli-internal/claude-cli-internal/staged-npm/anthropic-ai-claude-code-2.1.260.tgz", - "_integrity": "sha512-Arqg8BvlOehmC3QdACN2WKshqqWQVMo+5NwG22aiJbw7M6S1LM7E2pA2MjD8BS5P5EwZVkh2eKUmC6k7pVUqSQ==", - "_npmVersion": "11.17.0", + "_resolved": "/home/runner/work/claude-cli-internal/claude-cli-internal/staged-npm/anthropic-ai-claude-code-2.1.261.tgz", + "_integrity": "sha512-j6+AkfCl6/UJBcx66nlZUmWc4XGK3TscvW19Tiat+oDwkz3WqQfKzjvHO5FhR+shXTtktqs6vqSBrJmeSWpU3Q==", + "_npmVersion": "11.19.0", "description": "Use Claude, Anthropic's AI assistant, right from your terminal. Claude can understand your codebase, edit files, run terminal commands, and handle entire workflows for you.", "directories": {}, "maintainers": [ @@ -101,23 +101,24 @@ "email": "joan@anthropic.com" } ], - "_nodeVersion": "24.19.0", + "_nodeVersion": "24.20.0", "dependencies": {}, "_hasShrinkwrap": false, + "readmeFilename": "README.md", "optionalDependencies": { - "@anthropic-ai/claude-code-linux-x64": "2.1.260", - "@anthropic-ai/claude-code-win32-x64": "2.1.260", - "@anthropic-ai/claude-code-darwin-x64": "2.1.260", - "@anthropic-ai/claude-code-linux-arm64": "2.1.260", - "@anthropic-ai/claude-code-win32-arm64": "2.1.260", - "@anthropic-ai/claude-code-darwin-arm64": "2.1.260", - "@anthropic-ai/claude-code-linux-x64-musl": "2.1.260", - "@anthropic-ai/claude-code-linux-arm64-musl": "2.1.260" + "@anthropic-ai/claude-code-linux-x64": "2.1.261", + "@anthropic-ai/claude-code-win32-x64": "2.1.261", + "@anthropic-ai/claude-code-darwin-x64": "2.1.261", + "@anthropic-ai/claude-code-linux-arm64": "2.1.261", + "@anthropic-ai/claude-code-win32-arm64": "2.1.261", + "@anthropic-ai/claude-code-darwin-arm64": "2.1.261", + "@anthropic-ai/claude-code-linux-x64-musl": "2.1.261", + "@anthropic-ai/claude-code-linux-arm64-musl": "2.1.261" }, "_npmOperationalInternal": { - "tmp": "tmp/claude-code_2.1.260_1788474722006_0.7624845032002834", + "tmp": "tmp/claude-code_2.1.261_1788544174824_0.04353081113645341", "host": "s3://npm-registry-packages-npm-production" }, - "_id": "@anthropic-ai/claude-code@2.1.260", - "version": "2.1.260" + "_id": "@anthropic-ai/claude-code@2.1.261", + "version": "2.1.261" } \ No newline at end of file diff --git a/content/claude/cowork/changelog.md b/content/claude/cowork/changelog.md index f0ed0f282..f559bd9b8 100644 --- a/content/claude/cowork/changelog.md +++ b/content/claude/cowork/changelog.md @@ -6,6 +6,24 @@ > Release notes for Claude Desktop + + **General** + + * No user-facing changes. + + **Code** + + * No user-facing changes. + + **Cowork** + + * No user-facing changes. + + **3P** + + * No user-facing changes. + + **General** diff --git a/content/claude/government/config/settings.md b/content/claude/government/config/settings.md index b8fd47459..eeb05a339 100644 --- a/content/claude/government/config/settings.md +++ b/content/claude/government/config/settings.md @@ -148,7 +148,7 @@ Entries are hostnames or wildcard patterns such as `*.example.com`, which matche ### Allowed workspace folders -Controls which folders members can pick as a project folder in Claude Desktop, and where Claude can read and write files. Leave it unset to allow any folder. Add folder paths to limit members to those locations, or check **Block all workspace folders** to allow none, in which case Claude can still work in Chat and Cowork in folders it creates inside its own sandbox. A Code session starts only in a folder this setting permits, and [Code in Claude Desktop](/docs/government/security/security-and-data-handling#code-in-claude-desktop) describes how the setting applies to Code sessions on each operating system. You can list Windows and Mac paths together, and each device uses only the paths for its platform. An unset value shows as **Any folder** and an empty list shows as **No folders**. +Controls which folders members can pick as a project folder in Claude Desktop, and where Claude can read and write files. Leave it unset to allow any folder. Add folder paths to limit members to those locations, or check **Block all workspace folders** to allow none, in which case Claude can still work in Chat and Cowork in folders it creates inside its own sandbox. A Code session starts only in a folder this setting permits and Claude's file tools stay inside the permitted folders, but the setting does not stop the shell commands Claude runs in a Code session from reading files elsewhere on the device, and [Code in Claude Desktop](/docs/government/security/security-and-data-handling#code-in-claude-desktop) describes what confines those commands on each operating system. You can list Windows and Mac paths together, and each device uses only the paths for its platform. An unset value shows as **Any folder** and an empty list shows as **No folders**. Write each entry as an absolute path. A path can start with `~`, which stands for each member's home folder on both Windows and Mac; write these with forward slashes, for example `~/ClaudeWork`, and they resolve on both platforms. A path can also use one of the per-user variables `%OneDrive%`, `%OneDriveCommercial%`, `%OneDriveConsumer%`, `%APPDATA%`, `%LOCALAPPDATA%`, and `%USERNAME%`. A device ignores an entry whose variable it does not define, so a list with only Windows entries leaves Mac users with no allowed folder. Include a `~` path or a Mac path as well. Subfolders of a listed folder are included, Claude Desktop creates a listed folder that does not exist yet when a member opens the folder picker, and the picker opens in one of the listed folders. diff --git a/content/claude/government/security/security-and-data-handling.md b/content/claude/government/security/security-and-data-handling.md index 36ff3847b..b4c95bb8f 100644 --- a/content/claude/government/security/security-and-data-handling.md +++ b/content/claude/government/security/security-and-data-handling.md @@ -40,15 +40,15 @@ In Cowork, and for the file-analysis steps in Chat, the Claude Desktop applicati Code sessions use Claude Code built into the desktop application and run on the user's workstation itself, not in the virtual machine. The shell commands Claude runs during a Code session execute on the workstation's own operating system under the user's own account. -On macOS, those shell commands run inside an operating-system-level sandbox that the application builds from your organization's **Allowed network hosts** and **Allowed workspace folders** settings on the [Config](/docs/government/config/settings#allowed-network-hosts) page. The sandbox is in place whenever either setting restricts access, which the default configuration does. A user can exempt specific commands from this sandbox in a Claude Code settings file, and an exempted command runs outside the sandbox under the permission mode the user selects for the session. +On macOS, those shell commands run inside an operating-system-level sandbox that the application builds from your organization's **Allowed network hosts** and **Allowed workspace folders** settings on the [Config](/docs/government/config/settings#allowed-network-hosts) page. The sandbox is in place whenever either setting restricts access, which the default configuration does. Inside the sandbox, a command can create or change files only in the session's folder, the other folders **Allowed workspace folders** permits, and temporary locations, but the sandbox does not limit which files the command reads: it can read any file on the device that the user's account can open, and by default it runs without asking the user first. A user can exempt specific commands from this sandbox in a Claude Code settings file, and an exempted command runs outside the sandbox under the permission mode the user selects for the session. The macOS sandbox also blocks connections to local Unix sockets. A command that talks to a local agent through a socket, such as git signing a commit with a key held in an SSH agent or a hardware-backed key manager, cannot reach that agent from inside the sandbox. A user who needs such a command to work can list the agent's socket path under `sandbox.network.allowUnixSockets` in their Claude Code settings file, which keeps the command inside the sandbox. Every sandboxed command in that user's Code sessions can then ask the agent to sign or authenticate, so this is appropriate only for an agent that asks the user to approve each use, for example with Touch ID, and not for an agent that signs without prompting. See [Sandbox settings](https://code.claude.com/docs/en/settings-reference#sandbox-settings) in the Claude Code documentation. Exempting git commands such as `git commit` with `sandbox.excludedCommands` is not a safe way around the socket restriction. A sandboxed command can still change files that git runs during a commit, such as hook scripts kept in the working tree, and an exempted `git commit` would then run that code outside the sandbox. Git also cannot reach remotes over SSH from inside the sandbox, so a user who needs to push can use an HTTPS remote whose host is on the **Allowed network hosts** list, or push from a terminal outside the Code session. -On Windows, there is no operating-system-level sandbox for Code sessions. Shell commands run directly on the device under the permission mode the user selects for the session and under your agency's own endpoint and network controls. The **Allowed network hosts** and **Allowed workspace folders** settings do not confine what those commands can reach or change. +On Windows, there is no operating-system-level sandbox for Code sessions. Shell commands run directly on the device under the permission mode the user selects for the session and under your agency's own endpoint and network controls. The **Allowed network hosts** and **Allowed workspace folders** settings do not confine what those commands can reach, read, or change. -On both operating systems, the application starts a Code session only in a folder that **Allowed workspace folders** permits when that setting is configured. Administrators can also require a prompt on every shell command, in every permission mode, with the **Require approval for each command** sub-setting on the **Shell commands** card of the [Config](/docs/government/config/settings#tool-and-connector-cards) page. +On both operating systems, the application starts a Code session only in a folder that **Allowed workspace folders** permits when that setting is configured, and Claude's file reading and editing tools then work only inside the permitted folders. Administrators can also require a prompt on every shell command, in every permission mode, with the **Require approval for each command** sub-setting on the **Shell commands** card of the [Config](/docs/government/config/settings#tool-and-connector-cards) page. Code sessions in Claude for Government run on the local workstation only, and the environment options for Windows Subsystem for Linux (WSL) and SSH remote hosts are not available. Commands that belong to Claude Code's terminal interface, such as `/sandbox`, are not part of Code sessions in the desktop application. See [how your configuration reaches Code sessions](/docs/third-party/claude-desktop/code). If your agency also deploys Claude Code's own managed settings to the same devices, those settings take precedence over the macOS sandbox policy described above unless they opt in to merging, as that page explains. diff --git a/content/claude/third-party/claude-desktop/code.md b/content/claude/third-party/claude-desktop/code.md index ccb0e50a7..5f12023d2 100644 --- a/content/claude/third-party/claude-desktop/code.md +++ b/content/claude/third-party/claude-desktop/code.md @@ -18,31 +18,39 @@ Each key reaches Claude Code through one of two mechanisms, and the distinction These keys are passed directly to the Claude Code process as environment variables or launch options. They take effect on every Code session and cannot be overridden by user-level Claude Code settings or by a separately deployed `managed-settings.json`. -| Claude Desktop on 3P key | Effect in Code sessions | -| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| `inferenceProvider` and all provider credential keys (`inferenceGateway*`, `inferenceAnthropicApiKey`, `inferenceVertex*`, `inferenceBedrock*`, `inferenceFoundry*`, `inferenceCredentialHelper*`) | Selects the inference backend and supplies credentials. Code sessions use the same provider, endpoint, and credentials as Cowork sessions. | -| `inferenceModels` | Populates the model picker. The first entry is the default for new Code sessions. | -| `autoModeEnabled` | Offers **Auto mode** in the Code session's permission selector. A separately deployed Claude Code managed-settings file that sets `disableAutoMode` to `"disable"` overrides this and keeps Auto mode hidden; see below. | -| `disabledBuiltinTools` | Removes the listed tools from Code sessions. Tools your provider does not support, such as WebSearch on Amazon Bedrock, are removed automatically in addition to your list. | -| `builtinToolPolicy` | Tools set to `"ask"` require approval on each call in Code sessions, enforced via a PreToolUse hook and Claude Code `permissions.ask` rules. | -| `skipWebFetchPreflight` | Turns off Claude Code's Web Fetch [domain check](/docs/third-party/claude-desktop/web-tools#web-fetch) against `api.anthropic.com`. A separately deployed Claude Code managed-settings file that sets `skipWebFetchPreflight` takes precedence. | -| `managedMcpServers` | Makes the same managed MCP servers available in Code sessions. The app handles the connection and authentication; the Code session sees only the resulting tool list. | -| `mcpToolTimeoutSec` | Applies your per-call MCP tool timeout to Code sessions as well, taking precedence over a user-set `MCP_TOOL_TIMEOUT`. | -| `organizationInstructions` | Appended to the Code session's system prompt after Claude Code's own. `CLAUDE.md` instructions still apply. | -| `otlpEndpoint`, `otlpProtocol`, `otlpHeaders`, `otlpResourceAttributes` | Routes Claude Code's OpenTelemetry metrics and logs to your collector. See [Telemetry](/docs/third-party/claude-desktop/telemetry). | -| `disableEssentialTelemetry`, `disableNonessentialTelemetry` | Disables Claude Code's crash reporting and usage telemetry to Anthropic, mirroring Cowork. | -| `disableAutoUpdates` | The embedded Claude Code engine never self-updates regardless of this key; its version is managed by the app's own updater. | -| `inferenceMaxTokensPerWindow`, `inferenceTokenWindowHours` | The token budget is shared across Cowork and Code sessions and enforced before each turn. | +| Claude Desktop on 3P key | Effect in Code sessions | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `inferenceProvider` and all provider credential keys (`inferenceGateway*`, `inferenceAnthropicApiKey`, `inferenceVertex*`, `inferenceBedrock*`, `inferenceFoundry*`, `inferenceCredentialHelper*`) | Selects the inference backend and supplies credentials. Code sessions use the same provider, endpoint, and credentials as Cowork sessions. | +| `inferenceModels` | Populates the model picker. The first entry is the default for new Code sessions. | +| `autoModeEnabled` | Offers **Auto mode** in the Code session's permission selector. A separately deployed Claude Code managed-settings file that sets `disableAutoMode` to `"disable"` overrides this and keeps Auto mode hidden; see below. | +| `disabledBuiltinTools` | Removes the listed tools from Code sessions. Tools your provider does not support, such as WebSearch on Amazon Bedrock, are removed automatically in addition to your list. | +| `builtinToolPolicy` | Tools set to `"ask"` require approval on each call in Code sessions, enforced via a PreToolUse hook and Claude Code `permissions.ask` rules. | +| `disableBypassPermissionsMode` | Removes bypass permissions mode. The app stops offering the mode and starts a session that requests it in a stricter permission mode instead, independent of Claude Code managed-settings precedence. The key requires Claude Desktop 1.46388.1 or later. A separately deployed Claude Code managed-settings file that sets `permissions.disableBypassPermissionsMode` to `"disable"` removes the mode as well. | +| `skipWebFetchPreflight` | Turns off Claude Code's Web Fetch [domain check](/docs/third-party/claude-desktop/web-tools#web-fetch) against `api.anthropic.com`. A separately deployed Claude Code managed-settings file that sets `skipWebFetchPreflight` takes precedence. | +| `managedMcpServers` | Makes the same managed MCP servers available in Code sessions. The app handles the connection and authentication; the Code session sees only the resulting tool list. | +| `mcpToolTimeoutSec` | Applies your per-call MCP tool timeout to Code sessions as well, taking precedence over a user-set `MCP_TOOL_TIMEOUT`. | +| `organizationInstructions` | Appended to the Code session's system prompt after Claude Code's own. `CLAUDE.md` instructions still apply. | +| `otlpEndpoint`, `otlpProtocol`, `otlpHeaders`, `otlpResourceAttributes` | Routes Claude Code's OpenTelemetry metrics and logs to your collector. See [Telemetry](/docs/third-party/claude-desktop/telemetry). | +| `disableEssentialTelemetry`, `disableNonessentialTelemetry` | Disables Claude Code's crash reporting and usage telemetry to Anthropic, mirroring Cowork. | +| `disableAutoUpdates` | The embedded Claude Code engine never self-updates regardless of this key; its version is managed by the app's own updater. | +| `inferenceMaxTokensPerWindow`, `inferenceTokenWindowHours` | The token budget is shared across Cowork and Code sessions and enforced before each turn. | ### Applied as managed policy These keys are translated into Claude Code [managed settings](https://code.claude.com/docs/en/settings#settings-files) and supplied to the session as policy. They take precedence over user and project settings, but they participate in Claude Code's managed-settings precedence if you have also deployed a separate Claude Code policy. -| Claude Desktop on 3P key | Claude Code policy it produces | -| -------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `coworkEgressAllowedHosts` | A network sandbox restricted to your hosts plus the inference and telemetry endpoints, `WebFetch` permission rules for the same hosts, and `allowManagedDomainsOnly`. | -| `allowedWorkspaceFolders` | A filesystem sandbox (`sandbox.filesystem.allowRead` with `allowManagedReadPathsOnly`) scoped to your allowed roots. The roots are also passed as `additionalDirectories` at launch, which is always applied independent of managed-settings precedence. The app also refuses to start a Code session outside an allowed root. | -| `managedMcpServers` | `strictPluginOnlyCustomization` set to `["mcp"]`, so the Code session does not load MCP servers that users define on Claude Code's side (`~/.claude.json`, a project's `.mcp.json`, or `claude mcp add`); your managed servers, which the app connects and supplies to the session itself, and MCP servers bundled in plugins still load. When [`isLocalDevMcpEnabled`](/docs/third-party/claude-desktop/configuration#islocaldevmcpenabled) is `false`, the app also sets an `allowedMcpServers` list that admits only remote servers, with `allowManagedMcpServersOnly`, so local (stdio) servers bundled in plugins from marketplaces or that users install themselves are refused, while those plugins' remote servers still connect. Per-tool `toolPolicy` values on each server are emitted as `permissions.deny` (for `blocked`) or `permissions.ask` (for `ask`) rules against the corresponding `mcp____` names. | +| Claude Desktop on 3P key | Claude Code policy it produces | +| ------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `coworkEgressAllowedHosts` | A network sandbox restricted to your hosts plus the inference and telemetry endpoints, `WebFetch` permission rules for the same hosts, and `allowManagedDomainsOnly`. | +| `allowedWorkspaceFolders` | A filesystem sandbox for shell commands, which can then create or change files only inside your allowed roots and the session's temporary locations. The sandbox does not restrict which files those commands read unless you also set `blockReadsOutsideWorkingDirectories`. The roots are also passed as `additionalDirectories` at launch, which is always applied independent of managed-settings precedence, and the app keeps Claude's file tools inside the roots. The app also refuses to start a Code session outside an allowed root. | +| `blockReadsOutsideWorkingDirectories` | Claude Code's `permissions.blockReadsOutsideWorkingDirectories` for Code sessions. Claude's file tools refuse to read outside the working directories (the session's folder plus your allowed roots, if any) in every permission mode. Where the sandbox from `allowedWorkspaceFolders` or `coworkEgressAllowedHosts` is running, it also hides the user's home directory and similar locations, such as other users' home folders and mounted volumes, from shell commands, so a sandboxed command that reads there fails without a prompt. Without a running sandbox, a shell command that reads outside the working directories, or that Claude Code cannot analyze, asks the user for approval first, even in bypass permissions mode. The key requires Claude Desktop 1.46388.1 or later. The block takes effect only in sessions that run Claude Code v2.1.257 or later; if the app cannot install its current Claude Code engine and a session runs one older than v2.1.257 that is still on the device, that session runs without the block and the app logs a warning. | +| `managedMcpServers` | `strictPluginOnlyCustomization` set to `["mcp"]`, so the Code session does not load MCP servers that users define on Claude Code's side (`~/.claude.json`, a project's `.mcp.json`, or `claude mcp add`); your managed servers, which the app connects and supplies to the session itself, and MCP servers bundled in plugins still load. When [`isLocalDevMcpEnabled`](/docs/third-party/claude-desktop/configuration#islocaldevmcpenabled) is `false`, the app also sets an `allowedMcpServers` list that admits only remote servers, with `allowManagedMcpServersOnly`, so local (stdio) servers bundled in plugins from marketplaces or that users install themselves are refused, while those plugins' remote servers still connect. Per-tool `toolPolicy` values on each server are emitted as `permissions.deny` (for `blocked`) or `permissions.ask` (for `ask`) rules against the corresponding `mcp____` names. | + +The network and filesystem sandboxes apply on macOS, and on Linux devices and [SSH hosts](/docs/third-party/claude-desktop/ssh-remote-sessions#managed-configuration-on-the-remote-host) with Claude Code's [sandbox dependencies](https://code.claude.com/docs/en/sandboxing) installed. Claude Code does not sandbox shell commands on Windows devices, and on a Linux device or SSH host without the dependencies commands run unsandboxed with a warning in the session. In those cases, and when neither sandbox key is set, `blockReadsOutsideWorkingDirectories` still confines Claude's file tools but can only ask the user to approve shell commands that read outside the working directories or that Claude Code cannot verify. + +Under `blockReadsOutsideWorkingDirectories`, sandboxed shell commands can still read system locations such as `/usr`, the session's plugin and attachment folders (which become read-only), and the user's git configuration files (`~/.gitconfig` and the `config`, `ignore`, and `attributes` files under `~/.config/git`), which can themselves hold credentials such as tokens in remote URLs. Other files under the home folder outside the working directories are hidden from them, including `~/.ssh`, stored git credentials, included git configuration files, signing keys, and the target of a symlinked git configuration file, so git operations that need those files fail in the session until the user re-opens the paths. In a local session Claude also cannot read a file attached or `@`-mentioned from outside the working directories, so users should move such files into the session's folder or an allowed folder first. + +An allowed root that is or contains the home directory, such as `~` or `/Users`, leaves the home directory readable, so list folders below it. The block guards against content a session reads steering Claude into the user's files, not against the user, who can re-open any path, up to their whole home folder, with `sandbox.filesystem.allowRead` (shell commands) or `permissions.additionalDirectories` (file tools and shell commands) in their own Claude Code settings, while a settings file tracked in a git repository cannot. ## Interaction with Claude Code's own managed settings @@ -58,6 +66,8 @@ To have Claude Desktop's restrictions apply on top of your Claude Code policy, s With `"merge"`, Claude Desktop's policy values are layered under your Claude Code policy. Your values win any conflict, deny and allow lists are unioned, and Claude Desktop's values are filtered so they can only tighten policy, never loosen it. See [`parentSettingsBehavior`](https://code.claude.com/docs/en/settings-reference#parentsettingsbehavior) in the Claude Code settings reference. Requires Claude Code v2.1.133 or later, which ships with Claude Desktop on 3P. +With `"merge"`, two Claude Code policy keys weaken `blockReadsOutsideWorkingDirectories`. `sandbox.filesystem.allowManagedReadPathsOnly` limits the block to Claude's file tools, so a shell command that reads outside the working directories asks for approval instead of failing, and `allowManagedPermissionRulesOnly` removes the session's read access to its plugin and attachment folders, so skills that read their own files stop working. Leave both out of your Claude Code policy if you rely on the block. + In a third-party deployment there is no Anthropic authentication, so Claude Code's server-managed settings tier is never present. If you have not separately deployed a Claude Code `managed-settings.json` or OS profile, Claude Desktop's policy applies automatically and you do not need to set `parentSettingsBehavior`. diff --git a/content/claude/third-party/claude-desktop/configuration-changelog.md b/content/claude/third-party/claude-desktop/configuration-changelog.md index 872607a41..c7ac0a4dc 100644 --- a/content/claude/third-party/claude-desktop/configuration-changelog.md +++ b/content/claude/third-party/claude-desktop/configuration-changelog.md @@ -8,6 +8,10 @@ Configuration keys by Claude Desktop release. Each section lists keys added in that release, with the MDM key name (for plist/registry deployment) and the equivalent JSON shape (for local-file or bootstrap remote configuration). + + No configuration changes in this release. + + No configuration changes in this release. diff --git a/content/claude/third-party/claude-desktop/local-access.md b/content/claude/third-party/claude-desktop/local-access.md index b1666585b..e40c3107e 100644 --- a/content/claude/third-party/claude-desktop/local-access.md +++ b/content/claude/third-party/claude-desktop/local-access.md @@ -35,7 +35,7 @@ For example, `[{"path": "~/Documents/Claude"}, {"path": "/Volumes/Shared/Referen The check is enforced against the **resolved** path, so symlinks and `..` traversal can't be used to escape an allowed root. - The allowlist controls what users can **attach**. Within an attached read/write folder, the agent can read and write every file the user's OS account can reach. To keep data out of reach entirely, leave it outside the allowed roots. To let the agent read data in Cowork without changing it, list the folder with `mode` set to `ro`. + The allowlist controls what users can **attach**. Within an attached read/write folder, the agent can read and write every file the user's OS account can reach. Data outside the allowed roots cannot be attached in Cowork and is out of reach of Claude's file tools in Code sessions. A Code session's shell commands are confined only by the sandbox described under [Code](/docs/third-party/claude-desktop/code#applied-as-managed-policy): where it applies they can change files only inside the roots and temporary locations but can still read outside them unless you also set [`blockReadsOutsideWorkingDirectories`](/docs/third-party/claude-desktop/configuration#blockreadsoutsideworkingdirectories), and where it does not apply (Windows devices, hosts without the sandbox dependencies) the allowlist does not confine them and that key can only turn such reads into approval prompts. To let the agent read data in Cowork without changing it, list the folder with `mode` set to `ro`. ## Network drives on Windows diff --git a/content/claude/third-party/claude-desktop/ssh-remote-sessions.md b/content/claude/third-party/claude-desktop/ssh-remote-sessions.md index 2275d60ef..ae0a3665a 100644 --- a/content/claude/third-party/claude-desktop/ssh-remote-sessions.md +++ b/content/claude/third-party/claude-desktop/ssh-remote-sessions.md @@ -96,8 +96,9 @@ Most of the policy that Claude Desktop applies to a local Code session applies o * `disableEssentialTelemetry` and `disableNonessentialTelemetry`. * `otlpEndpoint`, `otlpProtocol`, `otlpHeaders`, `otlpResourceAttributes`, and `otlpContentCapture`. Remote sessions appear in your collector under the same `service.name` as local Code sessions. A collector at `localhost` on the device is not forwarded. An `otlpHeadersHelper` runs on the device at session start, and the remote session keeps those headers for its lifetime. -* `disabledBuiltinTools`, `builtinToolPolicy`, and `autoModeEnabled`. +* `disabledBuiltinTools`, `builtinToolPolicy`, `autoModeEnabled`, and `disableBypassPermissionsMode`. * [`allowedWorkspaceFolders`](/docs/third-party/claude-desktop/configuration#allowedworkspacefolders), evaluated against the host's filesystem. `~` is the SSH user's home on the host, `%VAR%` entries are ignored, and Claude Desktop refuses to start a session in a directory outside every entry, so a fleet value such as `~/Documents/Claude` confines remote sessions to that path under the SSH user's home. A folder with `mode` set to `ro` is allowed on the host but not read-only there. +* [`blockReadsOutsideWorkingDirectories`](/docs/third-party/claude-desktop/configuration#blockreadsoutsideworkingdirectories), evaluated on the host, so the working directories and the home directory it hides from shell commands are the SSH user's there. Hiding files from shell commands needs the host's sandbox dependencies (next item); on a host without them, or a Windows host, shell reads outside the working directories ask for approval instead, and the file-tool restriction applies regardless. Files a user attaches to a remote session stay readable, except on a Windows host, where the session's plugin files and attachments stay outside the file tools' reach under this key. * `coworkEgressAllowedHosts`, as Claude Code managed settings. The network and filesystem sandbox it produces with `allowedWorkspaceFolders` depends on the host having Claude Code's sandbox dependencies installed (see [Claude Code sandboxing](https://code.claude.com/docs/en/sandboxing)); without them, commands run unsandboxed and Claude Code shows a warning in the session. * `managedMcpServers`, as the Claude Code managed setting that keeps users from adding their own MCP servers. The managed servers themselves are reached from the device. * Plugins from your [allowed marketplaces](/docs/third-party/claude-desktop/extensions), copied to the host. A plugin's `hooks` directory is not copied, so its hooks do not run in a remote session, and a plugin whose manifest declares hooks elsewhere is not copied at all. diff --git a/content/en/api/admin.md b/content/en/api/admin.md index 102b437de..4faae670c 100644 --- a/content/en/api/admin.md +++ b/content/en/api/admin.md @@ -35,7 +35,7 @@ Retrieve information about the organization associated with the authenticated AP ```bash curl https://api.anthropic.com/v1/organizations/me \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -170,7 +170,7 @@ On plans that draw members from a finite pool of purchased seats, the invite aut curl https://api.anthropic.com/v1/organizations/invites \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "email": "user@emaildomain.com", "role": "user" @@ -288,7 +288,7 @@ Retrieve an invite by ID. ```bash curl https://api.anthropic.com/v1/organizations/invites/$INVITE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -448,7 +448,7 @@ List the organization's invites. ```bash curl https://api.anthropic.com/v1/organizations/invites \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -508,7 +508,7 @@ Delete a pending invite. curl https://api.anthropic.com/v1/organizations/invites/$INVITE_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -591,7 +591,7 @@ Retrieve a member of the organization by user ID. ```bash curl https://api.anthropic.com/v1/organizations/users/$USER_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -712,7 +712,7 @@ List the organization's members. ```bash curl https://api.anthropic.com/v1/organizations/users \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -823,7 +823,7 @@ Update a member's organization role. curl https://api.anthropic.com/v1/organizations/users/$USER_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "role": "user" }' @@ -874,7 +874,7 @@ Remove a member from the organization. curl https://api.anthropic.com/v1/organizations/users/$USER_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -967,7 +967,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_groups \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1055,7 +1055,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1140,7 +1140,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "name": "Engineering" }' @@ -1166,7 +1166,7 @@ curl https://api.anthropic.com/v1/organizations/rbac_groups \ **POST** `/v1/organizations/rbac_groups/{group_id}` -Update an RBAC Group's name. Groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. +Update an RBAC Group's name. Groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -1234,7 +1234,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "name": "Engineering" }' @@ -1260,7 +1260,7 @@ curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ **DELETE** `/v1/organizations/rbac_groups/{group_id}` -Delete an RBAC Group. Groups provisioned by an identity provider (source type `"scim"`) cannot be deleted via the API. +Delete an RBAC Group. Groups provisioned by an identity provider (source type `"scim"`) cannot be deleted via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -1292,7 +1292,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1377,7 +1377,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1402,7 +1402,7 @@ curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ **POST** `/v1/organizations/rbac_groups/{group_id}/members` -Add a User to an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. +Add a User to an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -1454,7 +1454,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q" }' @@ -1476,7 +1476,7 @@ curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ **DELETE** `/v1/organizations/rbac_groups/{group_id}/members/{user_id}` -Remove a User from an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. +Remove a User from an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -1514,7 +1514,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members/$USER_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1597,7 +1597,7 @@ The RBAC Roles API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_roles \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1669,7 +1669,7 @@ The RBAC Roles API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_roles/$ROLE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1841,7 +1841,7 @@ The RBAC Roles API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_roles/$ROLE_ID/permissions \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1915,15 +1915,25 @@ Create Workspace Geographic region for workspace data storage. Immutable after creation. Defaults to 'us' if omitted. +- `display_color: optional string or null` + + Hex color code representing the Workspace in the Anthropic Console. + + maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$ + - `external_key_id: optional string or null` ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `tags: optional map[string] or null` @@ -1949,8 +1959,13 @@ Create Workspace customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -1987,10 +2002,14 @@ Create Workspace ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -2014,9 +2033,10 @@ Create Workspace curl https://api.anthropic.com/v1/organizations/workspaces \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "name": "x", + "display_color": "#6C5BB9", "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK", "tags": { "env": "prod", @@ -2081,8 +2101,13 @@ Get Workspace customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -2119,10 +2144,14 @@ Get Workspace ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -2145,7 +2174,7 @@ Get Workspace ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -2222,8 +2251,13 @@ List Workspaces customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -2260,10 +2294,14 @@ List Workspaces ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -2298,7 +2336,7 @@ List Workspaces ```bash curl https://api.anthropic.com/v1/organizations/workspaces \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -2368,15 +2406,25 @@ Update Workspace - `"us"` +- `display_color: optional string` + + Hex color code representing the Workspace in the Anthropic Console. + + maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$ + - `external_key_id: optional string` ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: optional string` @@ -2408,8 +2456,13 @@ Update Workspace customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -2446,10 +2499,14 @@ Update Workspace ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -2473,8 +2530,9 @@ Update Workspace curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ + "display_color": "#6C5BB9", "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK", "tags": { "env": "prod", @@ -2537,8 +2595,13 @@ Archive Workspace customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -2575,10 +2638,14 @@ Archive Workspace ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -2602,7 +2669,7 @@ Archive Workspace curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -2701,7 +2768,7 @@ Create Workspace Member curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q", "workspace_role": "workspace_admin" @@ -2774,7 +2841,7 @@ Get Workspace Member ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -2869,7 +2936,7 @@ List Workspace Members ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -2962,7 +3029,7 @@ Update Workspace Member curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_role": "workspace_admin" }' @@ -3019,7 +3086,7 @@ Delete Workspace Member curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -3044,6 +3111,10 @@ Returns only the groups and limiter types that have a workspace-level override. Groups without overrides inherit the organization limits and are not listed; use `GET /v1/organizations/rate_limits` to see those. +When `limit` is omitted, every matching entry is returned in a single +page; when `limit` truncates the result, follow `next_page` to fetch +the remaining entries. + #### Path parameters - `workspace_id: string` @@ -3068,6 +3139,14 @@ are not listed; use `GET /v1/organizations/rate_limits` to see those. - `"web_search"` +- `limit: optional number` + + Maximum number of items to return per page. Ranges from `1` to `1000`. + + When omitted, every remaining entry is returned in a single page and `next_page` is `null`. + + maximum: 1000, minimum: 1 + - `page: optional string` Opaque cursor from a previous response's `next_page`. @@ -3130,14 +3209,14 @@ are not listed; use `GET /v1/organizations/rate_limits` to see those. - `next_page: string or null` - Token to provide in as `page` in the subsequent request to retrieve the next page of data. + Opaque cursor for the next page of results, or `null` when no entries remain beyond this response. #### Example ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/rate_limits \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -3172,6 +3251,8 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/rate_li **POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Add a service account to a workspace with the given `workspace_role`. The role determines what the service account can do in the workspace and @@ -3181,8 +3262,7 @@ through federation. Every service account is already an implicit assigns a chosen role. If the service account is already an explicit member of the workspace, its `workspace_role` is replaced with the value supplied here. Archived workspaces return 400. Archived service -accounts cannot be added and are rejected. Requires an OAuth bearer or -Console session; Admin API keys are not accepted. +accounts cannot be added and are rejected. #### Path parameters @@ -3258,7 +3338,7 @@ Console session; Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "service_account_id": "service_account_id", "workspace_role": "workspace_admin" @@ -3282,6 +3362,8 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service **GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a service account's membership in a workspace. Returns the membership record, including the service account's @@ -3350,7 +3432,7 @@ account returns 404. ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -3370,6 +3452,8 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service **GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List the service accounts that are members of a workspace. Each entry includes the service account's `workspace_role`. Use `limit` @@ -3452,7 +3536,7 @@ omitted from the results. ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -3477,6 +3561,8 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service **POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Change a service account's role in a workspace. The new `workspace_role` replaces the current one. Only explicit @@ -3484,8 +3570,7 @@ memberships can be updated; to set a role on the implicit default-workspace membership, add the service account explicitly with `POST /workspaces/{workspace_id}/service_accounts`. Archived workspaces return 400. Archived service accounts cannot be updated and are -rejected. Requires an OAuth bearer or Console session; Admin API keys -are not accepted. +rejected. #### Path parameters @@ -3561,7 +3646,7 @@ are not accepted. curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_role": "workspace_admin" }' @@ -3584,14 +3669,15 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service **DELETE** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Remove a service account from a workspace. Removal is idempotent (returns 200 even if the membership was already removed). A DELETE against the implicit default-workspace membership returns 200 but is a no-op and the membership persists; deleting an explicit default-workspace row reverts to the implicit `workspace_user` -membership. Archived workspaces return 400. Requires an OAuth bearer or -Console session; Admin API keys are not accepted. +membership. Archived workspaces return 400. #### Path parameters @@ -3631,7 +3717,7 @@ Console session; Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -3787,7 +3873,7 @@ Retrieve information about a single API key in your organization, looked up by i ```bash curl https://api.anthropic.com/v1/organizations/api_keys/$API_KEY_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -4002,7 +4088,7 @@ List API Keys ```bash curl https://api.anthropic.com/v1/organizations/api_keys \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -4199,7 +4285,7 @@ Update API Key curl https://api.anthropic.com/v1/organizations/api_keys/$API_KEY_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` @@ -4248,7 +4334,7 @@ Create an external key config owned by the caller's organization. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -4262,7 +4348,7 @@ Create an external key config owned by the caller's organization. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -4346,7 +4432,7 @@ Create an external key config owned by the caller's organization. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -4360,7 +4446,7 @@ Create an external key config owned by the caller's organization. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -4404,7 +4490,7 @@ Create an external key config owned by the caller's organization. curl https://api.anthropic.com/v1/organizations/external_keys \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "provider_config": { "kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222", @@ -4500,7 +4586,7 @@ Results are ordered by creation time (newest first). Use the - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -4514,7 +4600,7 @@ Results are ordered by creation time (newest first). Use the **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -4561,7 +4647,7 @@ Results are ordered by creation time (newest first). Use the ```bash curl https://api.anthropic.com/v1/organizations/external_keys \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -4647,7 +4733,7 @@ Retrieve a single external key config in the caller's organization by ID. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -4661,7 +4747,7 @@ Retrieve a single external key config in the caller's organization by ID. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -4704,7 +4790,7 @@ Retrieve a single external key config in the caller's organization by ID. ```bash curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -4767,7 +4853,7 @@ encrypted data requires the original key identity to decrypt. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -4781,7 +4867,7 @@ encrypted data requires the original key identity to decrypt. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -4855,7 +4941,7 @@ encrypted data requires the original key identity to decrypt. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -4869,7 +4955,7 @@ encrypted data requires the original key identity to decrypt. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -4913,7 +4999,7 @@ encrypted data requires the original key identity to decrypt. curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` @@ -4971,7 +5057,7 @@ The request is rejected if any workspace still references this config. curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -5026,7 +5112,7 @@ message if it failed or timed out. curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/validate \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -5304,7 +5390,7 @@ Get Messages Usage Report ```bash curl https://api.anthropic.com/v1/organizations/usage_report/messages \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -5530,7 +5616,7 @@ Enables organizations to analyze developer productivity and build custom dashboa ```bash curl https://api.anthropic.com/v1/organizations/usage_report/claude_code \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -5776,7 +5862,7 @@ Get Cost Report ```bash curl https://api.anthropic.com/v1/organizations/cost_report \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -6054,6 +6140,28 @@ key with the `read:analytics` scope. - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -6070,12 +6178,16 @@ key with the `read:analytics` scope. format: date-time -- `group_by: optional array of "context_window" or "inference_geo" or "model" or 4 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 6 more` Dimensions to break each time bucket out by. Defaults to no grouping (one total per bucket). Each bucket reports at most its top 100 groups; a group beyond that cap has no row in that bucket (there is no remainder row), so grouped buckets are not exhaustive when a dimension has more than 100 distinct values. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"inference_geo"` @@ -6200,6 +6312,24 @@ key with the `read:analytics` scope. The number of input tokens read from the cache. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -6306,6 +6436,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/usage_report \ "ephemeral_5m_input_tokens": 500 }, "cache_read_input_tokens": 0, + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "inference_geo": "global", "model": "claude-opus-5", @@ -6363,6 +6495,28 @@ organizations on a Claude Enterprise plan. Requires an API key with the - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -6385,12 +6539,16 @@ organizations on a Claude Enterprise plan. Requires an API key with the default: false -- `group_by: optional array of "context_window" or "inference_geo" or "model" or 4 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 6 more` Break each actor's row out by the given dimensions. Accepts the same values as the bucketed `/usage_report` endpoint. `limit` bounds (actor × time bucket × dimension) rows — with dimensions or `bucket_width` present, one actor may span several rows. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"inference_geo"` @@ -6553,6 +6711,24 @@ organizations on a Claude Enterprise plan. Requires an API key with the The number of input tokens read from the cache. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -6673,6 +6849,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/user_usage_report \ "ephemeral_5m_input_tokens": 500 }, "cache_read_input_tokens": 3200000, + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "ending_at": "2019-12-27T18:11:19.117Z", "inference_geo": "global", @@ -6731,6 +6909,28 @@ Requires an API key with the `read:analytics` scope. - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -6747,12 +6947,16 @@ Requires an API key with the `read:analytics` scope. format: date-time -- `group_by: optional array of "context_window" or "cost_type" or "inference_geo" or 6 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 8 more` Dimensions to break each time bucket out by. Defaults to no grouping (one total per bucket). Each bucket reports at most its top 100 groups; a group beyond that cap has no row in that bucket (there is no remainder row), so grouped buckets are not exhaustive when a dimension has more than 100 distinct values. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"cost_type"` @@ -6869,6 +7073,24 @@ Requires an API key with the `read:analytics` scope. Amount (post-discount, pre-credit) in fractional cents. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -6989,6 +7211,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/cost_report \ "results": [ { "amount": "amount", + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "cost_type": "code_execution", "currency": "USD", @@ -7045,6 +7269,28 @@ organizations on a Claude Enterprise plan. Requires an API key with the - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -7067,12 +7313,16 @@ organizations on a Claude Enterprise plan. Requires an API key with the default: false -- `group_by: optional array of "context_window" or "cost_type" or "inference_geo" or 6 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 8 more` Break each actor's row out by the given dimensions. Accepts the same values as the bucketed `/cost_report` endpoint. The `product`, `model`, `context_window`, `inference_geo`, and `speed` dimensions — and the time bucket, when `bucket_width` is set — count toward `limit`. `cost_type` and `token_type` do not: `cost_type` returns one row per cost component (tokens, web search, code execution); `token_type` returns one row per token type, each with `cost_type: "tokens"`; combining both returns the per-token-type rows plus the web-search and code-execution rows. A page can therefore contain more rows than `limit` when `cost_type` or `token_type` is requested. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"cost_type"` @@ -7223,6 +7473,24 @@ organizations on a Claude Enterprise plan. Requires an API key with the Amount (post-discount, pre-credit) in fractional cents (minor units). + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -7353,6 +7621,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/user_cost_report \ "user_id": "user_01AbCdEfGhIjKlMnOpQrSt" }, "amount": "41280.000000", + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "cost_type": "code_execution", "currency": "USD", @@ -8095,7 +8365,7 @@ on a Claude Enterprise plan. Requires an API key with the - `skill_display_name: optional string or null` - Human-readable display name for rows whose `skill_name` is an opaque skill id (user/organization skill types — user-defined names are withheld from the analytics pipeline). Only organization-shared skills resolve; the literal 'unknown' bucket row also gets a fixed 'Unknown skill' label. Null for private (user-defined) skills — their names are not disclosed to analytics-key holders — and null when `skill_name` is already a display name, when the skill was deleted, or when display-name resolution is not enabled for this organization. + Human-readable display name for rows whose `skill_name` is an opaque skill id (user/organization skill types and plugin-delivered skills — user-defined names are withheld from the analytics pipeline). Organization-shared skills and skills delivered by the organization's own plugins (its plugin marketplaces and its library) resolve; plugin skill names are shown without their 'plugin:' prefix. The literal 'unknown' bucket row gets a fixed 'Unknown skill' label. Null for private (user-defined) skills and members' personal-plugin skills — those names are not disclosed to analytics-key holders — and for Anthropic-provided plugin skills (not resolved), and null when `skill_name` is already a display name, when the skill or plugin was deleted, or when display-name resolution is not enabled for this organization. - `user_id: optional string or null` @@ -9031,7 +9301,7 @@ group, and organization-level defaults are configured in claude.ai. curl https://api.anthropic.com/v1/organizations/spend_limits \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "amount": "50000", "scope": { @@ -9171,7 +9441,7 @@ Retrieve a spend limit by ID. ```bash curl https://api.anthropic.com/v1/organizations/spend_limits/$SPEND_LIMIT_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -9222,7 +9492,7 @@ this endpoint. curl https://api.anthropic.com/v1/organizations/spend_limits/$SPEND_LIMIT_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -9401,7 +9671,7 @@ Paginates by member, so a member's periods never split across pages. ```bash curl https://api.anthropic.com/v1/organizations/spend_limits/effective \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -9708,7 +9978,7 @@ Requests whose requester is no longer a member are excluded. ```bash curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -10015,7 +10285,7 @@ requester at the request's period. ```bash curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$SPEND_LIMIT_INCREASE_REQUEST_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -10426,7 +10696,7 @@ the member was blocked on. Anthropic emails the requester unless curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$SPEND_LIMIT_INCREASE_REQUEST_ID/approve \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "amount": "50000", "period": "monthly" @@ -10750,7 +11020,7 @@ Idempotent on `denied`; denying an already-`approved` request returns curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$SPEND_LIMIT_INCREASE_REQUEST_ID/deny \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` @@ -10815,6 +11085,10 @@ Each entry corresponds to one rate-limit group (either a model family or an API-surface category such as the Files API or Message Batches) and contains the set of limiter values that apply to it. +When `limit` is omitted, every matching entry is returned in a single +page; when `limit` truncates the result, follow `next_page` to fetch +the remaining entries. + #### Query parameters - `group_type: optional "batch" or "files" or "model_group" or 3 more` @@ -10833,6 +11107,14 @@ and contains the set of limiter values that apply to it. - `"web_search"` +- `limit: optional number` + + Maximum number of items to return per page. Ranges from `1` to `1000`. + + When omitted, every remaining entry is returned in a single page and `next_page` is `null`. + + maximum: 1000, minimum: 1 + - `model: optional string` Filter to the single entry containing this model. Accepts full model names and aliases. Returns 404 if the model is not found or has no rate limits for this organization. @@ -10891,14 +11173,14 @@ and contains the set of limiter values that apply to it. - `next_page: string or null` - Token to provide in as `page` in the subsequent request to retrieve the next page of data. + Opaque cursor for the next page of results, or `null` when no entries remain beyond this response. #### Example ```bash curl https://api.anthropic.com/v1/organizations/rate_limits \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -10931,16 +11213,17 @@ curl https://api.anthropic.com/v1/organizations/rate_limits \ **POST** `/v1/organizations/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Create a service account. A service account is a named workload identity that federation rules target. `organization_role` is `developer` (default) or `admin`; a rule may only be created or retargeted to grant `org:admin` scope when the -target's `organization_role` is `admin`. Requires an OAuth bearer (user -or WIF-minted service account token) or a Console session; Admin API -keys are not accepted. Creating an `admin`-role service account requires -an interactive credential (a user OAuth token or a Console session) — a -workload may only create `developer`-role service accounts. +target's `organization_role` is `admin`. Creating an `admin`-role service +account requires an interactive credential (a user OAuth token or a +Console session) — a workload may only create `developer`-role service +accounts. #### Headers @@ -11041,7 +11324,7 @@ workload may only create `developer`-role service accounts. curl https://api.anthropic.com/v1/organizations/service_accounts \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "name": "ci-deploy-bot" }' @@ -11069,6 +11352,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts \ **GET** `/v1/organizations/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a service account by its ID (`svac_...`). #### Path parameters @@ -11153,7 +11438,7 @@ Retrieve a service account by its ID (`svac_...`). ```bash curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -11178,6 +11463,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **GET** `/v1/organizations/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List service accounts in the caller's organization. Results are ordered by creation time, newest first. Use `limit` and the @@ -11277,7 +11564,7 @@ archived service accounts. ```bash curl https://api.anthropic.com/v1/organizations/service_accounts \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -11307,13 +11594,14 @@ curl https://api.anthropic.com/v1/organizations/service_accounts \ **POST** `/v1/organizations/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Update a service account. Only `description` and `organization_role` are mutable; `name` cannot be changed. Archived service accounts cannot be updated; this returns 400. Setting `organization_role` to `admin` (even when unchanged) requires an -interactive credential (a user OAuth token or a Console session). Admin -API keys are not accepted. +interactive credential (a user OAuth token or a Console session). #### Path parameters @@ -11414,7 +11702,7 @@ API keys are not accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` @@ -11440,6 +11728,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **POST** `/v1/organizations/service_accounts/{service_account_id}/archive` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Archive a service account. Idempotent; re-archiving returns the service account with its original @@ -11447,9 +11737,6 @@ Idempotent; re-archiving returns the service account with its original rule still targets this service account, same as issuer archival; archive those rules first or change their target to another service account. -Requires an OAuth bearer or Console session; Admin API keys are not -accepted. - #### Path parameters - `service_account_id: string` @@ -11533,7 +11820,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -11560,6 +11847,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **POST** `/v1/organizations/service_accounts/{service_account_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Add a service account to a workspace with the given `workspace_role`. Mirror of `POST /workspaces/{workspace_id}/service_accounts`, addressed @@ -11567,8 +11856,7 @@ from the service-account side; both create the same membership. If the service account is already an explicit member of the workspace, its `workspace_role` is replaced with the value supplied here. Archived workspaces return 400. Archived service accounts cannot be added and are -rejected. Requires an OAuth bearer or Console session; Admin API keys -are not accepted. +rejected. #### Path parameters @@ -11644,7 +11932,7 @@ are not accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_id": "workspace_id", "workspace_role": "workspace_admin" @@ -11668,6 +11956,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **GET** `/v1/organizations/service_accounts/{service_account_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List the workspaces a service account is a member of. Each entry includes the service account's `workspace_role` in that @@ -11677,8 +11967,12 @@ implicit (`implicit: true`) membership is returned as the first entry on the first page; with `limit=1` the first page may return up to 2 entries (the implicit entry plus one explicit membership) so a pagination cursor can be derived. Memberships are returned only while -the service account is active; an archived service account returns an -empty list. +the service account is active. Without a `page` cursor, an archived +service account returns an empty list. A `page` cursor that does not +match an active membership returns a 400 invalid-request error. A cursor +stops matching when the membership is removed, the workspace is deleted, +or the service account is archived. Restart pagination from the first +page to recover. #### Path parameters @@ -11753,7 +12047,7 @@ empty list. ```bash curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -11778,6 +12072,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **DELETE** `/v1/organizations/service_accounts/{service_account_id}/workspaces/{workspace_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Remove a service account from a workspace. Mirror of `DELETE /workspaces/{workspace_id}/service_accounts/{service_account_id}`, @@ -11786,8 +12082,7 @@ addressed from the service-account side. Removal is idempotent (returns implicit default-workspace membership returns 200 but is a no-op and the membership persists; deleting an explicit default-workspace row reverts to the implicit `workspace_user` membership. Archived workspaces return -400. Requires an OAuth bearer or Console session; Admin API keys are not -accepted. +400. #### Path parameters @@ -11827,7 +12122,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces/$WORKSPACE_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -11846,6 +12141,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **POST** `/v1/organizations/federation_issuers` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Register an OIDC issuer that Anthropic will trust for workload identity federation in your organization. @@ -11858,9 +12155,6 @@ publicly reachable over HTTPS so Anthropic can fetch the discovery document; for `explicit_url` and `inline` modes the issuer URL is only matched as the JWT's `iss` claim and is not fetched. -Requires an OAuth bearer or Console session; Admin API keys are not -accepted. - #### Headers - `"anthropic-beta": optional array of string` @@ -12092,7 +12386,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/federation_issuers \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "issuer_url": "x", "name": "x" @@ -12133,6 +12427,8 @@ curl https://api.anthropic.com/v1/organizations/federation_issuers \ **GET** `/v1/organizations/federation_issuers/{federation_issuer_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a federation issuer by its ID (`fdis_...`). #### Path parameters @@ -12297,7 +12593,7 @@ Retrieve a federation issuer by its ID (`fdis_...`). ```bash curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -12334,6 +12630,8 @@ curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_I **GET** `/v1/organizations/federation_issuers` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List federation issuers in your organization. Archived issuers are excluded unless `include_archived=true`. @@ -12511,7 +12809,7 @@ Archived issuers are excluded unless `include_archived=true`. ```bash curl https://api.anthropic.com/v1/organizations/federation_issuers \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -12553,6 +12851,8 @@ curl https://api.anthropic.com/v1/organizations/federation_issuers \ **POST** `/v1/organizations/federation_issuers/{federation_issuer_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Partially update a federation issuer. Setting `jwks` replaces the full JWKS shape at once. Archived issuers @@ -12560,8 +12860,7 @@ cannot be updated; this returns 400. Create a new issuer instead. Updating an issuer that backs a rule with a scope outside `workspace:developer` or `workspace:inference` requires a Console -session. Requires an OAuth bearer or Console session; Admin API keys -are not accepted. +session. #### Path parameters @@ -12804,7 +13103,7 @@ are not accepted. curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` @@ -12842,6 +13141,8 @@ curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_I **POST** `/v1/organizations/federation_issuers/{federation_issuer_id}/archive` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Archive a federation issuer. Idempotent; re-archiving returns the issuer with its original @@ -12849,9 +13150,6 @@ Idempotent; re-archiving returns the issuer with its original rule still references the issuer; archive those rules first (a rule's issuer cannot be changed), or recreate them against another issuer. -Requires an OAuth bearer or Console session; Admin API keys are not -accepted. - #### Path parameters - `federation_issuer_id: string` @@ -13015,7 +13313,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -13054,6 +13352,8 @@ curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_I **POST** `/v1/organizations/federation_rules` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Create a federation rule owned by your organization. The referenced issuer and the target service account must already exist @@ -13068,8 +13368,7 @@ identity-bearing claim, a tenant-pinning subject prefix (such as `repo:YOUR_ORG/...`), or a CEL condition referencing one of those identity claims (e.g. `claims.repository_owner`). OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or -`workspace:inference`; other scopes require a Console session. Admin API -keys are not accepted. +`workspace:inference`; other scopes require a Console session. #### Headers @@ -13300,7 +13599,7 @@ keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "issuer_id": "issuer_id", "match": {}, @@ -13359,6 +13658,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules \ **GET** `/v1/organizations/federation_rules/{federation_rule_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a federation rule by its ID (`fdrl_...`). #### Path parameters @@ -13513,7 +13814,7 @@ Retrieve a federation rule by its ID (`fdrl_...`). ```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -13562,6 +13863,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RUL **GET** `/v1/organizations/federation_rules` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List federation rules in your organization. Optionally filter by issuer with `issuer_id`. Archived rules are excluded @@ -13728,7 +14031,7 @@ unless `include_archived=true`. ```bash curl https://api.anthropic.com/v1/organizations/federation_rules \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -13782,6 +14085,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules \ **POST** `/v1/organizations/federation_rules/{federation_rule_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Partially update a federation rule. `issuer_id` is immutable. `match` and `target` are replaced as whole @@ -13798,7 +14103,7 @@ match does not yet constrain tenant identity, any update (even a rename or description change) must also supply a conforming `match` in the same request. OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or `workspace:inference`; other scopes require a -Console session. Admin API keys are not accepted. +Console session. #### Path parameters @@ -14035,7 +14340,7 @@ Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` @@ -14085,6 +14390,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RUL **POST** `/v1/organizations/federation_rules/{federation_rule_id}/archive` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Archive a federation rule. Token exchange through this rule stops immediately. Idempotent; @@ -14093,7 +14400,7 @@ clears the rule's workspace targeting (`workspace_id` and `workspace_ids` are emptied). Tokens already minted before archive remain valid until they expire. OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or `workspace:inference`; -other scopes require a Console session. Admin API keys are not accepted. +other scopes require a Console session. #### Path parameters @@ -14248,7 +14555,7 @@ other scopes require a Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -14299,6 +14606,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RUL **GET** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List workspaces where this federation rule is enabled. Returns all workspace enablements in a single response; the `limit` and @@ -14372,7 +14681,7 @@ rules with `applies_to_all_workspaces` or a legacy single ```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -14397,6 +14706,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RUL **POST** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Enable a federation rule for a workspace. Idempotent; re-enabling returns the existing enablement. The rule and @@ -14404,9 +14715,9 @@ workspace must both belong to your organization. Membership of the rule's target service account in this workspace is not checked at enablement: token exchange into this workspace is rejected unless the target is a member (it is implicitly a member of the default workspace). -Archived rules are rejected with 400. OAuth callers may only manage rules whose -`oauth_scope` is `workspace:developer` or `workspace:inference`; other -scopes require a Console session. Admin API keys are not accepted. +Archived rules are rejected with 400. OAuth callers may only manage rules +whose `oauth_scope` is `workspace:developer` or `workspace:inference`; +other scopes require a Console session. #### Path parameters @@ -14462,7 +14773,7 @@ scopes require a Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_id": "workspace_id" }' @@ -14485,12 +14796,14 @@ curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RUL **DELETE** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Disable a federation rule for a workspace. Idempotent; succeeds even if the enablement was already removed. OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or `workspace:inference`; other scopes require a -Console session. Admin API keys are not accepted. +Console session. #### Path parameters @@ -14530,7 +14843,7 @@ Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces/$WORKSPACE_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -14612,7 +14925,7 @@ Retrieve a single tunnel in the caller's organization by ID. ```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -14725,7 +15038,7 @@ archived tunnels are excluded unless `include_archived` is set. ```bash curl https://api.anthropic.com/v1/organizations/tunnels \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -14797,7 +15110,7 @@ access logs. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/reveal_token \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -14867,7 +15180,7 @@ restarted after rotation must use the new value. An optional curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/rotate_token \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -14953,7 +15266,7 @@ tunnel returns the existing record unchanged. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -15054,7 +15367,7 @@ holds at most two non-archived certificates. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "ca_certificate_pem": "-----BEGIN CERTIFICATE-----\nMIIBexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexa\n...illustrative placeholder, not a real certificate...\n-----END CERTIFICATE-----\n" }' @@ -15145,7 +15458,7 @@ Retrieve a single certificate registered on a tunnel by ID. ```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -15257,7 +15570,7 @@ Archived certificates are excluded unless `include_archived` is set. ```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -15355,7 +15668,7 @@ certificate is added. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) diff --git a/content/en/api/admin/analytics.md b/content/en/api/admin/analytics.md index 1575e609a..1506e91c4 100644 --- a/content/en/api/admin/analytics.md +++ b/content/en/api/admin/analytics.md @@ -482,6 +482,28 @@ key with the `read:analytics` scope. - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -498,12 +520,16 @@ key with the `read:analytics` scope. format: date-time -- `group_by: optional array of "context_window" or "inference_geo" or "model" or 4 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 6 more` Dimensions to break each time bucket out by. Defaults to no grouping (one total per bucket). Each bucket reports at most its top 100 groups; a group beyond that cap has no row in that bucket (there is no remainder row), so grouped buckets are not exhaustive when a dimension has more than 100 distinct values. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"inference_geo"` @@ -628,6 +654,24 @@ key with the `read:analytics` scope. The number of input tokens read from the cache. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -734,6 +778,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/usage_report \ "ephemeral_5m_input_tokens": 500 }, "cache_read_input_tokens": 0, + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "inference_geo": "global", "model": "claude-opus-5", @@ -791,6 +837,28 @@ organizations on a Claude Enterprise plan. Requires an API key with the - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -813,12 +881,16 @@ organizations on a Claude Enterprise plan. Requires an API key with the default: false -- `group_by: optional array of "context_window" or "inference_geo" or "model" or 4 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 6 more` Break each actor's row out by the given dimensions. Accepts the same values as the bucketed `/usage_report` endpoint. `limit` bounds (actor × time bucket × dimension) rows — with dimensions or `bucket_width` present, one actor may span several rows. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"inference_geo"` @@ -981,6 +1053,24 @@ organizations on a Claude Enterprise plan. Requires an API key with the The number of input tokens read from the cache. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -1101,6 +1191,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/user_usage_report \ "ephemeral_5m_input_tokens": 500 }, "cache_read_input_tokens": 3200000, + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "ending_at": "2019-12-27T18:11:19.117Z", "inference_geo": "global", @@ -1159,6 +1251,28 @@ Requires an API key with the `read:analytics` scope. - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -1175,12 +1289,16 @@ Requires an API key with the `read:analytics` scope. format: date-time -- `group_by: optional array of "context_window" or "cost_type" or "inference_geo" or 6 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 8 more` Dimensions to break each time bucket out by. Defaults to no grouping (one total per bucket). Each bucket reports at most its top 100 groups; a group beyond that cap has no row in that bucket (there is no remainder row), so grouped buckets are not exhaustive when a dimension has more than 100 distinct values. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"cost_type"` @@ -1297,6 +1415,24 @@ Requires an API key with the `read:analytics` scope. Amount (post-discount, pre-credit) in fractional cents. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -1417,6 +1553,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/cost_report \ "results": [ { "amount": "amount", + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "cost_type": "code_execution", "currency": "USD", @@ -1473,6 +1611,28 @@ organizations on a Claude Enterprise plan. Requires an API key with the - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -1495,12 +1655,16 @@ organizations on a Claude Enterprise plan. Requires an API key with the default: false -- `group_by: optional array of "context_window" or "cost_type" or "inference_geo" or 6 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 8 more` Break each actor's row out by the given dimensions. Accepts the same values as the bucketed `/cost_report` endpoint. The `product`, `model`, `context_window`, `inference_geo`, and `speed` dimensions — and the time bucket, when `bucket_width` is set — count toward `limit`. `cost_type` and `token_type` do not: `cost_type` returns one row per cost component (tokens, web search, code execution); `token_type` returns one row per token type, each with `cost_type: "tokens"`; combining both returns the per-token-type rows plus the web-search and code-execution rows. A page can therefore contain more rows than `limit` when `cost_type` or `token_type` is requested. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"cost_type"` @@ -1651,6 +1815,24 @@ organizations on a Claude Enterprise plan. Requires an API key with the Amount (post-discount, pre-credit) in fractional cents (minor units). + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -1781,6 +1963,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/user_cost_report \ "user_id": "user_01AbCdEfGhIjKlMnOpQrSt" }, "amount": "41280.000000", + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "cost_type": "code_execution", "currency": "USD", @@ -2523,7 +2707,7 @@ on a Claude Enterprise plan. Requires an API key with the - `skill_display_name: optional string or null` - Human-readable display name for rows whose `skill_name` is an opaque skill id (user/organization skill types — user-defined names are withheld from the analytics pipeline). Only organization-shared skills resolve; the literal 'unknown' bucket row also gets a fixed 'Unknown skill' label. Null for private (user-defined) skills — their names are not disclosed to analytics-key holders — and null when `skill_name` is already a display name, when the skill was deleted, or when display-name resolution is not enabled for this organization. + Human-readable display name for rows whose `skill_name` is an opaque skill id (user/organization skill types and plugin-delivered skills — user-defined names are withheld from the analytics pipeline). Organization-shared skills and skills delivered by the organization's own plugins (its plugin marketplaces and its library) resolve; plugin skill names are shown without their 'plugin:' prefix. The literal 'unknown' bucket row gets a fixed 'Unknown skill' label. Null for private (user-defined) skills and members' personal-plugin skills — those names are not disclosed to analytics-key holders — and for Anthropic-provided plugin skills (not resolved), and null when `skill_name` is already a display name, when the skill or plugin was deleted, or when display-name resolution is not enabled for this organization. - `user_id: optional string or null` diff --git a/content/en/api/admin/analytics/cost.md b/content/en/api/admin/analytics/cost.md index 225a04635..c279682bd 100644 --- a/content/en/api/admin/analytics/cost.md +++ b/content/en/api/admin/analytics/cost.md @@ -31,6 +31,28 @@ Requires an API key with the `read:analytics` scope. - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -47,12 +69,16 @@ Requires an API key with the `read:analytics` scope. format: date-time -- `group_by: optional array of "context_window" or "cost_type" or "inference_geo" or 6 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 8 more` Dimensions to break each time bucket out by. Defaults to no grouping (one total per bucket). Each bucket reports at most its top 100 groups; a group beyond that cap has no row in that bucket (there is no remainder row), so grouped buckets are not exhaustive when a dimension has more than 100 distinct values. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"cost_type"` @@ -169,6 +195,24 @@ Requires an API key with the `read:analytics` scope. Amount (post-discount, pre-credit) in fractional cents. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -289,6 +333,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/cost_report \ "results": [ { "amount": "amount", + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "cost_type": "code_execution", "currency": "USD", @@ -345,6 +391,28 @@ organizations on a Claude Enterprise plan. Requires an API key with the - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -367,12 +435,16 @@ organizations on a Claude Enterprise plan. Requires an API key with the default: false -- `group_by: optional array of "context_window" or "cost_type" or "inference_geo" or 6 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 8 more` Break each actor's row out by the given dimensions. Accepts the same values as the bucketed `/cost_report` endpoint. The `product`, `model`, `context_window`, `inference_geo`, and `speed` dimensions — and the time bucket, when `bucket_width` is set — count toward `limit`. `cost_type` and `token_type` do not: `cost_type` returns one row per cost component (tokens, web search, code execution); `token_type` returns one row per token type, each with `cost_type: "tokens"`; combining both returns the per-token-type rows plus the web-search and code-execution rows. A page can therefore contain more rows than `limit` when `cost_type` or `token_type` is requested. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"cost_type"` @@ -523,6 +595,24 @@ organizations on a Claude Enterprise plan. Requires an API key with the Amount (post-discount, pre-credit) in fractional cents (minor units). + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -653,6 +743,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/user_cost_report \ "user_id": "user_01AbCdEfGhIjKlMnOpQrSt" }, "amount": "41280.000000", + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "cost_type": "code_execution", "currency": "USD", @@ -700,6 +792,24 @@ curl https://api.anthropic.com/v1/organizations/analytics/user_cost_report \ Amount (post-discount, pre-credit) in fractional cents. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -838,6 +948,24 @@ curl https://api.anthropic.com/v1/organizations/analytics/user_cost_report \ Amount (post-discount, pre-credit) in fractional cents (minor units). + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. diff --git a/content/en/api/admin/analytics/cost/list.md b/content/en/api/admin/analytics/cost/list.md index dc174b691..a8db44543 100644 --- a/content/en/api/admin/analytics/cost/list.md +++ b/content/en/api/admin/analytics/cost/list.md @@ -29,6 +29,28 @@ Requires an API key with the `read:analytics` scope. - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -45,12 +67,16 @@ Requires an API key with the `read:analytics` scope. format: date-time -- `group_by: optional array of "context_window" or "cost_type" or "inference_geo" or 6 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 8 more` Dimensions to break each time bucket out by. Defaults to no grouping (one total per bucket). Each bucket reports at most its top 100 groups; a group beyond that cap has no row in that bucket (there is no remainder row), so grouped buckets are not exhaustive when a dimension has more than 100 distinct values. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"cost_type"` @@ -167,6 +193,24 @@ Requires an API key with the `read:analytics` scope. Amount (post-discount, pre-credit) in fractional cents. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -287,6 +331,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/cost_report \ "results": [ { "amount": "amount", + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "cost_type": "code_execution", "currency": "USD", diff --git a/content/en/api/admin/analytics/cost/list_by_user.md b/content/en/api/admin/analytics/cost/list_by_user.md index e6d11a4a9..a171ec6b9 100644 --- a/content/en/api/admin/analytics/cost/list_by_user.md +++ b/content/en/api/admin/analytics/cost/list_by_user.md @@ -30,6 +30,28 @@ organizations on a Claude Enterprise plan. Requires an API key with the - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -52,12 +74,16 @@ organizations on a Claude Enterprise plan. Requires an API key with the default: false -- `group_by: optional array of "context_window" or "cost_type" or "inference_geo" or 6 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 8 more` Break each actor's row out by the given dimensions. Accepts the same values as the bucketed `/cost_report` endpoint. The `product`, `model`, `context_window`, `inference_geo`, and `speed` dimensions — and the time bucket, when `bucket_width` is set — count toward `limit`. `cost_type` and `token_type` do not: `cost_type` returns one row per cost component (tokens, web search, code execution); `token_type` returns one row per token type, each with `cost_type: "tokens"`; combining both returns the per-token-type rows plus the web-search and code-execution rows. A page can therefore contain more rows than `limit` when `cost_type` or `token_type` is requested. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"cost_type"` @@ -208,6 +234,24 @@ organizations on a Claude Enterprise plan. Requires an API key with the Amount (post-discount, pre-credit) in fractional cents (minor units). + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -338,6 +382,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/user_cost_report \ "user_id": "user_01AbCdEfGhIjKlMnOpQrSt" }, "amount": "41280.000000", + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "cost_type": "code_execution", "currency": "USD", diff --git a/content/en/api/admin/analytics/skills.md b/content/en/api/admin/analytics/skills.md index 520a87762..f3bfb2223 100644 --- a/content/en/api/admin/analytics/skills.md +++ b/content/en/api/admin/analytics/skills.md @@ -181,7 +181,7 @@ on a Claude Enterprise plan. Requires an API key with the - `skill_display_name: optional string or null` - Human-readable display name for rows whose `skill_name` is an opaque skill id (user/organization skill types — user-defined names are withheld from the analytics pipeline). Only organization-shared skills resolve; the literal 'unknown' bucket row also gets a fixed 'Unknown skill' label. Null for private (user-defined) skills — their names are not disclosed to analytics-key holders — and null when `skill_name` is already a display name, when the skill was deleted, or when display-name resolution is not enabled for this organization. + Human-readable display name for rows whose `skill_name` is an opaque skill id (user/organization skill types and plugin-delivered skills — user-defined names are withheld from the analytics pipeline). Organization-shared skills and skills delivered by the organization's own plugins (its plugin marketplaces and its library) resolve; plugin skill names are shown without their 'plugin:' prefix. The literal 'unknown' bucket row gets a fixed 'Unknown skill' label. Null for private (user-defined) skills and members' personal-plugin skills — those names are not disclosed to analytics-key holders — and for Anthropic-provided plugin skills (not resolved), and null when `skill_name` is already a display name, when the skill or plugin was deleted, or when display-name resolution is not enabled for this organization. - `user_id: optional string or null` @@ -357,7 +357,7 @@ curl https://api.anthropic.com/v1/organizations/analytics/skills \ - `skill_display_name: optional string or null` - Human-readable display name for rows whose `skill_name` is an opaque skill id (user/organization skill types — user-defined names are withheld from the analytics pipeline). Only organization-shared skills resolve; the literal 'unknown' bucket row also gets a fixed 'Unknown skill' label. Null for private (user-defined) skills — their names are not disclosed to analytics-key holders — and null when `skill_name` is already a display name, when the skill was deleted, or when display-name resolution is not enabled for this organization. + Human-readable display name for rows whose `skill_name` is an opaque skill id (user/organization skill types and plugin-delivered skills — user-defined names are withheld from the analytics pipeline). Organization-shared skills and skills delivered by the organization's own plugins (its plugin marketplaces and its library) resolve; plugin skill names are shown without their 'plugin:' prefix. The literal 'unknown' bucket row gets a fixed 'Unknown skill' label. Null for private (user-defined) skills and members' personal-plugin skills — those names are not disclosed to analytics-key holders — and for Anthropic-provided plugin skills (not resolved), and null when `skill_name` is already a display name, when the skill or plugin was deleted, or when display-name resolution is not enabled for this organization. - `user_id: optional string or null` diff --git a/content/en/api/admin/analytics/skills/list.md b/content/en/api/admin/analytics/skills/list.md index 9ed02cf6f..1f32a2bc1 100644 --- a/content/en/api/admin/analytics/skills/list.md +++ b/content/en/api/admin/analytics/skills/list.md @@ -179,7 +179,7 @@ on a Claude Enterprise plan. Requires an API key with the - `skill_display_name: optional string or null` - Human-readable display name for rows whose `skill_name` is an opaque skill id (user/organization skill types — user-defined names are withheld from the analytics pipeline). Only organization-shared skills resolve; the literal 'unknown' bucket row also gets a fixed 'Unknown skill' label. Null for private (user-defined) skills — their names are not disclosed to analytics-key holders — and null when `skill_name` is already a display name, when the skill was deleted, or when display-name resolution is not enabled for this organization. + Human-readable display name for rows whose `skill_name` is an opaque skill id (user/organization skill types and plugin-delivered skills — user-defined names are withheld from the analytics pipeline). Organization-shared skills and skills delivered by the organization's own plugins (its plugin marketplaces and its library) resolve; plugin skill names are shown without their 'plugin:' prefix. The literal 'unknown' bucket row gets a fixed 'Unknown skill' label. Null for private (user-defined) skills and members' personal-plugin skills — those names are not disclosed to analytics-key holders — and for Anthropic-provided plugin skills (not resolved), and null when `skill_name` is already a display name, when the skill or plugin was deleted, or when display-name resolution is not enabled for this organization. - `user_id: optional string or null` diff --git a/content/en/api/admin/analytics/usage.md b/content/en/api/admin/analytics/usage.md index cd03da0b6..434a858b1 100644 --- a/content/en/api/admin/analytics/usage.md +++ b/content/en/api/admin/analytics/usage.md @@ -31,6 +31,28 @@ key with the `read:analytics` scope. - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -47,12 +69,16 @@ key with the `read:analytics` scope. format: date-time -- `group_by: optional array of "context_window" or "inference_geo" or "model" or 4 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 6 more` Dimensions to break each time bucket out by. Defaults to no grouping (one total per bucket). Each bucket reports at most its top 100 groups; a group beyond that cap has no row in that bucket (there is no remainder row), so grouped buckets are not exhaustive when a dimension has more than 100 distinct values. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"inference_geo"` @@ -177,6 +203,24 @@ key with the `read:analytics` scope. The number of input tokens read from the cache. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -283,6 +327,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/usage_report \ "ephemeral_5m_input_tokens": 500 }, "cache_read_input_tokens": 0, + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "inference_geo": "global", "model": "claude-opus-5", @@ -340,6 +386,28 @@ organizations on a Claude Enterprise plan. Requires an API key with the - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -362,12 +430,16 @@ organizations on a Claude Enterprise plan. Requires an API key with the default: false -- `group_by: optional array of "context_window" or "inference_geo" or "model" or 4 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 6 more` Break each actor's row out by the given dimensions. Accepts the same values as the bucketed `/usage_report` endpoint. `limit` bounds (actor × time bucket × dimension) rows — with dimensions or `bucket_width` present, one actor may span several rows. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"inference_geo"` @@ -530,6 +602,24 @@ organizations on a Claude Enterprise plan. Requires an API key with the The number of input tokens read from the cache. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -650,6 +740,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/user_usage_report \ "ephemeral_5m_input_tokens": 500 }, "cache_read_input_tokens": 3200000, + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "ending_at": "2019-12-27T18:11:19.117Z", "inference_geo": "global", @@ -711,6 +803,24 @@ curl https://api.anthropic.com/v1/organizations/analytics/user_usage_report \ The number of input tokens read from the cache. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -843,6 +953,24 @@ curl https://api.anthropic.com/v1/organizations/analytics/user_usage_report \ The number of input tokens read from the cache. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. diff --git a/content/en/api/admin/analytics/usage/list.md b/content/en/api/admin/analytics/usage/list.md index 2dc04bebe..816c555c1 100644 --- a/content/en/api/admin/analytics/usage/list.md +++ b/content/en/api/admin/analytics/usage/list.md @@ -29,6 +29,28 @@ key with the `read:analytics` scope. - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -45,12 +67,16 @@ key with the `read:analytics` scope. format: date-time -- `group_by: optional array of "context_window" or "inference_geo" or "model" or 4 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 6 more` Dimensions to break each time bucket out by. Defaults to no grouping (one total per bucket). Each bucket reports at most its top 100 groups; a group beyond that cap has no row in that bucket (there is no remainder row), so grouped buckets are not exhaustive when a dimension has more than 100 distinct values. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"inference_geo"` @@ -175,6 +201,24 @@ key with the `read:analytics` scope. The number of input tokens read from the cache. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -281,6 +325,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/usage_report \ "ephemeral_5m_input_tokens": 500 }, "cache_read_input_tokens": 0, + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "inference_geo": "global", "model": "claude-opus-5", diff --git a/content/en/api/admin/analytics/usage/list_by_user.md b/content/en/api/admin/analytics/usage/list_by_user.md index d86c0920b..4759a0aef 100644 --- a/content/en/api/admin/analytics/usage/list_by_user.md +++ b/content/en/api/admin/analytics/usage/list_by_user.md @@ -30,6 +30,28 @@ organizations on a Claude Enterprise plan. Requires an API key with the - `"1m"` +- `claude_tag_categories: optional array of "dm" or "engaged" or "monitoring" or 2 more` + + Filter to Claude Tag (Claude in Slack) usage in specific spend categories. Usage with no category never matches. `dm` usage is reported under the user's product rather than `claude-tag`, so combining this filter with `products[]=claude-tag` excludes it. Use `group_by[]=claude_tag_category` to break out per-category values. + + maxItems: 100 + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + +- `claude_tag_user_ids: optional array of string` + + Filter to Claude Tag (Claude in Slack) usage attributed to specific Slack users, by Slack user ID (for example `U0123ABCDEF`), not claude.ai user ID. Usage that is not Claude Tag, and Claude Tag usage not attributed to a single user, never matches. Use `group_by[]=claude_tag_user_id` to break out per-user values. + + maxItems: 100 + - `context_windows: optional array of "0-200k" or "200k-1M"` Filter to specific context-window pricing tiers. Use `group_by[]=context_window` to break out per-tier values. @@ -52,12 +74,16 @@ organizations on a Claude Enterprise plan. Requires an API key with the default: false -- `group_by: optional array of "context_window" or "inference_geo" or "model" or 4 more` +- `group_by: optional array of "claude_tag_category" or "claude_tag_user_id" or "context_window" or 6 more` Break each actor's row out by the given dimensions. Accepts the same values as the bucketed `/usage_report` endpoint. `limit` bounds (actor × time bucket × dimension) rows — with dimensions or `bucket_width` present, one actor may span several rows. maxItems: 100 + - `"claude_tag_category"` + + - `"claude_tag_user_id"` + - `"context_window"` - `"inference_geo"` @@ -220,6 +246,24 @@ organizations on a Claude Enterprise plan. Requires an API key with the The number of input tokens read from the cache. + - `claude_tag_category: "dm" or "engaged" or "monitoring" or 2 more or null` + + Claude Tag (Claude in Slack) spend category: `engaged` (a person addressed Claude in a channel or thread), `proactive` (Claude responded without being addressed), `scheduled` (a scheduled routine ran), `monitoring` (Claude watching a channel it was asked to monitor), or `dm` (direct messages with Claude). Populated only when `claude_tag_category` is in `group_by[]`; null for usage that is not Claude Tag. Direct-message usage is billed to the individual user and is reported under that user's product, not under `claude-tag`. New categories may be added over time. + + - `"dm"` + + - `"engaged"` + + - `"monitoring"` + + - `"proactive"` + + - `"scheduled"` + + - `claude_tag_user_id: string or null` + + Slack user ID (for example `U0123ABCDEF`) of the member the Claude Tag (Claude in Slack) usage is attributed to, not a claude.ai user ID. Populated only when `claude_tag_user_id` is in `group_by[]`; null for usage that is not Claude Tag and for Claude Tag usage that is not attributed to a single user (for example `monitoring`, and `proactive` usage Claude initiated), so per-user rows can sum to less than the Claude Tag total. Cannot be combined with `group_by[]=rbac_group_id` or the `rbac_group_ids[]` filter. + - `context_window: "0-200k" or "200k-1M" or null` Context-window pricing tier of the usage or cost. Null unless `context_window` is in `group_by[]`; it can also be null on grouped rows with no context-window tier, such as code execution. @@ -340,6 +384,8 @@ curl https://api.anthropic.com/v1/organizations/analytics/user_usage_report \ "ephemeral_5m_input_tokens": 500 }, "cache_read_input_tokens": 3200000, + "claude_tag_category": "dm", + "claude_tag_user_id": "U0123ABCDEF", "context_window": "0-200k", "ending_at": "2019-12-27T18:11:19.117Z", "inference_geo": "global", diff --git a/content/en/api/admin/api_keys.md b/content/en/api/admin/api_keys.md index 1dbb1667b..24a183e40 100644 --- a/content/en/api/admin/api_keys.md +++ b/content/en/api/admin/api_keys.md @@ -141,7 +141,7 @@ Retrieve information about a single API key in your organization, looked up by i ```bash curl https://api.anthropic.com/v1/organizations/api_keys/$API_KEY_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -356,7 +356,7 @@ List API Keys ```bash curl https://api.anthropic.com/v1/organizations/api_keys \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -553,7 +553,7 @@ Update API Key curl https://api.anthropic.com/v1/organizations/api_keys/$API_KEY_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` diff --git a/content/en/api/admin/api_keys/list.md b/content/en/api/admin/api_keys/list.md index be875392c..d7fd03bd9 100644 --- a/content/en/api/admin/api_keys/list.md +++ b/content/en/api/admin/api_keys/list.md @@ -183,7 +183,7 @@ List API Keys ```bash curl https://api.anthropic.com/v1/organizations/api_keys \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/api_keys/retrieve.md b/content/en/api/admin/api_keys/retrieve.md index 6af3dac4b..63b85daae 100644 --- a/content/en/api/admin/api_keys/retrieve.md +++ b/content/en/api/admin/api_keys/retrieve.md @@ -139,7 +139,7 @@ Retrieve information about a single API key in your organization, looked up by i ```bash curl https://api.anthropic.com/v1/organizations/api_keys/$API_KEY_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/api_keys/update.md b/content/en/api/admin/api_keys/update.md index c2493f7c5..85964edc7 100644 --- a/content/en/api/admin/api_keys/update.md +++ b/content/en/api/admin/api_keys/update.md @@ -158,7 +158,7 @@ Update API Key curl https://api.anthropic.com/v1/organizations/api_keys/$API_KEY_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` diff --git a/content/en/api/admin/cost_report.md b/content/en/api/admin/cost_report.md index fc0cde74e..2eedbd731 100644 --- a/content/en/api/admin/cost_report.md +++ b/content/en/api/admin/cost_report.md @@ -163,7 +163,7 @@ Get Cost Report ```bash curl https://api.anthropic.com/v1/organizations/cost_report \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/cost_report/retrieve.md b/content/en/api/admin/cost_report/retrieve.md index 6d3c8730b..3a01a296b 100644 --- a/content/en/api/admin/cost_report/retrieve.md +++ b/content/en/api/admin/cost_report/retrieve.md @@ -161,7 +161,7 @@ Get Cost Report ```bash curl https://api.anthropic.com/v1/organizations/cost_report \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/external_keys.md b/content/en/api/admin/external_keys.md index dacfc1e36..181835ee0 100644 --- a/content/en/api/admin/external_keys.md +++ b/content/en/api/admin/external_keys.md @@ -16,7 +16,7 @@ Create an external key config owned by the caller's organization. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -30,7 +30,7 @@ Create an external key config owned by the caller's organization. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -114,7 +114,7 @@ Create an external key config owned by the caller's organization. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -128,7 +128,7 @@ Create an external key config owned by the caller's organization. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -172,7 +172,7 @@ Create an external key config owned by the caller's organization. curl https://api.anthropic.com/v1/organizations/external_keys \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "provider_config": { "kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222", @@ -268,7 +268,7 @@ Results are ordered by creation time (newest first). Use the - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -282,7 +282,7 @@ Results are ordered by creation time (newest first). Use the **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -329,7 +329,7 @@ Results are ordered by creation time (newest first). Use the ```bash curl https://api.anthropic.com/v1/organizations/external_keys \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -415,7 +415,7 @@ Retrieve a single external key config in the caller's organization by ID. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -429,7 +429,7 @@ Retrieve a single external key config in the caller's organization by ID. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -472,7 +472,7 @@ Retrieve a single external key config in the caller's organization by ID. ```bash curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -535,7 +535,7 @@ encrypted data requires the original key identity to decrypt. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -549,7 +549,7 @@ encrypted data requires the original key identity to decrypt. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -623,7 +623,7 @@ encrypted data requires the original key identity to decrypt. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -637,7 +637,7 @@ encrypted data requires the original key identity to decrypt. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -681,7 +681,7 @@ encrypted data requires the original key identity to decrypt. curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` @@ -739,7 +739,7 @@ The request is rejected if any workspace still references this config. curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -794,7 +794,7 @@ message if it failed or timed out. curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/validate \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -859,7 +859,7 @@ curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/v - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -873,7 +873,7 @@ curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/v **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -961,7 +961,7 @@ curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/v - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -975,7 +975,7 @@ curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/v **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -1063,7 +1063,7 @@ curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/v - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -1077,7 +1077,7 @@ curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/v **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -1165,7 +1165,7 @@ curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/v - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -1179,7 +1179,7 @@ curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/v **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` diff --git a/content/en/api/admin/external_keys/create.md b/content/en/api/admin/external_keys/create.md index 70315b59b..24a9dcfb6 100644 --- a/content/en/api/admin/external_keys/create.md +++ b/content/en/api/admin/external_keys/create.md @@ -14,7 +14,7 @@ Create an external key config owned by the caller's organization. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -28,7 +28,7 @@ Create an external key config owned by the caller's organization. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -112,7 +112,7 @@ Create an external key config owned by the caller's organization. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -126,7 +126,7 @@ Create an external key config owned by the caller's organization. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -170,7 +170,7 @@ Create an external key config owned by the caller's organization. curl https://api.anthropic.com/v1/organizations/external_keys \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "provider_config": { "kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222", diff --git a/content/en/api/admin/external_keys/delete.md b/content/en/api/admin/external_keys/delete.md index 03e043d5e..1b5d4bea6 100644 --- a/content/en/api/admin/external_keys/delete.md +++ b/content/en/api/admin/external_keys/delete.md @@ -30,7 +30,7 @@ The request is rejected if any workspace still references this config. curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/external_keys/list.md b/content/en/api/admin/external_keys/list.md index 25d68446d..f0a3a17b7 100644 --- a/content/en/api/admin/external_keys/list.md +++ b/content/en/api/admin/external_keys/list.md @@ -63,7 +63,7 @@ Results are ordered by creation time (newest first). Use the - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -77,7 +77,7 @@ Results are ordered by creation time (newest first). Use the **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -124,7 +124,7 @@ Results are ordered by creation time (newest first). Use the ```bash curl https://api.anthropic.com/v1/organizations/external_keys \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/external_keys/retrieve.md b/content/en/api/admin/external_keys/retrieve.md index 8f54c0c03..51b69de72 100644 --- a/content/en/api/admin/external_keys/retrieve.md +++ b/content/en/api/admin/external_keys/retrieve.md @@ -54,7 +54,7 @@ Retrieve a single external key config in the caller's organization by ID. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -68,7 +68,7 @@ Retrieve a single external key config in the caller's organization by ID. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -111,7 +111,7 @@ Retrieve a single external key config in the caller's organization by ID. ```bash curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/external_keys/update.md b/content/en/api/admin/external_keys/update.md index 44393dc79..08aa26250 100644 --- a/content/en/api/admin/external_keys/update.md +++ b/content/en/api/admin/external_keys/update.md @@ -36,7 +36,7 @@ encrypted data requires the original key identity to decrypt. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -50,7 +50,7 @@ encrypted data requires the original key identity to decrypt. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -124,7 +124,7 @@ encrypted data requires the original key identity to decrypt. - `kms_arn: string` - Full ARN of the AWS KMS key. + Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected. maxLength: 2048 @@ -138,7 +138,7 @@ encrypted data requires the original key identity to decrypt. **Deprecated** - IAM role ARN. Deprecated — Anthropic reaches the KMS key via a managed intermediate role; this field is ignored. + IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored. - `Gcp object` @@ -182,7 +182,7 @@ encrypted data requires the original key identity to decrypt. curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` diff --git a/content/en/api/admin/external_keys/validate.md b/content/en/api/admin/external_keys/validate.md index 6a8ef33c9..33178ce14 100644 --- a/content/en/api/admin/external_keys/validate.md +++ b/content/en/api/admin/external_keys/validate.md @@ -41,7 +41,7 @@ message if it failed or timed out. curl https://api.anthropic.com/v1/organizations/external_keys/$EXTERNAL_KEY_ID/validate \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/federation_issuers.md b/content/en/api/admin/federation_issuers.md index be87a778d..dfc7d38fa 100644 --- a/content/en/api/admin/federation_issuers.md +++ b/content/en/api/admin/federation_issuers.md @@ -4,6 +4,8 @@ **POST** `/v1/organizations/federation_issuers` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Register an OIDC issuer that Anthropic will trust for workload identity federation in your organization. @@ -16,9 +18,6 @@ publicly reachable over HTTPS so Anthropic can fetch the discovery document; for `explicit_url` and `inline` modes the issuer URL is only matched as the JWT's `iss` claim and is not fetched. -Requires an OAuth bearer or Console session; Admin API keys are not -accepted. - ### Headers - `"anthropic-beta": optional array of string` @@ -250,7 +249,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/federation_issuers \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "issuer_url": "x", "name": "x" @@ -291,6 +290,8 @@ curl https://api.anthropic.com/v1/organizations/federation_issuers \ **GET** `/v1/organizations/federation_issuers/{federation_issuer_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a federation issuer by its ID (`fdis_...`). ### Path parameters @@ -455,7 +456,7 @@ Retrieve a federation issuer by its ID (`fdis_...`). ```bash curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -492,6 +493,8 @@ curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_I **GET** `/v1/organizations/federation_issuers` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List federation issuers in your organization. Archived issuers are excluded unless `include_archived=true`. @@ -669,7 +672,7 @@ Archived issuers are excluded unless `include_archived=true`. ```bash curl https://api.anthropic.com/v1/organizations/federation_issuers \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -711,6 +714,8 @@ curl https://api.anthropic.com/v1/organizations/federation_issuers \ **POST** `/v1/organizations/federation_issuers/{federation_issuer_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Partially update a federation issuer. Setting `jwks` replaces the full JWKS shape at once. Archived issuers @@ -718,8 +723,7 @@ cannot be updated; this returns 400. Create a new issuer instead. Updating an issuer that backs a rule with a scope outside `workspace:developer` or `workspace:inference` requires a Console -session. Requires an OAuth bearer or Console session; Admin API keys -are not accepted. +session. ### Path parameters @@ -962,7 +966,7 @@ are not accepted. curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` @@ -1000,6 +1004,8 @@ curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_I **POST** `/v1/organizations/federation_issuers/{federation_issuer_id}/archive` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Archive a federation issuer. Idempotent; re-archiving returns the issuer with its original @@ -1007,9 +1013,6 @@ Idempotent; re-archiving returns the issuer with its original rule still references the issuer; archive those rules first (a rule's issuer cannot be changed), or recreate them against another issuer. -Requires an OAuth bearer or Console session; Admin API keys are not -accepted. - ### Path parameters - `federation_issuer_id: string` @@ -1173,7 +1176,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/federation_issuers/archive.md b/content/en/api/admin/federation_issuers/archive.md index 6fa09ff4c..a514d5e88 100644 --- a/content/en/api/admin/federation_issuers/archive.md +++ b/content/en/api/admin/federation_issuers/archive.md @@ -2,6 +2,8 @@ **POST** `/v1/organizations/federation_issuers/{federation_issuer_id}/archive` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Archive a federation issuer. Idempotent; re-archiving returns the issuer with its original @@ -9,9 +11,6 @@ Idempotent; re-archiving returns the issuer with its original rule still references the issuer; archive those rules first (a rule's issuer cannot be changed), or recreate them against another issuer. -Requires an OAuth bearer or Console session; Admin API keys are not -accepted. - ## Path parameters - `federation_issuer_id: string` @@ -175,7 +174,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/federation_issuers/create.md b/content/en/api/admin/federation_issuers/create.md index 4e8770d9e..801de3d61 100644 --- a/content/en/api/admin/federation_issuers/create.md +++ b/content/en/api/admin/federation_issuers/create.md @@ -2,6 +2,8 @@ **POST** `/v1/organizations/federation_issuers` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Register an OIDC issuer that Anthropic will trust for workload identity federation in your organization. @@ -14,9 +16,6 @@ publicly reachable over HTTPS so Anthropic can fetch the discovery document; for `explicit_url` and `inline` modes the issuer URL is only matched as the JWT's `iss` claim and is not fetched. -Requires an OAuth bearer or Console session; Admin API keys are not -accepted. - ## Headers - `"anthropic-beta": optional array of string` @@ -248,7 +247,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/federation_issuers \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "issuer_url": "x", "name": "x" diff --git a/content/en/api/admin/federation_issuers/list.md b/content/en/api/admin/federation_issuers/list.md index 3114150f2..23bfbe50f 100644 --- a/content/en/api/admin/federation_issuers/list.md +++ b/content/en/api/admin/federation_issuers/list.md @@ -2,6 +2,8 @@ **GET** `/v1/organizations/federation_issuers` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List federation issuers in your organization. Archived issuers are excluded unless `include_archived=true`. @@ -179,7 +181,7 @@ Archived issuers are excluded unless `include_archived=true`. ```bash curl https://api.anthropic.com/v1/organizations/federation_issuers \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/federation_issuers/retrieve.md b/content/en/api/admin/federation_issuers/retrieve.md index 0e697aebb..dc4aa214c 100644 --- a/content/en/api/admin/federation_issuers/retrieve.md +++ b/content/en/api/admin/federation_issuers/retrieve.md @@ -2,6 +2,8 @@ **GET** `/v1/organizations/federation_issuers/{federation_issuer_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a federation issuer by its ID (`fdis_...`). ## Path parameters @@ -166,7 +168,7 @@ Retrieve a federation issuer by its ID (`fdis_...`). ```bash curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/federation_issuers/update.md b/content/en/api/admin/federation_issuers/update.md index b0d21fb8c..4a5af3cec 100644 --- a/content/en/api/admin/federation_issuers/update.md +++ b/content/en/api/admin/federation_issuers/update.md @@ -2,6 +2,8 @@ **POST** `/v1/organizations/federation_issuers/{federation_issuer_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Partially update a federation issuer. Setting `jwks` replaces the full JWKS shape at once. Archived issuers @@ -9,8 +11,7 @@ cannot be updated; this returns 400. Create a new issuer instead. Updating an issuer that backs a rule with a scope outside `workspace:developer` or `workspace:inference` requires a Console -session. Requires an OAuth bearer or Console session; Admin API keys -are not accepted. +session. ## Path parameters @@ -253,7 +254,7 @@ are not accepted. curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` diff --git a/content/en/api/admin/federation_rules.md b/content/en/api/admin/federation_rules.md index 872786474..639e150cc 100644 --- a/content/en/api/admin/federation_rules.md +++ b/content/en/api/admin/federation_rules.md @@ -4,6 +4,8 @@ **POST** `/v1/organizations/federation_rules` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Create a federation rule owned by your organization. The referenced issuer and the target service account must already exist @@ -18,8 +20,7 @@ identity-bearing claim, a tenant-pinning subject prefix (such as `repo:YOUR_ORG/...`), or a CEL condition referencing one of those identity claims (e.g. `claims.repository_owner`). OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or -`workspace:inference`; other scopes require a Console session. Admin API -keys are not accepted. +`workspace:inference`; other scopes require a Console session. ### Headers @@ -250,7 +251,7 @@ keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "issuer_id": "issuer_id", "match": {}, @@ -309,6 +310,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules \ **GET** `/v1/organizations/federation_rules/{federation_rule_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a federation rule by its ID (`fdrl_...`). ### Path parameters @@ -463,7 +466,7 @@ Retrieve a federation rule by its ID (`fdrl_...`). ```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -512,6 +515,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RUL **GET** `/v1/organizations/federation_rules` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List federation rules in your organization. Optionally filter by issuer with `issuer_id`. Archived rules are excluded @@ -678,7 +683,7 @@ unless `include_archived=true`. ```bash curl https://api.anthropic.com/v1/organizations/federation_rules \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -732,6 +737,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules \ **POST** `/v1/organizations/federation_rules/{federation_rule_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Partially update a federation rule. `issuer_id` is immutable. `match` and `target` are replaced as whole @@ -748,7 +755,7 @@ match does not yet constrain tenant identity, any update (even a rename or description change) must also supply a conforming `match` in the same request. OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or `workspace:inference`; other scopes require a -Console session. Admin API keys are not accepted. +Console session. ### Path parameters @@ -985,7 +992,7 @@ Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` @@ -1035,6 +1042,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RUL **POST** `/v1/organizations/federation_rules/{federation_rule_id}/archive` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Archive a federation rule. Token exchange through this rule stops immediately. Idempotent; @@ -1043,7 +1052,7 @@ clears the rule's workspace targeting (`workspace_id` and `workspace_ids` are emptied). Tokens already minted before archive remain valid until they expire. OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or `workspace:inference`; -other scopes require a Console session. Admin API keys are not accepted. +other scopes require a Console session. ### Path parameters @@ -1198,7 +1207,7 @@ other scopes require a Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -1384,6 +1393,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RUL **GET** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List workspaces where this federation rule is enabled. Returns all workspace enablements in a single response; the `limit` and @@ -1457,7 +1468,7 @@ rules with `applies_to_all_workspaces` or a legacy single ```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1482,6 +1493,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RUL **POST** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Enable a federation rule for a workspace. Idempotent; re-enabling returns the existing enablement. The rule and @@ -1489,9 +1502,9 @@ workspace must both belong to your organization. Membership of the rule's target service account in this workspace is not checked at enablement: token exchange into this workspace is rejected unless the target is a member (it is implicitly a member of the default workspace). -Archived rules are rejected with 400. OAuth callers may only manage rules whose -`oauth_scope` is `workspace:developer` or `workspace:inference`; other -scopes require a Console session. Admin API keys are not accepted. +Archived rules are rejected with 400. OAuth callers may only manage rules +whose `oauth_scope` is `workspace:developer` or `workspace:inference`; +other scopes require a Console session. #### Path parameters @@ -1547,7 +1560,7 @@ scopes require a Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_id": "workspace_id" }' @@ -1570,12 +1583,14 @@ curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RUL **DELETE** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Disable a federation rule for a workspace. Idempotent; succeeds even if the enablement was already removed. OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or `workspace:inference`; other scopes require a -Console session. Admin API keys are not accepted. +Console session. #### Path parameters @@ -1615,7 +1630,7 @@ Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces/$WORKSPACE_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) diff --git a/content/en/api/admin/federation_rules/archive.md b/content/en/api/admin/federation_rules/archive.md index cfd4120fd..fa7b239dd 100644 --- a/content/en/api/admin/federation_rules/archive.md +++ b/content/en/api/admin/federation_rules/archive.md @@ -2,6 +2,8 @@ **POST** `/v1/organizations/federation_rules/{federation_rule_id}/archive` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Archive a federation rule. Token exchange through this rule stops immediately. Idempotent; @@ -10,7 +12,7 @@ clears the rule's workspace targeting (`workspace_id` and `workspace_ids` are emptied). Tokens already minted before archive remain valid until they expire. OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or `workspace:inference`; -other scopes require a Console session. Admin API keys are not accepted. +other scopes require a Console session. ## Path parameters @@ -165,7 +167,7 @@ other scopes require a Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/federation_rules/create.md b/content/en/api/admin/federation_rules/create.md index 382ba3ec3..8b57442df 100644 --- a/content/en/api/admin/federation_rules/create.md +++ b/content/en/api/admin/federation_rules/create.md @@ -2,6 +2,8 @@ **POST** `/v1/organizations/federation_rules` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Create a federation rule owned by your organization. The referenced issuer and the target service account must already exist @@ -16,8 +18,7 @@ identity-bearing claim, a tenant-pinning subject prefix (such as `repo:YOUR_ORG/...`), or a CEL condition referencing one of those identity claims (e.g. `claims.repository_owner`). OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or -`workspace:inference`; other scopes require a Console session. Admin API -keys are not accepted. +`workspace:inference`; other scopes require a Console session. ## Headers @@ -248,7 +249,7 @@ keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "issuer_id": "issuer_id", "match": {}, diff --git a/content/en/api/admin/federation_rules/list.md b/content/en/api/admin/federation_rules/list.md index 33022a1af..aa2667992 100644 --- a/content/en/api/admin/federation_rules/list.md +++ b/content/en/api/admin/federation_rules/list.md @@ -2,6 +2,8 @@ **GET** `/v1/organizations/federation_rules` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List federation rules in your organization. Optionally filter by issuer with `issuer_id`. Archived rules are excluded @@ -168,7 +170,7 @@ unless `include_archived=true`. ```bash curl https://api.anthropic.com/v1/organizations/federation_rules \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/federation_rules/retrieve.md b/content/en/api/admin/federation_rules/retrieve.md index d3992f1fd..aad0a4b95 100644 --- a/content/en/api/admin/federation_rules/retrieve.md +++ b/content/en/api/admin/federation_rules/retrieve.md @@ -2,6 +2,8 @@ **GET** `/v1/organizations/federation_rules/{federation_rule_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a federation rule by its ID (`fdrl_...`). ## Path parameters @@ -156,7 +158,7 @@ Retrieve a federation rule by its ID (`fdrl_...`). ```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/federation_rules/update.md b/content/en/api/admin/federation_rules/update.md index 0db71fd1f..5b2bde4c6 100644 --- a/content/en/api/admin/federation_rules/update.md +++ b/content/en/api/admin/federation_rules/update.md @@ -2,6 +2,8 @@ **POST** `/v1/organizations/federation_rules/{federation_rule_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Partially update a federation rule. `issuer_id` is immutable. `match` and `target` are replaced as whole @@ -18,7 +20,7 @@ match does not yet constrain tenant identity, any update (even a rename or description change) must also supply a conforming `match` in the same request. OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or `workspace:inference`; other scopes require a -Console session. Admin API keys are not accepted. +Console session. ## Path parameters @@ -255,7 +257,7 @@ Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` diff --git a/content/en/api/admin/federation_rules/workspaces.md b/content/en/api/admin/federation_rules/workspaces.md index 023baa6ba..91ad66593 100644 --- a/content/en/api/admin/federation_rules/workspaces.md +++ b/content/en/api/admin/federation_rules/workspaces.md @@ -4,6 +4,8 @@ **GET** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List workspaces where this federation rule is enabled. Returns all workspace enablements in a single response; the `limit` and @@ -77,7 +79,7 @@ rules with `applies_to_all_workspaces` or a legacy single ```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -102,6 +104,8 @@ curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RUL **POST** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Enable a federation rule for a workspace. Idempotent; re-enabling returns the existing enablement. The rule and @@ -109,9 +113,9 @@ workspace must both belong to your organization. Membership of the rule's target service account in this workspace is not checked at enablement: token exchange into this workspace is rejected unless the target is a member (it is implicitly a member of the default workspace). -Archived rules are rejected with 400. OAuth callers may only manage rules whose -`oauth_scope` is `workspace:developer` or `workspace:inference`; other -scopes require a Console session. Admin API keys are not accepted. +Archived rules are rejected with 400. OAuth callers may only manage rules +whose `oauth_scope` is `workspace:developer` or `workspace:inference`; +other scopes require a Console session. ### Path parameters @@ -167,7 +171,7 @@ scopes require a Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_id": "workspace_id" }' @@ -190,12 +194,14 @@ curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RUL **DELETE** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Disable a federation rule for a workspace. Idempotent; succeeds even if the enablement was already removed. OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or `workspace:inference`; other scopes require a -Console session. Admin API keys are not accepted. +Console session. ### Path parameters @@ -235,7 +241,7 @@ Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces/$WORKSPACE_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/federation_rules/workspaces/create.md b/content/en/api/admin/federation_rules/workspaces/create.md index c0b24735f..6579afca9 100644 --- a/content/en/api/admin/federation_rules/workspaces/create.md +++ b/content/en/api/admin/federation_rules/workspaces/create.md @@ -2,6 +2,8 @@ **POST** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Enable a federation rule for a workspace. Idempotent; re-enabling returns the existing enablement. The rule and @@ -9,9 +11,9 @@ workspace must both belong to your organization. Membership of the rule's target service account in this workspace is not checked at enablement: token exchange into this workspace is rejected unless the target is a member (it is implicitly a member of the default workspace). -Archived rules are rejected with 400. OAuth callers may only manage rules whose -`oauth_scope` is `workspace:developer` or `workspace:inference`; other -scopes require a Console session. Admin API keys are not accepted. +Archived rules are rejected with 400. OAuth callers may only manage rules +whose `oauth_scope` is `workspace:developer` or `workspace:inference`; +other scopes require a Console session. ## Path parameters @@ -67,7 +69,7 @@ scopes require a Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_id": "workspace_id" }' diff --git a/content/en/api/admin/federation_rules/workspaces/delete.md b/content/en/api/admin/federation_rules/workspaces/delete.md index 2e0a791a2..946eee17c 100644 --- a/content/en/api/admin/federation_rules/workspaces/delete.md +++ b/content/en/api/admin/federation_rules/workspaces/delete.md @@ -2,12 +2,14 @@ **DELETE** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Disable a federation rule for a workspace. Idempotent; succeeds even if the enablement was already removed. OAuth callers may only manage rules whose `oauth_scope` is `workspace:developer` or `workspace:inference`; other scopes require a -Console session. Admin API keys are not accepted. +Console session. ## Path parameters @@ -47,7 +49,7 @@ Console session. Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces/$WORKSPACE_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/federation_rules/workspaces/list.md b/content/en/api/admin/federation_rules/workspaces/list.md index e8ff3b66d..1b439ab61 100644 --- a/content/en/api/admin/federation_rules/workspaces/list.md +++ b/content/en/api/admin/federation_rules/workspaces/list.md @@ -2,6 +2,8 @@ **GET** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List workspaces where this federation rule is enabled. Returns all workspace enablements in a single response; the `limit` and @@ -75,7 +77,7 @@ rules with `applies_to_all_workspaces` or a legacy single ```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/invites.md b/content/en/api/admin/invites.md index 836618670..d9fd50f14 100644 --- a/content/en/api/admin/invites.md +++ b/content/en/api/admin/invites.md @@ -120,7 +120,7 @@ On plans that draw members from a finite pool of purchased seats, the invite aut curl https://api.anthropic.com/v1/organizations/invites \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "email": "user@emaildomain.com", "role": "user" @@ -238,7 +238,7 @@ Retrieve an invite by ID. ```bash curl https://api.anthropic.com/v1/organizations/invites/$INVITE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -398,7 +398,7 @@ List the organization's invites. ```bash curl https://api.anthropic.com/v1/organizations/invites \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -458,7 +458,7 @@ Delete a pending invite. curl https://api.anthropic.com/v1/organizations/invites/$INVITE_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/invites/create.md b/content/en/api/admin/invites/create.md index e6313b50e..d31aaacb4 100644 --- a/content/en/api/admin/invites/create.md +++ b/content/en/api/admin/invites/create.md @@ -118,7 +118,7 @@ On plans that draw members from a finite pool of purchased seats, the invite aut curl https://api.anthropic.com/v1/organizations/invites \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "email": "user@emaildomain.com", "role": "user" diff --git a/content/en/api/admin/invites/delete.md b/content/en/api/admin/invites/delete.md index ee97c108a..c03fa9aaf 100644 --- a/content/en/api/admin/invites/delete.md +++ b/content/en/api/admin/invites/delete.md @@ -30,7 +30,7 @@ Delete a pending invite. curl https://api.anthropic.com/v1/organizations/invites/$INVITE_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/invites/list.md b/content/en/api/admin/invites/list.md index 474f96fab..49581fc50 100644 --- a/content/en/api/admin/invites/list.md +++ b/content/en/api/admin/invites/list.md @@ -137,7 +137,7 @@ List the organization's invites. ```bash curl https://api.anthropic.com/v1/organizations/invites \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/invites/retrieve.md b/content/en/api/admin/invites/retrieve.md index 898a9709d..91dfd9794 100644 --- a/content/en/api/admin/invites/retrieve.md +++ b/content/en/api/admin/invites/retrieve.md @@ -91,7 +91,7 @@ Retrieve an invite by ID. ```bash curl https://api.anthropic.com/v1/organizations/invites/$INVITE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/mcp_tunnels.md b/content/en/api/admin/mcp_tunnels.md index 305551e06..41a326b38 100644 --- a/content/en/api/admin/mcp_tunnels.md +++ b/content/en/api/admin/mcp_tunnels.md @@ -67,7 +67,7 @@ Retrieve a single tunnel in the caller's organization by ID. ```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -180,7 +180,7 @@ archived tunnels are excluded unless `include_archived` is set. ```bash curl https://api.anthropic.com/v1/organizations/tunnels \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -252,7 +252,7 @@ access logs. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/reveal_token \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -322,7 +322,7 @@ restarted after rotation must use the new value. An optional curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/rotate_token \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -408,7 +408,7 @@ tunnel returns the existing record unchanged. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -675,7 +675,7 @@ holds at most two non-archived certificates. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "ca_certificate_pem": "-----BEGIN CERTIFICATE-----\nMIIBexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexa\n...illustrative placeholder, not a real certificate...\n-----END CERTIFICATE-----\n" }' @@ -766,7 +766,7 @@ Retrieve a single certificate registered on a tunnel by ID. ```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -878,7 +878,7 @@ Archived certificates are excluded unless `include_archived` is set. ```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -976,7 +976,7 @@ certificate is added. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) diff --git a/content/en/api/admin/mcp_tunnels/archive.md b/content/en/api/admin/mcp_tunnels/archive.md index 9f29aae37..d8b571ba3 100644 --- a/content/en/api/admin/mcp_tunnels/archive.md +++ b/content/en/api/admin/mcp_tunnels/archive.md @@ -71,7 +71,7 @@ tunnel returns the existing record unchanged. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/mcp_tunnels/list.md b/content/en/api/admin/mcp_tunnels/list.md index 499121762..9b4b8e55b 100644 --- a/content/en/api/admin/mcp_tunnels/list.md +++ b/content/en/api/admin/mcp_tunnels/list.md @@ -94,7 +94,7 @@ archived tunnels are excluded unless `include_archived` is set. ```bash curl https://api.anthropic.com/v1/organizations/tunnels \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/mcp_tunnels/retrieve.md b/content/en/api/admin/mcp_tunnels/retrieve.md index 57ed5e5a6..99147feb5 100644 --- a/content/en/api/admin/mcp_tunnels/retrieve.md +++ b/content/en/api/admin/mcp_tunnels/retrieve.md @@ -65,7 +65,7 @@ Retrieve a single tunnel in the caller's organization by ID. ```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/mcp_tunnels/reveal_token.md b/content/en/api/admin/mcp_tunnels/reveal_token.md index b600a2ab4..00d47c61d 100644 --- a/content/en/api/admin/mcp_tunnels/reveal_token.md +++ b/content/en/api/admin/mcp_tunnels/reveal_token.md @@ -48,7 +48,7 @@ access logs. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/reveal_token \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/mcp_tunnels/rotate_token.md b/content/en/api/admin/mcp_tunnels/rotate_token.md index f4f88aa20..2d8d09891 100644 --- a/content/en/api/admin/mcp_tunnels/rotate_token.md +++ b/content/en/api/admin/mcp_tunnels/rotate_token.md @@ -55,7 +55,7 @@ restarted after rotation must use the new value. An optional curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/rotate_token \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/mcp_tunnels/tunnel_certificates.md b/content/en/api/admin/mcp_tunnels/tunnel_certificates.md index e3512be8a..692f38d0c 100644 --- a/content/en/api/admin/mcp_tunnels/tunnel_certificates.md +++ b/content/en/api/admin/mcp_tunnels/tunnel_certificates.md @@ -82,7 +82,7 @@ holds at most two non-archived certificates. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "ca_certificate_pem": "-----BEGIN CERTIFICATE-----\nMIIBexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexa\n...illustrative placeholder, not a real certificate...\n-----END CERTIFICATE-----\n" }' @@ -173,7 +173,7 @@ Retrieve a single certificate registered on a tunnel by ID. ```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -285,7 +285,7 @@ Archived certificates are excluded unless `include_archived` is set. ```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -383,7 +383,7 @@ certificate is added. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/mcp_tunnels/tunnel_certificates/archive.md b/content/en/api/admin/mcp_tunnels/tunnel_certificates/archive.md index a8831f4e3..8580052ce 100644 --- a/content/en/api/admin/mcp_tunnels/tunnel_certificates/archive.md +++ b/content/en/api/admin/mcp_tunnels/tunnel_certificates/archive.md @@ -74,7 +74,7 @@ certificate is added. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/mcp_tunnels/tunnel_certificates/create.md b/content/en/api/admin/mcp_tunnels/tunnel_certificates/create.md index 6d07775ea..86338ce80 100644 --- a/content/en/api/admin/mcp_tunnels/tunnel_certificates/create.md +++ b/content/en/api/admin/mcp_tunnels/tunnel_certificates/create.md @@ -80,7 +80,7 @@ holds at most two non-archived certificates. curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "ca_certificate_pem": "-----BEGIN CERTIFICATE-----\nMIIBexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexampleEXAMPLEexa\n...illustrative placeholder, not a real certificate...\n-----END CERTIFICATE-----\n" }' diff --git a/content/en/api/admin/mcp_tunnels/tunnel_certificates/list.md b/content/en/api/admin/mcp_tunnels/tunnel_certificates/list.md index 7b8825888..67d80ae49 100644 --- a/content/en/api/admin/mcp_tunnels/tunnel_certificates/list.md +++ b/content/en/api/admin/mcp_tunnels/tunnel_certificates/list.md @@ -93,7 +93,7 @@ Archived certificates are excluded unless `include_archived` is set. ```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/mcp_tunnels/tunnel_certificates/retrieve.md b/content/en/api/admin/mcp_tunnels/tunnel_certificates/retrieve.md index 874717c99..07fe87c81 100644 --- a/content/en/api/admin/mcp_tunnels/tunnel_certificates/retrieve.md +++ b/content/en/api/admin/mcp_tunnels/tunnel_certificates/retrieve.md @@ -69,7 +69,7 @@ Retrieve a single certificate registered on a tunnel by ID. ```bash curl https://api.anthropic.com/v1/organizations/tunnels/$TUNNEL_ID/certificates/$CERTIFICATE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/organizations.md b/content/en/api/admin/organizations.md index 772eaf9ef..43a58b22a 100644 --- a/content/en/api/admin/organizations.md +++ b/content/en/api/admin/organizations.md @@ -33,7 +33,7 @@ Retrieve information about the organization associated with the authenticated AP ```bash curl https://api.anthropic.com/v1/organizations/me \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/organizations/me.md b/content/en/api/admin/organizations/me.md index 48a160105..eec2676a2 100644 --- a/content/en/api/admin/organizations/me.md +++ b/content/en/api/admin/organizations/me.md @@ -31,7 +31,7 @@ Retrieve information about the organization associated with the authenticated AP ```bash curl https://api.anthropic.com/v1/organizations/me \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/rate_limits.md b/content/en/api/admin/rate_limits.md index b122c118b..9a9dcbae2 100644 --- a/content/en/api/admin/rate_limits.md +++ b/content/en/api/admin/rate_limits.md @@ -10,6 +10,10 @@ Each entry corresponds to one rate-limit group (either a model family or an API-surface category such as the Files API or Message Batches) and contains the set of limiter values that apply to it. +When `limit` is omitted, every matching entry is returned in a single +page; when `limit` truncates the result, follow `next_page` to fetch +the remaining entries. + ### Query parameters - `group_type: optional "batch" or "files" or "model_group" or 3 more` @@ -28,6 +32,14 @@ and contains the set of limiter values that apply to it. - `"web_search"` +- `limit: optional number` + + Maximum number of items to return per page. Ranges from `1` to `1000`. + + When omitted, every remaining entry is returned in a single page and `next_page` is `null`. + + maximum: 1000, minimum: 1 + - `model: optional string` Filter to the single entry containing this model. Accepts full model names and aliases. Returns 404 if the model is not found or has no rate limits for this organization. @@ -86,14 +98,14 @@ and contains the set of limiter values that apply to it. - `next_page: string or null` - Token to provide in as `page` in the subsequent request to retrieve the next page of data. + Opaque cursor for the next page of results, or `null` when no entries remain beyond this response. ### Example ```bash curl https://api.anthropic.com/v1/organizations/rate_limits \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -126,52 +138,44 @@ curl https://api.anthropic.com/v1/organizations/rate_limits \ - `RateLimitListResponse object` - - `data: array of object` - - Rate-limit entries for the organization, one per group. - - - `id: string` - - Stable identifier for this rate-limit group within the organization. - - - `group_type: "batch" or "files" or "model_group" or 3 more` + - `id: string` - The kind of rate-limit group this entry represents. `model_group` entries apply to a family of models (listed in `models`); other values apply to an API-surface category and have `models` set to `null`. + Stable identifier for this rate-limit group within the organization. - - `"batch"` + - `group_type: "batch" or "files" or "model_group" or 3 more` - - `"files"` + The kind of rate-limit group this entry represents. `model_group` entries apply to a family of models (listed in `models`); other values apply to an API-surface category and have `models` set to `null`. - - `"model_group"` + - `"batch"` - - `"skills"` + - `"files"` - - `"token_count"` + - `"model_group"` - - `"web_search"` + - `"skills"` - - `limits: array of object` + - `"token_count"` - The limiter values that apply to this group. + - `"web_search"` - - `type: string` + - `limits: array of object` - The limiter type (for example, `requests_per_minute` or `input_tokens_per_minute`). + The limiter values that apply to this group. - - `value: number` + - `type: string` - The configured limit value for this limiter type. + The limiter type (for example, `requests_per_minute` or `input_tokens_per_minute`). - - `models: array of string or null` + - `value: number` - Model names this entry's limits apply to, including aliases. `null` when `group_type` is not `"model_group"`. + The configured limit value for this limiter type. - - `type: "rate_limit"` + - `models: array of string or null` - Object type. Always `rate_limit` for organization rate-limit entries. + Model names this entry's limits apply to, including aliases. `null` when `group_type` is not `"model_group"`. - default: rate_limit + - `type: "rate_limit"` - - `next_page: string or null` + Object type. Always `rate_limit` for organization rate-limit entries. - Token to provide in as `page` in the subsequent request to retrieve the next page of data. + default: rate_limit diff --git a/content/en/api/admin/rate_limits/list.md b/content/en/api/admin/rate_limits/list.md index d902f35eb..aac109d9a 100644 --- a/content/en/api/admin/rate_limits/list.md +++ b/content/en/api/admin/rate_limits/list.md @@ -8,6 +8,10 @@ Each entry corresponds to one rate-limit group (either a model family or an API-surface category such as the Files API or Message Batches) and contains the set of limiter values that apply to it. +When `limit` is omitted, every matching entry is returned in a single +page; when `limit` truncates the result, follow `next_page` to fetch +the remaining entries. + ## Query parameters - `group_type: optional "batch" or "files" or "model_group" or 3 more` @@ -26,6 +30,14 @@ and contains the set of limiter values that apply to it. - `"web_search"` +- `limit: optional number` + + Maximum number of items to return per page. Ranges from `1` to `1000`. + + When omitted, every remaining entry is returned in a single page and `next_page` is `null`. + + maximum: 1000, minimum: 1 + - `model: optional string` Filter to the single entry containing this model. Accepts full model names and aliases. Returns 404 if the model is not found or has no rate limits for this organization. @@ -84,14 +96,14 @@ and contains the set of limiter values that apply to it. - `next_page: string or null` - Token to provide in as `page` in the subsequent request to retrieve the next page of data. + Opaque cursor for the next page of results, or `null` when no entries remain beyond this response. ## Example ```bash curl https://api.anthropic.com/v1/organizations/rate_limits \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/rbac_groups.md b/content/en/api/admin/rbac_groups.md index 93a5d5f93..2911907bb 100644 --- a/content/en/api/admin/rbac_groups.md +++ b/content/en/api/admin/rbac_groups.md @@ -79,7 +79,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_groups \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -167,7 +167,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -252,7 +252,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "name": "Engineering" }' @@ -278,7 +278,7 @@ curl https://api.anthropic.com/v1/organizations/rbac_groups \ **POST** `/v1/organizations/rbac_groups/{group_id}` -Update an RBAC Group's name. Groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. +Update an RBAC Group's name. Groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -346,7 +346,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "name": "Engineering" }' @@ -372,7 +372,7 @@ curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ **DELETE** `/v1/organizations/rbac_groups/{group_id}` -Delete an RBAC Group. Groups provisioned by an identity provider (source type `"scim"`) cannot be deleted via the API. +Delete an RBAC Group. Groups provisioned by an identity provider (source type `"scim"`) cannot be deleted via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -404,7 +404,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -551,7 +551,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -576,7 +576,7 @@ curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ **POST** `/v1/organizations/rbac_groups/{group_id}/members` -Add a User to an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. +Add a User to an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -628,7 +628,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q" }' @@ -650,7 +650,7 @@ curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ **DELETE** `/v1/organizations/rbac_groups/{group_id}/members/{user_id}` -Remove a User from an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. +Remove a User from an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -688,7 +688,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members/$USER_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) diff --git a/content/en/api/admin/rbac_groups/create.md b/content/en/api/admin/rbac_groups/create.md index cd5c04182..e8a901ce9 100644 --- a/content/en/api/admin/rbac_groups/create.md +++ b/content/en/api/admin/rbac_groups/create.md @@ -64,7 +64,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "name": "Engineering" }' diff --git a/content/en/api/admin/rbac_groups/delete.md b/content/en/api/admin/rbac_groups/delete.md index 2c02474f9..cfcef8261 100644 --- a/content/en/api/admin/rbac_groups/delete.md +++ b/content/en/api/admin/rbac_groups/delete.md @@ -2,7 +2,7 @@ **DELETE** `/v1/organizations/rbac_groups/{group_id}` -Delete an RBAC Group. Groups provisioned by an identity provider (source type `"scim"`) cannot be deleted via the API. +Delete an RBAC Group. Groups provisioned by an identity provider (source type `"scim"`) cannot be deleted via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -34,7 +34,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/rbac_groups/list.md b/content/en/api/admin/rbac_groups/list.md index 4b3199c19..03aea538a 100644 --- a/content/en/api/admin/rbac_groups/list.md +++ b/content/en/api/admin/rbac_groups/list.md @@ -77,7 +77,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_groups \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/rbac_groups/members.md b/content/en/api/admin/rbac_groups/members.md index 08a59ce83..7700fef15 100644 --- a/content/en/api/admin/rbac_groups/members.md +++ b/content/en/api/admin/rbac_groups/members.md @@ -71,7 +71,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -96,7 +96,7 @@ curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ **POST** `/v1/organizations/rbac_groups/{group_id}/members` -Add a User to an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. +Add a User to an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -148,7 +148,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q" }' @@ -170,7 +170,7 @@ curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ **DELETE** `/v1/organizations/rbac_groups/{group_id}/members/{user_id}` -Remove a User from an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. +Remove a User from an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -208,7 +208,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members/$USER_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/rbac_groups/members/create.md b/content/en/api/admin/rbac_groups/members/create.md index 77ad6b652..33d93850b 100644 --- a/content/en/api/admin/rbac_groups/members/create.md +++ b/content/en/api/admin/rbac_groups/members/create.md @@ -2,7 +2,7 @@ **POST** `/v1/organizations/rbac_groups/{group_id}/members` -Add a User to an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. +Add a User to an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -54,7 +54,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q" }' diff --git a/content/en/api/admin/rbac_groups/members/delete.md b/content/en/api/admin/rbac_groups/members/delete.md index db0b54232..410d7b3ab 100644 --- a/content/en/api/admin/rbac_groups/members/delete.md +++ b/content/en/api/admin/rbac_groups/members/delete.md @@ -2,7 +2,7 @@ **DELETE** `/v1/organizations/rbac_groups/{group_id}/members/{user_id}` -Remove a User from an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. +Remove a User from an RBAC Group. Membership of groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -40,7 +40,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members/$USER_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/rbac_groups/members/list.md b/content/en/api/admin/rbac_groups/members/list.md index 4f43d8646..f481fe06b 100644 --- a/content/en/api/admin/rbac_groups/members/list.md +++ b/content/en/api/admin/rbac_groups/members/list.md @@ -69,7 +69,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID/members \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/rbac_groups/retrieve.md b/content/en/api/admin/rbac_groups/retrieve.md index d63dbf8a7..2fc4a4e2b 100644 --- a/content/en/api/admin/rbac_groups/retrieve.md +++ b/content/en/api/admin/rbac_groups/retrieve.md @@ -61,7 +61,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/rbac_groups/update.md b/content/en/api/admin/rbac_groups/update.md index 99597f25e..a5860b3ca 100644 --- a/content/en/api/admin/rbac_groups/update.md +++ b/content/en/api/admin/rbac_groups/update.md @@ -2,7 +2,7 @@ **POST** `/v1/organizations/rbac_groups/{group_id}` -Update an RBAC Group's name. Groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API. +Update an RBAC Group's name. Groups provisioned by an identity provider (source type `"scim"`) cannot be modified via the API while an organization in the tenant uses SCIM provisioning. The RBAC Groups API is available to Claude Enterprise organizations only. @@ -70,7 +70,7 @@ The RBAC Groups API is available to Claude Enterprise organizations only. curl https://api.anthropic.com/v1/organizations/rbac_groups/$GROUP_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "name": "Engineering" }' diff --git a/content/en/api/admin/rbac_roles.md b/content/en/api/admin/rbac_roles.md index c8e9c6077..5c352099a 100644 --- a/content/en/api/admin/rbac_roles.md +++ b/content/en/api/admin/rbac_roles.md @@ -68,7 +68,7 @@ The RBAC Roles API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_roles \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -140,7 +140,7 @@ The RBAC Roles API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_roles/$ROLE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -346,7 +346,7 @@ The RBAC Roles API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_roles/$ROLE_ID/permissions \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) diff --git a/content/en/api/admin/rbac_roles/list.md b/content/en/api/admin/rbac_roles/list.md index 5608d8a5a..15e3e6d4f 100644 --- a/content/en/api/admin/rbac_roles/list.md +++ b/content/en/api/admin/rbac_roles/list.md @@ -66,7 +66,7 @@ The RBAC Roles API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_roles \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/rbac_roles/permissions.md b/content/en/api/admin/rbac_roles/permissions.md index a8bb34648..7b2648682 100644 --- a/content/en/api/admin/rbac_roles/permissions.md +++ b/content/en/api/admin/rbac_roles/permissions.md @@ -155,7 +155,7 @@ The RBAC Roles API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_roles/$ROLE_ID/permissions \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/rbac_roles/permissions/list.md b/content/en/api/admin/rbac_roles/permissions/list.md index a0aa42d34..4eb5577d7 100644 --- a/content/en/api/admin/rbac_roles/permissions/list.md +++ b/content/en/api/admin/rbac_roles/permissions/list.md @@ -153,7 +153,7 @@ The RBAC Roles API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_roles/$ROLE_ID/permissions \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/rbac_roles/retrieve.md b/content/en/api/admin/rbac_roles/retrieve.md index 5feb0388b..dc33903b5 100644 --- a/content/en/api/admin/rbac_roles/retrieve.md +++ b/content/en/api/admin/rbac_roles/retrieve.md @@ -49,7 +49,7 @@ The RBAC Roles API is available to Claude Enterprise organizations only. ```bash curl https://api.anthropic.com/v1/organizations/rbac_roles/$ROLE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/service_accounts.md b/content/en/api/admin/service_accounts.md index 8c15e988d..bd5a1909b 100644 --- a/content/en/api/admin/service_accounts.md +++ b/content/en/api/admin/service_accounts.md @@ -4,16 +4,17 @@ **POST** `/v1/organizations/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Create a service account. A service account is a named workload identity that federation rules target. `organization_role` is `developer` (default) or `admin`; a rule may only be created or retargeted to grant `org:admin` scope when the -target's `organization_role` is `admin`. Requires an OAuth bearer (user -or WIF-minted service account token) or a Console session; Admin API -keys are not accepted. Creating an `admin`-role service account requires -an interactive credential (a user OAuth token or a Console session) — a -workload may only create `developer`-role service accounts. +target's `organization_role` is `admin`. Creating an `admin`-role service +account requires an interactive credential (a user OAuth token or a +Console session) — a workload may only create `developer`-role service +accounts. ### Headers @@ -114,7 +115,7 @@ workload may only create `developer`-role service accounts. curl https://api.anthropic.com/v1/organizations/service_accounts \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "name": "ci-deploy-bot" }' @@ -142,6 +143,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts \ **GET** `/v1/organizations/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a service account by its ID (`svac_...`). ### Path parameters @@ -226,7 +229,7 @@ Retrieve a service account by its ID (`svac_...`). ```bash curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -251,6 +254,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **GET** `/v1/organizations/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List service accounts in the caller's organization. Results are ordered by creation time, newest first. Use `limit` and the @@ -350,7 +355,7 @@ archived service accounts. ```bash curl https://api.anthropic.com/v1/organizations/service_accounts \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -380,13 +385,14 @@ curl https://api.anthropic.com/v1/organizations/service_accounts \ **POST** `/v1/organizations/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Update a service account. Only `description` and `organization_role` are mutable; `name` cannot be changed. Archived service accounts cannot be updated; this returns 400. Setting `organization_role` to `admin` (even when unchanged) requires an -interactive credential (a user OAuth token or a Console session). Admin -API keys are not accepted. +interactive credential (a user OAuth token or a Console session). ### Path parameters @@ -487,7 +493,7 @@ API keys are not accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` @@ -513,6 +519,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **POST** `/v1/organizations/service_accounts/{service_account_id}/archive` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Archive a service account. Idempotent; re-archiving returns the service account with its original @@ -520,9 +528,6 @@ Idempotent; re-archiving returns the service account with its original rule still targets this service account, same as issuer archival; archive those rules first or change their target to another service account. -Requires an OAuth bearer or Console session; Admin API keys are not -accepted. - ### Path parameters - `service_account_id: string` @@ -606,7 +611,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -698,6 +703,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **POST** `/v1/organizations/service_accounts/{service_account_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Add a service account to a workspace with the given `workspace_role`. Mirror of `POST /workspaces/{workspace_id}/service_accounts`, addressed @@ -705,8 +712,7 @@ from the service-account side; both create the same membership. If the service account is already an explicit member of the workspace, its `workspace_role` is replaced with the value supplied here. Archived workspaces return 400. Archived service accounts cannot be added and are -rejected. Requires an OAuth bearer or Console session; Admin API keys -are not accepted. +rejected. #### Path parameters @@ -782,7 +788,7 @@ are not accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_id": "workspace_id", "workspace_role": "workspace_admin" @@ -806,6 +812,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **GET** `/v1/organizations/service_accounts/{service_account_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List the workspaces a service account is a member of. Each entry includes the service account's `workspace_role` in that @@ -815,8 +823,12 @@ implicit (`implicit: true`) membership is returned as the first entry on the first page; with `limit=1` the first page may return up to 2 entries (the implicit entry plus one explicit membership) so a pagination cursor can be derived. Memberships are returned only while -the service account is active; an archived service account returns an -empty list. +the service account is active. Without a `page` cursor, an archived +service account returns an empty list. A `page` cursor that does not +match an active membership returns a 400 invalid-request error. A cursor +stops matching when the membership is removed, the workspace is deleted, +or the service account is archived. Restart pagination from the first +page to recover. #### Path parameters @@ -891,7 +903,7 @@ empty list. ```bash curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -916,6 +928,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **DELETE** `/v1/organizations/service_accounts/{service_account_id}/workspaces/{workspace_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Remove a service account from a workspace. Mirror of `DELETE /workspaces/{workspace_id}/service_accounts/{service_account_id}`, @@ -924,8 +938,7 @@ addressed from the service-account side. Removal is idempotent (returns implicit default-workspace membership returns 200 but is a no-op and the membership persists; deleting an explicit default-workspace row reverts to the implicit `workspace_user` membership. Archived workspaces return -400. Requires an OAuth bearer or Console session; Admin API keys are not -accepted. +400. #### Path parameters @@ -965,7 +978,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces/$WORKSPACE_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) diff --git a/content/en/api/admin/service_accounts/archive.md b/content/en/api/admin/service_accounts/archive.md index e53fa9540..fe241ca69 100644 --- a/content/en/api/admin/service_accounts/archive.md +++ b/content/en/api/admin/service_accounts/archive.md @@ -2,6 +2,8 @@ **POST** `/v1/organizations/service_accounts/{service_account_id}/archive` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Archive a service account. Idempotent; re-archiving returns the service account with its original @@ -9,9 +11,6 @@ Idempotent; re-archiving returns the service account with its original rule still targets this service account, same as issuer archival; archive those rules first or change their target to another service account. -Requires an OAuth bearer or Console session; Admin API keys are not -accepted. - ## Path parameters - `service_account_id: string` @@ -95,7 +94,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/service_accounts/create.md b/content/en/api/admin/service_accounts/create.md index 86669d06e..f4d409e81 100644 --- a/content/en/api/admin/service_accounts/create.md +++ b/content/en/api/admin/service_accounts/create.md @@ -2,16 +2,17 @@ **POST** `/v1/organizations/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Create a service account. A service account is a named workload identity that federation rules target. `organization_role` is `developer` (default) or `admin`; a rule may only be created or retargeted to grant `org:admin` scope when the -target's `organization_role` is `admin`. Requires an OAuth bearer (user -or WIF-minted service account token) or a Console session; Admin API -keys are not accepted. Creating an `admin`-role service account requires -an interactive credential (a user OAuth token or a Console session) — a -workload may only create `developer`-role service accounts. +target's `organization_role` is `admin`. Creating an `admin`-role service +account requires an interactive credential (a user OAuth token or a +Console session) — a workload may only create `developer`-role service +accounts. ## Headers @@ -112,7 +113,7 @@ workload may only create `developer`-role service accounts. curl https://api.anthropic.com/v1/organizations/service_accounts \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "name": "ci-deploy-bot" }' diff --git a/content/en/api/admin/service_accounts/list.md b/content/en/api/admin/service_accounts/list.md index b4148f798..0fab2d19e 100644 --- a/content/en/api/admin/service_accounts/list.md +++ b/content/en/api/admin/service_accounts/list.md @@ -2,6 +2,8 @@ **GET** `/v1/organizations/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List service accounts in the caller's organization. Results are ordered by creation time, newest first. Use `limit` and the @@ -101,7 +103,7 @@ archived service accounts. ```bash curl https://api.anthropic.com/v1/organizations/service_accounts \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/service_accounts/retrieve.md b/content/en/api/admin/service_accounts/retrieve.md index ecb951e01..0dc53551d 100644 --- a/content/en/api/admin/service_accounts/retrieve.md +++ b/content/en/api/admin/service_accounts/retrieve.md @@ -2,6 +2,8 @@ **GET** `/v1/organizations/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a service account by its ID (`svac_...`). ## Path parameters @@ -86,7 +88,7 @@ Retrieve a service account by its ID (`svac_...`). ```bash curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/service_accounts/update.md b/content/en/api/admin/service_accounts/update.md index 3c6adaac2..4a12219f3 100644 --- a/content/en/api/admin/service_accounts/update.md +++ b/content/en/api/admin/service_accounts/update.md @@ -2,13 +2,14 @@ **POST** `/v1/organizations/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Update a service account. Only `description` and `organization_role` are mutable; `name` cannot be changed. Archived service accounts cannot be updated; this returns 400. Setting `organization_role` to `admin` (even when unchanged) requires an -interactive credential (a user OAuth token or a Console session). Admin -API keys are not accepted. +interactive credential (a user OAuth token or a Console session). ## Path parameters @@ -109,7 +110,7 @@ API keys are not accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` diff --git a/content/en/api/admin/service_accounts/workspaces.md b/content/en/api/admin/service_accounts/workspaces.md index a672dd108..3242b79f4 100644 --- a/content/en/api/admin/service_accounts/workspaces.md +++ b/content/en/api/admin/service_accounts/workspaces.md @@ -4,6 +4,8 @@ **POST** `/v1/organizations/service_accounts/{service_account_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Add a service account to a workspace with the given `workspace_role`. Mirror of `POST /workspaces/{workspace_id}/service_accounts`, addressed @@ -11,8 +13,7 @@ from the service-account side; both create the same membership. If the service account is already an explicit member of the workspace, its `workspace_role` is replaced with the value supplied here. Archived workspaces return 400. Archived service accounts cannot be added and are -rejected. Requires an OAuth bearer or Console session; Admin API keys -are not accepted. +rejected. ### Path parameters @@ -88,7 +89,7 @@ are not accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_id": "workspace_id", "workspace_role": "workspace_admin" @@ -112,6 +113,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **GET** `/v1/organizations/service_accounts/{service_account_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List the workspaces a service account is a member of. Each entry includes the service account's `workspace_role` in that @@ -121,8 +124,12 @@ implicit (`implicit: true`) membership is returned as the first entry on the first page; with `limit=1` the first page may return up to 2 entries (the implicit entry plus one explicit membership) so a pagination cursor can be derived. Memberships are returned only while -the service account is active; an archived service account returns an -empty list. +the service account is active. Without a `page` cursor, an archived +service account returns an empty list. A `page` cursor that does not +match an active membership returns a 400 invalid-request error. A cursor +stops matching when the membership is removed, the workspace is deleted, +or the service account is archived. Restart pagination from the first +page to recover. ### Path parameters @@ -197,7 +204,7 @@ empty list. ```bash curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -222,6 +229,8 @@ curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUN **DELETE** `/v1/organizations/service_accounts/{service_account_id}/workspaces/{workspace_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Remove a service account from a workspace. Mirror of `DELETE /workspaces/{workspace_id}/service_accounts/{service_account_id}`, @@ -230,8 +239,7 @@ addressed from the service-account side. Removal is idempotent (returns implicit default-workspace membership returns 200 but is a no-op and the membership persists; deleting an explicit default-workspace row reverts to the implicit `workspace_user` membership. Archived workspaces return -400. Requires an OAuth bearer or Console session; Admin API keys are not -accepted. +400. ### Path parameters @@ -271,7 +279,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces/$WORKSPACE_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/service_accounts/workspaces/create.md b/content/en/api/admin/service_accounts/workspaces/create.md index e89fa2831..a8d327f19 100644 --- a/content/en/api/admin/service_accounts/workspaces/create.md +++ b/content/en/api/admin/service_accounts/workspaces/create.md @@ -2,6 +2,8 @@ **POST** `/v1/organizations/service_accounts/{service_account_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Add a service account to a workspace with the given `workspace_role`. Mirror of `POST /workspaces/{workspace_id}/service_accounts`, addressed @@ -9,8 +11,7 @@ from the service-account side; both create the same membership. If the service account is already an explicit member of the workspace, its `workspace_role` is replaced with the value supplied here. Archived workspaces return 400. Archived service accounts cannot be added and are -rejected. Requires an OAuth bearer or Console session; Admin API keys -are not accepted. +rejected. ## Path parameters @@ -86,7 +87,7 @@ are not accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_id": "workspace_id", "workspace_role": "workspace_admin" diff --git a/content/en/api/admin/service_accounts/workspaces/delete.md b/content/en/api/admin/service_accounts/workspaces/delete.md index b4e6ffb6e..8cd41c327 100644 --- a/content/en/api/admin/service_accounts/workspaces/delete.md +++ b/content/en/api/admin/service_accounts/workspaces/delete.md @@ -2,6 +2,8 @@ **DELETE** `/v1/organizations/service_accounts/{service_account_id}/workspaces/{workspace_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Remove a service account from a workspace. Mirror of `DELETE /workspaces/{workspace_id}/service_accounts/{service_account_id}`, @@ -10,8 +12,7 @@ addressed from the service-account side. Removal is idempotent (returns implicit default-workspace membership returns 200 but is a no-op and the membership persists; deleting an explicit default-workspace row reverts to the implicit `workspace_user` membership. Archived workspaces return -400. Requires an OAuth bearer or Console session; Admin API keys are not -accepted. +400. ## Path parameters @@ -51,7 +52,7 @@ accepted. curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces/$WORKSPACE_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/service_accounts/workspaces/list.md b/content/en/api/admin/service_accounts/workspaces/list.md index b16dcb7bb..71a3724d9 100644 --- a/content/en/api/admin/service_accounts/workspaces/list.md +++ b/content/en/api/admin/service_accounts/workspaces/list.md @@ -2,6 +2,8 @@ **GET** `/v1/organizations/service_accounts/{service_account_id}/workspaces` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List the workspaces a service account is a member of. Each entry includes the service account's `workspace_role` in that @@ -11,8 +13,12 @@ implicit (`implicit: true`) membership is returned as the first entry on the first page; with `limit=1` the first page may return up to 2 entries (the implicit entry plus one explicit membership) so a pagination cursor can be derived. Memberships are returned only while -the service account is active; an archived service account returns an -empty list. +the service account is active. Without a `page` cursor, an archived +service account returns an empty list. A `page` cursor that does not +match an active membership returns a 400 invalid-request error. A cursor +stops matching when the membership is removed, the workspace is deleted, +or the service account is archived. Restart pagination from the first +page to recover. ## Path parameters @@ -87,7 +93,7 @@ empty list. ```bash curl https://api.anthropic.com/v1/organizations/service_accounts/$SERVICE_ACCOUNT_ID/workspaces \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/spend_limits.md b/content/en/api/admin/spend_limits.md index b6ac60f92..68598605a 100644 --- a/content/en/api/admin/spend_limits.md +++ b/content/en/api/admin/spend_limits.md @@ -138,7 +138,7 @@ group, and organization-level defaults are configured in claude.ai. curl https://api.anthropic.com/v1/organizations/spend_limits \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "amount": "50000", "scope": { @@ -278,7 +278,7 @@ Retrieve a spend limit by ID. ```bash curl https://api.anthropic.com/v1/organizations/spend_limits/$SPEND_LIMIT_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -329,7 +329,7 @@ this endpoint. curl https://api.anthropic.com/v1/organizations/spend_limits/$SPEND_LIMIT_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -508,7 +508,7 @@ Paginates by member, so a member's periods never split across pages. ```bash curl https://api.anthropic.com/v1/organizations/spend_limits/effective \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -1043,7 +1043,7 @@ Requests whose requester is no longer a member are excluded. ```bash curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1350,7 +1350,7 @@ requester at the request's period. ```bash curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$SPEND_LIMIT_INCREASE_REQUEST_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1761,7 +1761,7 @@ the member was blocked on. Anthropic emails the requester unless curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$SPEND_LIMIT_INCREASE_REQUEST_ID/approve \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "amount": "50000", "period": "monthly" @@ -2085,7 +2085,7 @@ Idempotent on `denied`; denying an already-`approved` request returns curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$SPEND_LIMIT_INCREASE_REQUEST_ID/deny \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` diff --git a/content/en/api/admin/spend_limits/create.md b/content/en/api/admin/spend_limits/create.md index a3a07debf..876a2744d 100644 --- a/content/en/api/admin/spend_limits/create.md +++ b/content/en/api/admin/spend_limits/create.md @@ -136,7 +136,7 @@ group, and organization-level defaults are configured in claude.ai. curl https://api.anthropic.com/v1/organizations/spend_limits \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "amount": "50000", "scope": { diff --git a/content/en/api/admin/spend_limits/delete.md b/content/en/api/admin/spend_limits/delete.md index 6f1c4e71b..00c4dd860 100644 --- a/content/en/api/admin/spend_limits/delete.md +++ b/content/en/api/admin/spend_limits/delete.md @@ -28,7 +28,7 @@ this endpoint. curl https://api.anthropic.com/v1/organizations/spend_limits/$SPEND_LIMIT_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/spend_limits/increase_requests.md b/content/en/api/admin/spend_limits/increase_requests.md index 1900fb925..eb0d19983 100644 --- a/content/en/api/admin/spend_limits/increase_requests.md +++ b/content/en/api/admin/spend_limits/increase_requests.md @@ -270,7 +270,7 @@ Requests whose requester is no longer a member are excluded. ```bash curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -577,7 +577,7 @@ requester at the request's period. ```bash curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$SPEND_LIMIT_INCREASE_REQUEST_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -988,7 +988,7 @@ the member was blocked on. Anthropic emails the requester unless curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$SPEND_LIMIT_INCREASE_REQUEST_ID/approve \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "amount": "50000", "period": "monthly" @@ -1312,7 +1312,7 @@ Idempotent on `denied`; denying an already-`approved` request returns curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$SPEND_LIMIT_INCREASE_REQUEST_ID/deny \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` diff --git a/content/en/api/admin/spend_limits/increase_requests/approve.md b/content/en/api/admin/spend_limits/increase_requests/approve.md index 8ac669deb..bdef6de35 100644 --- a/content/en/api/admin/spend_limits/increase_requests/approve.md +++ b/content/en/api/admin/spend_limits/increase_requests/approve.md @@ -357,7 +357,7 @@ the member was blocked on. Anthropic emails the requester unless curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$SPEND_LIMIT_INCREASE_REQUEST_ID/approve \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "amount": "50000", "period": "monthly" diff --git a/content/en/api/admin/spend_limits/increase_requests/deny.md b/content/en/api/admin/spend_limits/increase_requests/deny.md index bddabbf86..e5c76ce7c 100644 --- a/content/en/api/admin/spend_limits/increase_requests/deny.md +++ b/content/en/api/admin/spend_limits/increase_requests/deny.md @@ -253,7 +253,7 @@ Idempotent on `denied`; denying an already-`approved` request returns curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$SPEND_LIMIT_INCREASE_REQUEST_ID/deny \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{}' ``` diff --git a/content/en/api/admin/spend_limits/increase_requests/list.md b/content/en/api/admin/spend_limits/increase_requests/list.md index 87435b3e5..6ffa08de9 100644 --- a/content/en/api/admin/spend_limits/increase_requests/list.md +++ b/content/en/api/admin/spend_limits/increase_requests/list.md @@ -268,7 +268,7 @@ Requests whose requester is no longer a member are excluded. ```bash curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/spend_limits/increase_requests/retrieve.md b/content/en/api/admin/spend_limits/increase_requests/retrieve.md index b9fc62868..5ad4a85ca 100644 --- a/content/en/api/admin/spend_limits/increase_requests/retrieve.md +++ b/content/en/api/admin/spend_limits/increase_requests/retrieve.md @@ -248,7 +248,7 @@ requester at the request's period. ```bash curl https://api.anthropic.com/v1/organizations/spend_limit_increase_requests/$SPEND_LIMIT_INCREASE_REQUEST_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/spend_limits/list_effective.md b/content/en/api/admin/spend_limits/list_effective.md index 172f15902..88497ad7d 100644 --- a/content/en/api/admin/spend_limits/list_effective.md +++ b/content/en/api/admin/spend_limits/list_effective.md @@ -165,7 +165,7 @@ Paginates by member, so a member's periods never split across pages. ```bash curl https://api.anthropic.com/v1/organizations/spend_limits/effective \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/spend_limits/retrieve.md b/content/en/api/admin/spend_limits/retrieve.md index aeba54bcb..5e2330a99 100644 --- a/content/en/api/admin/spend_limits/retrieve.md +++ b/content/en/api/admin/spend_limits/retrieve.md @@ -109,7 +109,7 @@ Retrieve a spend limit by ID. ```bash curl https://api.anthropic.com/v1/organizations/spend_limits/$SPEND_LIMIT_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/usage_report.md b/content/en/api/admin/usage_report.md index 2ae518d42..d4c576997 100644 --- a/content/en/api/admin/usage_report.md +++ b/content/en/api/admin/usage_report.md @@ -263,7 +263,7 @@ Get Messages Usage Report ```bash curl https://api.anthropic.com/v1/organizations/usage_report/messages \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -489,7 +489,7 @@ Enables organizations to analyze developer productivity and build custom dashboa ```bash curl https://api.anthropic.com/v1/organizations/usage_report/claude_code \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/usage_report/retrieve_claude_code.md b/content/en/api/admin/usage_report/retrieve_claude_code.md index 136ccaaec..14b1b97e8 100644 --- a/content/en/api/admin/usage_report/retrieve_claude_code.md +++ b/content/en/api/admin/usage_report/retrieve_claude_code.md @@ -184,7 +184,7 @@ Enables organizations to analyze developer productivity and build custom dashboa ```bash curl https://api.anthropic.com/v1/organizations/usage_report/claude_code \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/usage_report/retrieve_messages.md b/content/en/api/admin/usage_report/retrieve_messages.md index bad8cb070..173b684e1 100644 --- a/content/en/api/admin/usage_report/retrieve_messages.md +++ b/content/en/api/admin/usage_report/retrieve_messages.md @@ -261,7 +261,7 @@ Get Messages Usage Report ```bash curl https://api.anthropic.com/v1/organizations/usage_report/messages \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/users.md b/content/en/api/admin/users.md index b1668944a..87be90adb 100644 --- a/content/en/api/admin/users.md +++ b/content/en/api/admin/users.md @@ -69,7 +69,7 @@ Retrieve a member of the organization by user ID. ```bash curl https://api.anthropic.com/v1/organizations/users/$USER_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -190,7 +190,7 @@ List the organization's members. ```bash curl https://api.anthropic.com/v1/organizations/users \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -301,7 +301,7 @@ Update a member's organization role. curl https://api.anthropic.com/v1/organizations/users/$USER_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "role": "user" }' @@ -352,7 +352,7 @@ Remove a member from the organization. curl https://api.anthropic.com/v1/organizations/users/$USER_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/users/delete.md b/content/en/api/admin/users/delete.md index 68aef1c62..13d74aa2a 100644 --- a/content/en/api/admin/users/delete.md +++ b/content/en/api/admin/users/delete.md @@ -30,7 +30,7 @@ Remove a member from the organization. curl https://api.anthropic.com/v1/organizations/users/$USER_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/users/list.md b/content/en/api/admin/users/list.md index d2ea0b00f..7de5f9f5f 100644 --- a/content/en/api/admin/users/list.md +++ b/content/en/api/admin/users/list.md @@ -103,7 +103,7 @@ List the organization's members. ```bash curl https://api.anthropic.com/v1/organizations/users \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/users/retrieve.md b/content/en/api/admin/users/retrieve.md index 03fbf440d..5a9ccd0e8 100644 --- a/content/en/api/admin/users/retrieve.md +++ b/content/en/api/admin/users/retrieve.md @@ -67,7 +67,7 @@ Retrieve a member of the organization by user ID. ```bash curl https://api.anthropic.com/v1/organizations/users/$USER_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/users/update.md b/content/en/api/admin/users/update.md index 8bec05188..cbbbf61ca 100644 --- a/content/en/api/admin/users/update.md +++ b/content/en/api/admin/users/update.md @@ -86,7 +86,7 @@ Update a member's organization role. curl https://api.anthropic.com/v1/organizations/users/$USER_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "role": "user" }' diff --git a/content/en/api/admin/workspaces.md b/content/en/api/admin/workspaces.md index 77381c5a7..360a589b1 100644 --- a/content/en/api/admin/workspaces.md +++ b/content/en/api/admin/workspaces.md @@ -50,15 +50,25 @@ Create Workspace Geographic region for workspace data storage. Immutable after creation. Defaults to 'us' if omitted. +- `display_color: optional string or null` + + Hex color code representing the Workspace in the Anthropic Console. + + maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$ + - `external_key_id: optional string or null` ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `tags: optional map[string] or null` @@ -84,8 +94,13 @@ Create Workspace customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -122,10 +137,14 @@ Create Workspace ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -149,9 +168,10 @@ Create Workspace curl https://api.anthropic.com/v1/organizations/workspaces \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "name": "x", + "display_color": "#6C5BB9", "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK", "tags": { "env": "prod", @@ -216,8 +236,13 @@ Get Workspace customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -254,10 +279,14 @@ Get Workspace ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -280,7 +309,7 @@ Get Workspace ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -357,8 +386,13 @@ List Workspaces customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -395,10 +429,14 @@ List Workspaces ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -433,7 +471,7 @@ List Workspaces ```bash curl https://api.anthropic.com/v1/organizations/workspaces \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -503,15 +541,25 @@ Update Workspace - `"us"` +- `display_color: optional string` + + Hex color code representing the Workspace in the Anthropic Console. + + maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$ + - `external_key_id: optional string` ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: optional string` @@ -543,8 +591,13 @@ Update Workspace customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -581,10 +634,14 @@ Update Workspace ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -608,8 +665,9 @@ Update Workspace curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ + "display_color": "#6C5BB9", "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK", "tags": { "env": "prod", @@ -672,8 +730,13 @@ Archive Workspace customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -710,10 +773,14 @@ Archive Workspace ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -737,7 +804,7 @@ Archive Workspace curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -836,7 +903,7 @@ Create Workspace Member curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q", "workspace_role": "workspace_admin" @@ -909,7 +976,7 @@ Get Workspace Member ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1004,7 +1071,7 @@ List Workspace Members ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1097,7 +1164,7 @@ Update Workspace Member curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_role": "workspace_admin" }' @@ -1154,7 +1221,7 @@ Delete Workspace Member curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1179,6 +1246,10 @@ Returns only the groups and limiter types that have a workspace-level override. Groups without overrides inherit the organization limits and are not listed; use `GET /v1/organizations/rate_limits` to see those. +When `limit` is omitted, every matching entry is returned in a single +page; when `limit` truncates the result, follow `next_page` to fetch +the remaining entries. + #### Path parameters - `workspace_id: string` @@ -1203,6 +1274,14 @@ are not listed; use `GET /v1/organizations/rate_limits` to see those. - `"web_search"` +- `limit: optional number` + + Maximum number of items to return per page. Ranges from `1` to `1000`. + + When omitted, every remaining entry is returned in a single page and `next_page` is `null`. + + maximum: 1000, minimum: 1 + - `page: optional string` Opaque cursor from a previous response's `next_page`. @@ -1265,14 +1344,14 @@ are not listed; use `GET /v1/organizations/rate_limits` to see those. - `next_page: string or null` - Token to provide in as `page` in the subsequent request to retrieve the next page of data. + Opaque cursor for the next page of results, or `null` when no entries remain beyond this response. #### Example ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/rate_limits \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1307,6 +1386,8 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/rate_li **POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Add a service account to a workspace with the given `workspace_role`. The role determines what the service account can do in the workspace and @@ -1316,8 +1397,7 @@ through federation. Every service account is already an implicit assigns a chosen role. If the service account is already an explicit member of the workspace, its `workspace_role` is replaced with the value supplied here. Archived workspaces return 400. Archived service -accounts cannot be added and are rejected. Requires an OAuth bearer or -Console session; Admin API keys are not accepted. +accounts cannot be added and are rejected. #### Path parameters @@ -1393,7 +1473,7 @@ Console session; Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "service_account_id": "service_account_id", "workspace_role": "workspace_admin" @@ -1417,6 +1497,8 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service **GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a service account's membership in a workspace. Returns the membership record, including the service account's @@ -1485,7 +1567,7 @@ account returns 404. ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1505,6 +1587,8 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service **GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List the service accounts that are members of a workspace. Each entry includes the service account's `workspace_role`. Use `limit` @@ -1587,7 +1671,7 @@ omitted from the results. ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) @@ -1612,6 +1696,8 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service **POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Change a service account's role in a workspace. The new `workspace_role` replaces the current one. Only explicit @@ -1619,8 +1705,7 @@ memberships can be updated; to set a role on the implicit default-workspace membership, add the service account explicitly with `POST /workspaces/{workspace_id}/service_accounts`. Archived workspaces return 400. Archived service accounts cannot be updated and are -rejected. Requires an OAuth bearer or Console session; Admin API keys -are not accepted. +rejected. #### Path parameters @@ -1696,7 +1781,7 @@ are not accepted. curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_role": "workspace_admin" }' @@ -1719,14 +1804,15 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service **DELETE** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Remove a service account from a workspace. Removal is idempotent (returns 200 even if the membership was already removed). A DELETE against the implicit default-workspace membership returns 200 but is a no-op and the membership persists; deleting an explicit default-workspace row reverts to the implicit `workspace_user` -membership. Archived workspaces return 400. Requires an OAuth bearer or -Console session; Admin API keys are not accepted. +membership. Archived workspaces return 400. #### Path parameters @@ -1766,7 +1852,7 @@ Console session; Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ##### Response (200) diff --git a/content/en/api/admin/workspaces/archive.md b/content/en/api/admin/workspaces/archive.md index cc3477cc6..9cbeb4058 100644 --- a/content/en/api/admin/workspaces/archive.md +++ b/content/en/api/admin/workspaces/archive.md @@ -28,8 +28,13 @@ Archive Workspace customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -66,10 +71,14 @@ Archive Workspace ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -93,7 +102,7 @@ Archive Workspace curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/workspaces/create.md b/content/en/api/admin/workspaces/create.md index 2a67808df..3d2aeb7c8 100644 --- a/content/en/api/admin/workspaces/create.md +++ b/content/en/api/admin/workspaces/create.md @@ -48,15 +48,25 @@ Create Workspace Geographic region for workspace data storage. Immutable after creation. Defaults to 'us' if omitted. +- `display_color: optional string or null` + + Hex color code representing the Workspace in the Anthropic Console. + + maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$ + - `external_key_id: optional string or null` ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `tags: optional map[string] or null` @@ -82,8 +92,13 @@ Create Workspace customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -120,10 +135,14 @@ Create Workspace ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -147,9 +166,10 @@ Create Workspace curl https://api.anthropic.com/v1/organizations/workspaces \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "name": "x", + "display_color": "#6C5BB9", "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK", "tags": { "env": "prod", diff --git a/content/en/api/admin/workspaces/list.md b/content/en/api/admin/workspaces/list.md index 2602295d9..2327031e4 100644 --- a/content/en/api/admin/workspaces/list.md +++ b/content/en/api/admin/workspaces/list.md @@ -48,8 +48,13 @@ List Workspaces customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -86,10 +91,14 @@ List Workspaces ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -124,7 +133,7 @@ List Workspaces ```bash curl https://api.anthropic.com/v1/organizations/workspaces \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/workspaces/members.md b/content/en/api/admin/workspaces/members.md index 7ca589372..0b33bed87 100644 --- a/content/en/api/admin/workspaces/members.md +++ b/content/en/api/admin/workspaces/members.md @@ -70,7 +70,7 @@ Create Workspace Member curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q", "workspace_role": "workspace_admin" @@ -143,7 +143,7 @@ Get Workspace Member ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -238,7 +238,7 @@ List Workspace Members ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -331,7 +331,7 @@ Update Workspace Member curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_role": "workspace_admin" }' @@ -388,7 +388,7 @@ Delete Workspace Member curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/workspaces/members/create.md b/content/en/api/admin/workspaces/members/create.md index c617ddfa2..50c3a9455 100644 --- a/content/en/api/admin/workspaces/members/create.md +++ b/content/en/api/admin/workspaces/members/create.md @@ -68,7 +68,7 @@ Create Workspace Member curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q", "workspace_role": "workspace_admin" diff --git a/content/en/api/admin/workspaces/members/delete.md b/content/en/api/admin/workspaces/members/delete.md index 13c66cf60..25533f4e8 100644 --- a/content/en/api/admin/workspaces/members/delete.md +++ b/content/en/api/admin/workspaces/members/delete.md @@ -38,7 +38,7 @@ Delete Workspace Member curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/workspaces/members/list.md b/content/en/api/admin/workspaces/members/list.md index 8a96b96bb..19d719c0b 100644 --- a/content/en/api/admin/workspaces/members/list.md +++ b/content/en/api/admin/workspaces/members/list.md @@ -79,7 +79,7 @@ List Workspace Members ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/workspaces/members/retrieve.md b/content/en/api/admin/workspaces/members/retrieve.md index 8be6eb284..b482c1522 100644 --- a/content/en/api/admin/workspaces/members/retrieve.md +++ b/content/en/api/admin/workspaces/members/retrieve.md @@ -53,7 +53,7 @@ Get Workspace Member ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/workspaces/members/update.md b/content/en/api/admin/workspaces/members/update.md index 282f74b1a..5bdbd0ab6 100644 --- a/content/en/api/admin/workspaces/members/update.md +++ b/content/en/api/admin/workspaces/members/update.md @@ -70,7 +70,7 @@ Update Workspace Member curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/members/$USER_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_role": "workspace_admin" }' diff --git a/content/en/api/admin/workspaces/rate_limits.md b/content/en/api/admin/workspaces/rate_limits.md index 3604e9ccb..b69abdf5d 100644 --- a/content/en/api/admin/workspaces/rate_limits.md +++ b/content/en/api/admin/workspaces/rate_limits.md @@ -10,6 +10,10 @@ Returns only the groups and limiter types that have a workspace-level override. Groups without overrides inherit the organization limits and are not listed; use `GET /v1/organizations/rate_limits` to see those. +When `limit` is omitted, every matching entry is returned in a single +page; when `limit` truncates the result, follow `next_page` to fetch +the remaining entries. + ### Path parameters - `workspace_id: string` @@ -34,6 +38,14 @@ are not listed; use `GET /v1/organizations/rate_limits` to see those. - `"web_search"` +- `limit: optional number` + + Maximum number of items to return per page. Ranges from `1` to `1000`. + + When omitted, every remaining entry is returned in a single page and `next_page` is `null`. + + maximum: 1000, minimum: 1 + - `page: optional string` Opaque cursor from a previous response's `next_page`. @@ -96,14 +108,14 @@ are not listed; use `GET /v1/organizations/rate_limits` to see those. - `next_page: string or null` - Token to provide in as `page` in the subsequent request to retrieve the next page of data. + Opaque cursor for the next page of results, or `null` when no entries remain beyond this response. ### Example ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/rate_limits \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -138,60 +150,52 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/rate_li - `RateLimitListResponse object` - - `data: array of object` - - Rate-limit entries for the workspace, one per group that has at least one override. - - - `group_type: "batch" or "files" or "model_group" or 3 more` - - The kind of rate-limit group this entry represents. `model_group` entries apply to a family of models (listed in `models`); other values apply to an API-surface category and have `models` set to `null`. - - - `"batch"` + - `group_type: "batch" or "files" or "model_group" or 3 more` - - `"files"` + The kind of rate-limit group this entry represents. `model_group` entries apply to a family of models (listed in `models`); other values apply to an API-surface category and have `models` set to `null`. - - `"model_group"` + - `"batch"` - - `"skills"` + - `"files"` - - `"token_count"` + - `"model_group"` - - `"web_search"` + - `"skills"` - - `limits: array of object` + - `"token_count"` - The limiter values overridden for this group in this workspace. Limiter types without a workspace override are omitted and inherit the organization value. + - `"web_search"` - - `org_limit: number or null` + - `limits: array of object` - The organization-level value for the same limiter type, for reference. `null` when the organization has no limit configured for this limiter type. + The limiter values overridden for this group in this workspace. Limiter types without a workspace override are omitted and inherit the organization value. - - `type: string` + - `org_limit: number or null` - The limiter type (for example, `requests_per_minute` or `input_tokens_per_minute`). + The organization-level value for the same limiter type, for reference. `null` when the organization has no limit configured for this limiter type. - - `value: number` + - `type: string` - The workspace-level override value for this limiter type. + The limiter type (for example, `requests_per_minute` or `input_tokens_per_minute`). - - `models: array of string or null` + - `value: number` - Model names this entry's limits apply to, including aliases. `null` when `group_type` is not `"model_group"`. + The workspace-level override value for this limiter type. - - `rate_limit_id: string` + - `models: array of string or null` - The `id` of the RateLimit group this override applies to. + Model names this entry's limits apply to, including aliases. `null` when `group_type` is not `"model_group"`. - - `type: "workspace_rate_limit"` + - `rate_limit_id: string` - Object type. Always `workspace_rate_limit` for workspace rate-limit entries. + The `id` of the RateLimit group this override applies to. - default: workspace_rate_limit + - `type: "workspace_rate_limit"` - - `workspace_id: string` + Object type. Always `workspace_rate_limit` for workspace rate-limit entries. - ID of the Workspace this override applies to. + default: workspace_rate_limit - - `next_page: string or null` + - `workspace_id: string` - Token to provide in as `page` in the subsequent request to retrieve the next page of data. + ID of the Workspace this override applies to. diff --git a/content/en/api/admin/workspaces/rate_limits/list.md b/content/en/api/admin/workspaces/rate_limits/list.md index 06b007845..20436c78e 100644 --- a/content/en/api/admin/workspaces/rate_limits/list.md +++ b/content/en/api/admin/workspaces/rate_limits/list.md @@ -8,6 +8,10 @@ Returns only the groups and limiter types that have a workspace-level override. Groups without overrides inherit the organization limits and are not listed; use `GET /v1/organizations/rate_limits` to see those. +When `limit` is omitted, every matching entry is returned in a single +page; when `limit` truncates the result, follow `next_page` to fetch +the remaining entries. + ## Path parameters - `workspace_id: string` @@ -32,6 +36,14 @@ are not listed; use `GET /v1/organizations/rate_limits` to see those. - `"web_search"` +- `limit: optional number` + + Maximum number of items to return per page. Ranges from `1` to `1000`. + + When omitted, every remaining entry is returned in a single page and `next_page` is `null`. + + maximum: 1000, minimum: 1 + - `page: optional string` Opaque cursor from a previous response's `next_page`. @@ -94,14 +106,14 @@ are not listed; use `GET /v1/organizations/rate_limits` to see those. - `next_page: string or null` - Token to provide in as `page` in the subsequent request to retrieve the next page of data. + Opaque cursor for the next page of results, or `null` when no entries remain beyond this response. ## Example ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/rate_limits \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/workspaces/retrieve.md b/content/en/api/admin/workspaces/retrieve.md index a07add636..4f219cfab 100644 --- a/content/en/api/admin/workspaces/retrieve.md +++ b/content/en/api/admin/workspaces/retrieve.md @@ -30,8 +30,13 @@ Get Workspace customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -68,10 +73,14 @@ Get Workspace ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -94,7 +103,7 @@ Get Workspace ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/workspaces/service_accounts.md b/content/en/api/admin/workspaces/service_accounts.md index 731211e72..6a3f982f7 100644 --- a/content/en/api/admin/workspaces/service_accounts.md +++ b/content/en/api/admin/workspaces/service_accounts.md @@ -4,6 +4,8 @@ **POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Add a service account to a workspace with the given `workspace_role`. The role determines what the service account can do in the workspace and @@ -13,8 +15,7 @@ through federation. Every service account is already an implicit assigns a chosen role. If the service account is already an explicit member of the workspace, its `workspace_role` is replaced with the value supplied here. Archived workspaces return 400. Archived service -accounts cannot be added and are rejected. Requires an OAuth bearer or -Console session; Admin API keys are not accepted. +accounts cannot be added and are rejected. ### Path parameters @@ -90,7 +91,7 @@ Console session; Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "service_account_id": "service_account_id", "workspace_role": "workspace_admin" @@ -114,6 +115,8 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service **GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a service account's membership in a workspace. Returns the membership record, including the service account's @@ -182,7 +185,7 @@ account returns 404. ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -202,6 +205,8 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service **GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List the service accounts that are members of a workspace. Each entry includes the service account's `workspace_role`. Use `limit` @@ -284,7 +289,7 @@ omitted from the results. ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) @@ -309,6 +314,8 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service **POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Change a service account's role in a workspace. The new `workspace_role` replaces the current one. Only explicit @@ -316,8 +323,7 @@ memberships can be updated; to set a role on the implicit default-workspace membership, add the service account explicitly with `POST /workspaces/{workspace_id}/service_accounts`. Archived workspaces return 400. Archived service accounts cannot be updated and are -rejected. Requires an OAuth bearer or Console session; Admin API keys -are not accepted. +rejected. ### Path parameters @@ -393,7 +399,7 @@ are not accepted. curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_role": "workspace_admin" }' @@ -416,14 +422,15 @@ curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service **DELETE** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Remove a service account from a workspace. Removal is idempotent (returns 200 even if the membership was already removed). A DELETE against the implicit default-workspace membership returns 200 but is a no-op and the membership persists; deleting an explicit default-workspace row reverts to the implicit `workspace_user` -membership. Archived workspaces return 400. Requires an OAuth bearer or -Console session; Admin API keys are not accepted. +membership. Archived workspaces return 400. ### Path parameters @@ -463,7 +470,7 @@ Console session; Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` #### Response (200) diff --git a/content/en/api/admin/workspaces/service_accounts/create.md b/content/en/api/admin/workspaces/service_accounts/create.md index 8e5d1c7c6..5e6468483 100644 --- a/content/en/api/admin/workspaces/service_accounts/create.md +++ b/content/en/api/admin/workspaces/service_accounts/create.md @@ -2,6 +2,8 @@ **POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Add a service account to a workspace with the given `workspace_role`. The role determines what the service account can do in the workspace and @@ -11,8 +13,7 @@ through federation. Every service account is already an implicit assigns a chosen role. If the service account is already an explicit member of the workspace, its `workspace_role` is replaced with the value supplied here. Archived workspaces return 400. Archived service -accounts cannot be added and are rejected. Requires an OAuth bearer or -Console session; Admin API keys are not accepted. +accounts cannot be added and are rejected. ## Path parameters @@ -88,7 +89,7 @@ Console session; Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "service_account_id": "service_account_id", "workspace_role": "workspace_admin" diff --git a/content/en/api/admin/workspaces/service_accounts/delete.md b/content/en/api/admin/workspaces/service_accounts/delete.md index fb3394771..9f5f48910 100644 --- a/content/en/api/admin/workspaces/service_accounts/delete.md +++ b/content/en/api/admin/workspaces/service_accounts/delete.md @@ -2,14 +2,15 @@ **DELETE** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Remove a service account from a workspace. Removal is idempotent (returns 200 even if the membership was already removed). A DELETE against the implicit default-workspace membership returns 200 but is a no-op and the membership persists; deleting an explicit default-workspace row reverts to the implicit `workspace_user` -membership. Archived workspaces return 400. Requires an OAuth bearer or -Console session; Admin API keys are not accepted. +membership. Archived workspaces return 400. ## Path parameters @@ -49,7 +50,7 @@ Console session; Admin API keys are not accepted. curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/workspaces/service_accounts/list.md b/content/en/api/admin/workspaces/service_accounts/list.md index 562c6f421..4c006ac06 100644 --- a/content/en/api/admin/workspaces/service_accounts/list.md +++ b/content/en/api/admin/workspaces/service_accounts/list.md @@ -2,6 +2,8 @@ **GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + List the service accounts that are members of a workspace. Each entry includes the service account's `workspace_role`. Use `limit` @@ -84,7 +86,7 @@ omitted from the results. ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/workspaces/service_accounts/retrieve.md b/content/en/api/admin/workspaces/service_accounts/retrieve.md index 24461329c..9dd5bbd18 100644 --- a/content/en/api/admin/workspaces/service_accounts/retrieve.md +++ b/content/en/api/admin/workspaces/service_accounts/retrieve.md @@ -2,6 +2,8 @@ **GET** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Retrieve a service account's membership in a workspace. Returns the membership record, including the service account's @@ -70,7 +72,7 @@ account returns 404. ```bash curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" ``` ### Response (200) diff --git a/content/en/api/admin/workspaces/service_accounts/update.md b/content/en/api/admin/workspaces/service_accounts/update.md index ee8974474..6f40eeac0 100644 --- a/content/en/api/admin/workspaces/service_accounts/update.md +++ b/content/en/api/admin/workspaces/service_accounts/update.md @@ -2,6 +2,8 @@ **POST** `/v1/organizations/workspaces/{workspace_id}/service_accounts/{service_account_id}` +**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api). + Change a service account's role in a workspace. The new `workspace_role` replaces the current one. Only explicit @@ -9,8 +11,7 @@ memberships can be updated; to set a role on the implicit default-workspace membership, add the service account explicitly with `POST /workspaces/{workspace_id}/service_accounts`. Archived workspaces return 400. Archived service accounts cannot be updated and are -rejected. Requires an OAuth bearer or Console session; Admin API keys -are not accepted. +rejected. ## Path parameters @@ -86,7 +87,7 @@ are not accepted. curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID/service_accounts/$SERVICE_ACCOUNT_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ "workspace_role": "workspace_admin" }' diff --git a/content/en/api/admin/workspaces/update.md b/content/en/api/admin/workspaces/update.md index 5999ee240..4b815e4b9 100644 --- a/content/en/api/admin/workspaces/update.md +++ b/content/en/api/admin/workspaces/update.md @@ -34,15 +34,25 @@ Update Workspace - `"us"` +- `display_color: optional string` + + Hex color code representing the Workspace in the Anthropic Console. + + maxLength: 7, pattern: ^#[0-9A-Fa-f]{6}$ + - `external_key_id: optional string` ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: optional string` @@ -74,8 +84,13 @@ Update Workspace customer-managed encryption key (CMEK) on AWS, reference this value in your KMS key-policy condition so the key is scoped to this compartment. On GCP and Azure, Anthropic enforces the compartment binding automatically; you do not - need to reference this value in your key configuration. See the CMEK integration guide for the - required key configuration, including the value used during key validation. + need to reference this value in your key configuration. See the CMEK + integration guide for the required key configuration; unless your organization + is on Claude Platform on AWS, it includes a separate value used during key + validation. On Claude Platform on AWS there is no separate validation value: + the key is validated against this Workspace's own value when it is attached, so + if your key policy uses the compartment condition, add this value to it before + attaching the key. - `created_at: string` @@ -112,10 +127,14 @@ Update Workspace ID of the customer-managed encryption key (CMEK) configuration to use for this Workspace. Setting this field requires CMEK to be enabled for your organization. When set, data stored for this Workspace is encrypted with the - referenced key. Create key configurations with the External Keys API. This - field is write-once: once a key is attached to a Workspace it cannot be - detached or replaced. To rotate key material, rotate the underlying key on - your cloud KMS; the `external_key_id` stays the same. + referenced key. Create key configurations with the External Keys API. On + Claude Platform on AWS the value is the AWS KMS key ARN, and the key must be a + single-Region key in the same AWS account and Region as the Workspace. On that + platform the key is validated against this Workspace when it is attached, so a + key-policy problem is reported as an error on this request. This field is write-once: + once a key is attached to a Workspace it cannot be detached or replaced. To + rotate key material, rotate the underlying key on your cloud KMS; the + `external_key_id` stays the same. - `name: string` @@ -139,8 +158,9 @@ Update Workspace curl https://api.anthropic.com/v1/organizations/workspaces/$WORKSPACE_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \ - -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \ + -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \ -d '{ + "display_color": "#6C5BB9", "external_key_id": "ekey_01SDCCSbTxrXDpWc1phhtcfK", "tags": { "env": "prod", diff --git a/content/en/cli-sdks-libraries/cli/apply.md b/content/en/cli-sdks-libraries/cli/apply.md new file mode 100644 index 000000000..ef681eb75 --- /dev/null +++ b/content/en/cli-sdks-libraries/cli/apply.md @@ -0,0 +1,259 @@ +--- +title: Manage resources as code with ant apply +url: https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply +description: Declare agents, environments, skills, memory stores, and deployments as files in your repository and keep the API's resources in sync with them using ant apply. +--- + +`ant apply` creates and updates Claude API resources from files: agents, environments, skills, memory stores, and deployments. They live in your repository and change through the same review as your code. You describe each resource in a file, run `ant apply`, and approve the plan it shows. Then you commit the `claude-lock.json` it writes, so the next run updates the same resources instead of creating new ones. + +To install and authenticate the CLI, see the [CLI quickstart](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/quickstart). `ant apply` requires CLI version 1.30.0 or later. + +## Apply your first agent + +Write the agent as a Markdown file under `agents/` and apply it: + + + ```bash CLI + ant apply agents/summarizer.md + ``` + + + ```markdown + --- + name: Summarizer + model: claude-opus-5 + tools: + - type: agent_toolset_20260401 + --- + + You are a helpful assistant that writes concise summaries. + ``` + + + +The frontmatter holds the agent's configuration (the fields from [Define your agent](https://platform.claude.com/docs/en/managed-agents/agent-setup)) and the body is its system prompt. `ant apply` [infers](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/apply#kind-inference) that the file is an agent from its path, here the `agents/` directory. + +In an interactive terminal, `ant apply` prints the plan and waits for your approval: + +```text Output wrap +First apply ./claude-lock.json does not exist yet and will be created + +Resources will be created with + credentials API key (--api-key / ANTHROPIC_API_KEY) + host api.anthropic.com + organization 1b0c2a4d-6c1f-4f0e-9a57-2e8d1c3b4a5f + workspace wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ + +Preview ./claude-lock.json (new) + +± Name Plan ++ ./agents/summarizer.md create + +Resources + 1 to create + +Apply these changes? (y)es / (n)o / (d)etails y + +Apply ./claude-lock.json + +± Name Status ++ ./agents/summarizer.md created agent_011CYm1BLqPXpQRk5khsSXrs + +Resources + 1 created + +State written to ./claude-lock.json +``` + +Answer `d` to see details first: the fields of each new resource, or a field-by-field diff of each update. `--dry-run` prints that detailed plan and exits without changing anything. + +To change the agent, edit the file and run `ant apply` again. The plan then shows an update instead of a create. + +## Commit claude-lock.json + +The first `ant apply` writes `claude-lock.json`, the lockfile, in the directory you run it from, so run it from the repository root. It records the ID of the resource each file created and the organization and workspace the resources live in: + +```json claude-lock.json +{ + "version": 1, + "origin": { + "base_url": "https://api.anthropic.com", + "organization_id": "1b0c2a4d-6c1f-4f0e-9a57-2e8d1c3b4a5f", + "workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" + }, + "resources": { + "./agents/summarizer.md": { + "kind": "agent", + "id": "agent_011CYm1BLqPXpQRk5khsSXrs", + "version": "1", + "hash": "d23251c8d99b3613a64f3f8d87f5fad4", + "remote_hash": "1b771bee5bdbf600a5ad972fdac32d94" + } + } +} +``` + +Commit it with your files. It's how the next run, on your machine or in CI, finds these resources instead of creating them again, and it's where you read an agent's ID to [start a session](https://platform.claude.com/docs/en/managed-agents/sessions). The two hashes fingerprint what was last sent and what the API returned. That's how a later run notices an edited file, or a resource changed outside these files. + +## Grow it into a project + +You can declaratively define the other resources as files as well. A file holds the request body you would send to that kind's create endpoint: + +* An [environment](https://platform.claude.com/docs/en/managed-agents/environments) is a YAML file in `environments/`. +* A [memory store](https://platform.claude.com/docs/en/managed-agents/memory) is a YAML file in `memory_stores/`. +* A [deployment](https://platform.claude.com/docs/en/managed-agents/scheduled-deployments) is a Markdown file in `deployments/`: the frontmatter is the request body and the prose becomes the message that starts each session. +* A [skill](https://platform.claude.com/docs/en/managed-agents/skills) is a directory with a `SKILL.md` at its root, conventionally under `skills/`, uploaded as one bundle. + +Any resource except a skill can be written as YAML, JSON, or Markdown. In Markdown, the frontmatter is the body and the prose fills the kind's text field: an agent's `system`, an environment's or memory store's `description`, a deployment's first message. + +Resources refer to each other by path. Wherever the API expects another resource's ID, write the relative path to that resource's file instead. In this project, the reviewer agent lists `../skills/pr-summary` under `skills`, the lead agent lists `./reviewer.md` in its roster, and the deployment names its agent, environment, and memory store by path. `ant apply` creates them in dependency order and fills in the real IDs. Apply the whole directory: + + + ```bash CLI + ant apply . + ``` + + + ```markdown + --- + name: Code reviewer + model: claude-opus-5 + tools: + - type: agent_toolset_20260401 + skills: + - ../skills/pr-summary + --- + + You review pull requests for correctness, security, and readability. + ``` + + + + ```markdown + --- + name: Engineering lead + model: claude-opus-5 + multiagent: + type: coordinator + agents: + - ./reviewer.md + --- + + You coordinate engineering work. Delegate code review to the reviewer. + ``` + + + + ```markdown + --- + name: pr-summary + description: Summarize a pull request's changes and risks in the team's review format. + --- + + # PR summary + + List what changed, why, and anything a reviewer should look at closely, in three short sections. + ``` + + + + ```yaml + name: review-env + description: Cloud container with unrestricted networking for review sessions. + config: + type: cloud + networking: + type: unrestricted + ``` + + + + ```yaml + name: Review notes + description: Recurring issues and house-style decisions the reviewer has recorded between runs. + ``` + + + + ```markdown + --- + name: Nightly review + agent: ../agents/reviewer.md # the API's agent field: sent as {type: agent, id, version} + environment_id: ../environments/cloud.yaml # sent as the environment's ID + resources: + - path: ../memory_stores/review-notes.yaml + access: read_write + schedule: + type: cron + expression: "0 3 * * *" + timezone: America/Los_Angeles + --- + + Review any open pull requests. Start with the oldest. + ``` + + + +`claude-lock.json` then has an entry for every file in the project. + +Relative paths are how these files point at each other. `ant apply` pins agent and skill references to the version it just applied, so editing `reviewer.md` or the skill updates everything that references them in the same run. A path also works inside an object, as in the deployment's `resources` entry, where the other keys such as `access` are kept. + +To point at a resource these files don't manage, write its ID (`agent_...`, `skill_...`) instead. Anything else, such as `{type: anthropic, skill_id: xlsx}`, is sent to the API as written. A skill reference can also be a GitHub URL of the form `https://github.com///tree//`, for example a directory of Anthropic's open-source [skills repository](https://github.com/anthropics/skills): `ant apply` downloads and uploads that directory, pinned to the resolved commit until you run with `--upgrade` (set `GITHUB_TOKEN` for a private repository). + +### How ant apply infers a file's kind + +When `ant apply` walks a directory, it determines each file's kind from the first of these that matches: + +1. A top-level `type` field in the file. +2. The directory the file is directly in: `agents/`, `environments/`, `memory_stores/`, or `deployments/`. +3. A file name that starts with the kind, such as `environment_staging.md`. + +It skips files that match none of these, such as READMEs and CI configuration, unless you name them on the command line. A named Markdown file that matches none is treated as an agent, and a named YAML or JSON file that matches none is an error. + +## Edit and reapply + +Running `ant apply` with no arguments reconciles every file the lockfile tracks. At a terminal, it also lists untracked resource files under the lockfile's directory and offers to add them. Deleting a field from a file clears it on the resource if the API allows that field to be cleared. A field you never set, or one the API can't clear, keeps its current value. + +If a resource was edited, archived, or deleted outside these files (in the Claude Console, for example), the plan ends with `This plan cannot be applied:` and the reason. The command then exits with `refusing to apply`. Pass `--force` to overwrite the edit or create a replacement. + +Deleting a file leaves its resource in place with a warning, and `--prune` removes it (archiving it, or deleting it for a skill). Renaming a file therefore declares a new resource and leaves the old one in place until you prune. + +`ant apply` can't adopt a resource you created in the Console or with `ant beta:agents create`. Only what's in the lockfile is managed, and applying a file that describes an existing agent creates a second one. If you downloaded your agent from the Console with **Export as code**, the download includes its own `claude-lock.json`, so applying it updates the resources you built there. + +## Run ant apply in CI + +Without a terminal, `ant apply` prints the plan and stops with `cannot ask for confirmation without a terminal; re-run with --yes to apply, or --dry-run to see the plan only`. Set up CI as follows: + +* Run `ant apply --yes .` on your default branch after merge, naming the project directory. A bare `ant apply --yes` reconciles only files the lockfile already tracks and skips a newly added one. +* On pull requests, run `ant apply --dry-run .` to print the plan for reviewers. It's informational only and exits 0 even when the plan is blocked. +* Commit the updated `claude-lock.json` at the end of the job, even when the apply step failed partway, because a partial apply still records what it created. +* Run one apply at a time, because nothing locks the lockfile. +* Authenticate with [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation) rather than a stored API key, as an identity that reaches the organization and workspace recorded in `claude-lock.json`. `ant apply` refuses credentials that resolve to any other organization or workspace. + +For a complete GitHub Actions workflow, see the [CI example in the CLI README](https://github.com/anthropics/anthropic-cli#in-ci). + +## Flags + +| Flag | Effect | +| -------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `--dry-run` | Print the plan and exit without applying or writing the lockfile. Exits 0 even when the plan is blocked. | +| `--yes` | Apply without asking for confirmation. Required when there's no terminal. | +| `--force` | Apply even where a resource was changed, archived, or deleted outside these files. | +| `--prune` | Remove resources that are in the lockfile but no longer declared in a file. | +| `--upgrade` | Re-resolve skills referenced by GitHub URL, which otherwise stay pinned to the commit recorded in the lockfile. | +| `--lock-file ` | Use this lockfile instead of searching upward from the current directory. Keep one for each organization or workspace: `ant apply` refuses a lockfile whose organization or workspace doesn't match your credentials. | +| `--verbose`, `-v` | Show unchanged resources and full field values in the plan. | + +## Next steps + + + + Run the agents you applied, from the CLI or an SDK + + + + Deployment fields, run history, and pausing + + + + Scripting patterns and use from Claude Code + + diff --git a/content/en/cli-sdks-libraries/cli/quickstart.md b/content/en/cli-sdks-libraries/cli/quickstart.md index 1afb4bd64..ef2424f43 100644 --- a/content/en/cli-sdks-libraries/cli/quickstart.md +++ b/content/en/cli-sdks-libraries/cli/quickstart.md @@ -29,7 +29,7 @@ Compared to `curl`, `ant` builds request bodies from typed flags or piped YAML i For Linux environments, download the release binary directly. ```bash - VERSION=1.29.0 + VERSION=1.30.0 OS=$(uname -s | tr '[:upper:]' '[:lower:]') case $(uname -m) in x86_64) ARCH=amd64 ;; diff --git a/content/en/cli-sdks-libraries/cli/scripting.md b/content/en/cli-sdks-libraries/cli/scripting.md index 8364f9523..e19ab4f2d 100644 --- a/content/en/cli-sdks-libraries/cli/scripting.md +++ b/content/en/cli-sdks-libraries/cli/scripting.md @@ -1,7 +1,7 @@ --- title: CLI scripting and automation url: https://platform.claude.com/docs/en/cli-sdks-libraries/cli/scripting -description: Version-control API resources as YAML, chain ant CLI commands in scripts, operate on resources from Claude Code, and authenticate curl calls with CLI credentials. +description: Version-control API resources as files with ant apply, chain ant CLI commands in scripts, operate on resources from Claude Code, and authenticate curl calls with CLI credentials. --- This page covers task-oriented workflows built on the `ant` CLI. For the underlying flags and output options, see [Using the CLI](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/using). diff --git a/content/en/docs/claude-code/accessibility.md b/content/en/docs/claude-code/accessibility.md index cff8c341f..a8c2dabf5 100644 --- a/content/en/docs/claude-code/accessibility.md +++ b/content/en/docs/claude-code/accessibility.md @@ -82,7 +82,7 @@ As you type at the end of the input line, or press `Backspace` there, Claude Cod When you delete a word or a line with one of the [text editing shortcuts](/docs/en/interactive-mode#text-editing), Claude Code announces the deleted text: -* Deleting a word with `Ctrl+W`, `Option+Delete` on macOS, or `Ctrl+Backspace` on Windows +* Deleting words with `Ctrl+W` or `Alt+D`, or with `Option+Delete` on macOS or `Ctrl+Backspace` on Windows * Deleting to the start of the line with `Ctrl+U` or `Cmd+Backspace` * Deleting to the end of the line with `Ctrl+K` diff --git a/content/en/docs/claude-code/agent-sdk/permissions.md b/content/en/docs/claude-code/agent-sdk/permissions.md index a703c0978..63447e90a 100644 --- a/content/en/docs/claude-code/agent-sdk/permissions.md +++ b/content/en/docs/claude-code/agent-sdk/permissions.md @@ -39,6 +39,8 @@ When Claude requests a tool, the SDK checks permissions in this order: If not resolved by any of the above, call your [`canUseTool` callback](/docs/en/agent-sdk/user-input) for a decision. In `dontAsk` mode, this step is skipped and the tool is denied. + + In the TypeScript SDK, if you set [`permissionPrompts: 'none'`](/docs/en/agent-sdk/typescript#options), your callback isn't called at this step. A [`PermissionRequest` hook](/docs/en/hooks#permissionrequest) still gets a chance to decide, and if it doesn't, Claude Code denies the call. The option requires Claude Code v2.1.259 or later. diff --git a/content/en/docs/claude-code/agent-sdk/typescript.md b/content/en/docs/claude-code/agent-sdk/typescript.md index 62c0fdf01..000120d4a 100644 --- a/content/en/docs/claude-code/agent-sdk/typescript.md +++ b/content/en/docs/claude-code/agent-sdk/typescript.md @@ -451,6 +451,7 @@ Configuration object for the `query()` function. | `pathToClaudeCodeExecutable` | `string` | Auto-resolved from bundled native binary | Path to Claude Code executable. Only needed if optional dependencies were skipped during install or your platform isn't in the supported set | | `permissionMode` | [`PermissionMode`](#permissionmode) | `'default'` | Permission mode for the session | | `permissionPromptToolName` | `string` | `undefined` | MCP tool name for permission prompts | +| `permissionPrompts` | `'host' \| 'none'` | `'host'` | Who answers permission prompts: `'host'` routes them to your [`canUseTool`](#canusetool) callback or the `permissionPromptToolName` tool, and `'none'` [denies the calls that would have prompted](/docs/en/agent-sdk/permissions#how-permissions-are-evaluated). Requires Claude Code v2.1.259 or later | | `persistSession` | `boolean` | `true` | When `false`, disables session persistence to disk. Sessions cannot be resumed later | | `planModeInstructions` | `string` | `undefined` | Custom workflow instructions for plan mode. When `permissionMode` is `'plan'`, this string replaces the default plan-mode workflow body. The CLI still wraps it with the read-only enforcement preamble and the ExitPlanMode protocol footer | | `plugins` | [`SdkPluginConfig`](#sdkpluginconfig)`[]` | `[]` | Load custom plugins from local paths. See [Plugins](/docs/en/agent-sdk/plugins) for details | @@ -556,7 +557,7 @@ interface Query extends AsyncGenerator { | Method | Description | | :------------------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `interrupt()` | Interrupts the query. Only available in streaming input mode. When the CLI advertises the `interrupt_receipt_v1` capability in [`SDKSystemMessage.capabilities`](#sdksystemmessage), resolves with an [`SDKControlInterruptResponse`](#sdkcontrolinterruptresponse) listing the queued messages that survive the interrupt. Resolves `undefined` on CLIs before v2.1.205 | +| `interrupt()` | Interrupts the query. Only available in streaming input mode. When the CLI advertises the `interrupt_receipt_v1` capability in [`SDKSystemMessage.capabilities`](#sdksystemmessage), resolves with an [`SDKControlInterruptResponse`](#sdkcontrolinterruptresponse) listing the messages that were pending when the interrupt arrived. Resolves `undefined` on CLIs before v2.1.205 | | `rewindFiles(userMessageId, options?)` | Restores files to their state at the specified user message. Pass `{ dryRun: true }` to preview changes. Requires `enableFileCheckpointing: true`. See [File checkpointing](/docs/en/agent-sdk/file-checkpointing) | | `setPermissionMode()` | Changes the permission mode (only available in streaming input mode) | | `setModel()` | Changes the model (only available in streaming input mode). Passing `undefined` or the string `"default"` resets to the session default model | @@ -680,7 +681,9 @@ type SDKControlInterruptResponse = { }; ``` -`still_queued` lists the UUIDs of user messages that survive the interrupt: messages still in the queue, plus any messages Claude Code had already taken off the queue for the next turn before the interrupt arrived. Claude Code processes the listed messages after the interrupt unless you cancel them first, and can merge several into one turn. Use the receipt to decide whether to resend anything. Resending a message that is already listed delivers it to Claude twice. +`still_queued` lists the UUIDs of the user messages that were pending when the interrupt arrived: messages still in the queue, plus any messages Claude Code had already taken off the queue for the next turn. Once the session's first turn has started, Claude Code processes the listed messages after the interrupt unless you cancel them first, and can merge several into one turn. If you interrupt before the first turn starts, Claude Code aborts that turn as soon as it starts, and the listed messages in that turn get no response. + +Use the receipt to decide whether to resend anything. A listed message that you don't cancel enters the conversation whether or not it gets a response, so resending it delivers it to Claude twice. Interpret the list with these caveats: @@ -1183,6 +1186,7 @@ type SDKAssistantMessage = { timestamp?: string; context_usage?: SDKContextUsage; user_message_uuid?: string; + user_message_uuids?: string[]; }; ``` @@ -1192,7 +1196,7 @@ The `message` field is a [`BetaMessage`](https://platform.claude.com/docs/en/api `aborted` is `true` when an interrupt or abort truncated the assistant message before the stream completed: the message has no `stop_reason` and the content may end mid-word. The field is absent on normally completed messages. It requires Agent SDK v0.3.214 or later. -Claude Code sets `user_message_uuid` on the turn's first assistant message, under the conditions in [`user_message_uuid`](#user_message_uuid). +Claude Code sets `user_message_uuid` and `user_message_uuids` on the turn's first assistant message, under the conditions in [`user_message_uuid`](#user_message_uuid). `timestamp` is the ISO 8601 time when the message's content finished generating on the process that produced it. The value comes from that machine's clock, so use it for display only and don't order messages by it. One API turn can produce several assistant messages that share a `message.id`, each with its own `timestamp`. When the field is absent, fall back to the time you received the message. @@ -1265,7 +1269,12 @@ type SDKResultMessage = ttft_ms?: number; ttft_stream_ms?: number; user_message_uuid?: string; + user_message_uuids?: string[]; request_sent_wall_ms?: number; + first_content_frame_ms?: number; + first_stream_post_ms?: number; + first_stream_post_ack_ms?: number; + first_stream_post_wall_ms?: number; total_cost_usd: number; usage: NonNullableUsage; modelUsage: { [modelName: string]: ModelUsage }; @@ -1299,6 +1308,7 @@ type SDKResultMessage = queued_turn_count?: number; errors: string[]; user_message_uuid?: string; + user_message_uuids?: string[]; terminal_reason?: TerminalReason; fast_mode_state?: FastModeState; fast_mode_disabled_reason?: FastModeDisabledReason; @@ -1312,7 +1322,10 @@ Several fields on the result carry diagnostic detail beyond `subtype`: * `ttft_ms`: time to first token in milliseconds, measured when the first complete assistant message arrives. Present on the success arm only. * `ttft_stream_ms`: time in milliseconds until the first `message_start` stream event, when the response stream opens. Lower than `ttft_ms`; the gap between the two is time spent streaming the first message. Present on the success arm only. * `user_message_uuid`: the `uuid` of the message you sent that started this turn. See [`user_message_uuid`](#user_message_uuid) for which results carry it. +* `user_message_uuids`: the `uuid`s of every message you sent that Claude Code answered in this turn. See [`user_message_uuids`](#user_message_uuids). * `request_sent_wall_ms`: epoch milliseconds at which Claude Code dispatched the API request, for joins against server-side timestamps. Present on the success arm only, together with `user_message_uuid`, when `is_error` is false. +* `first_content_frame_ms`: time in milliseconds until the first `content_block_start` or `content_block_delta` stream event, counting thinking blocks as content. Present on the success arm only, when `is_error` is false. Requires Agent SDK v0.3.260 or later. +* `first_stream_post_ms`, `first_stream_post_ack_ms`, `first_stream_post_wall_ms`: timings for uploading the turn's first stream event. Claude Code records them only in sessions it streams to claude.ai, such as [cloud sessions](/docs/en/claude-code-on-the-web), and the results `query()` yields don't carry them. Requires Agent SDK v0.3.260 or later. * `usage`: main agent loop only. Excludes subagent and auxiliary model calls, and is per-turn in streaming-input sessions. Prefer `modelUsage` for token/cost accounting. * `modelUsage`: per-model totals for every model call made through the query pipeline during this `query()` call, including the main loop, subagents, and internal calls such as compaction and Workflow agents. Helper calls outside that pipeline, such as the permission classifier and token-counting requests, are excluded. In streaming-input sessions the totals are cumulative across turns, so read the latest result rather than summing across results. See [Track costs in streaming input mode](/docs/en/agent-sdk/cost-tracking#track-costs-in-streaming-input-mode) for resets and [Recover totals after a session crash](/docs/en/agent-sdk/cost-tracking#recover-totals-after-a-session-crash) for zeroed results. * `total_cost_usd`: cumulative estimated cost in USD for this `query()` call, covering the same calls as `modelUsage` and reset at the same points. It is an estimate, not a billing statement. See [Track cost and usage](/docs/en/agent-sdk/cost-tracking) for accuracy caveats. @@ -1346,17 +1359,30 @@ When a `PreToolUse` hook returns `permissionDecision: "defer"`, the result has ` #### `user_message_uuid` -The `uuid` of the [`SDKUserMessage`](#sdkusermessage) that started the turn, echoed so you can match Claude Code's reply to the message you sent. Claude Code echoes it only if you set `uuid` on that message. The field is optional on `SDKUserMessage`, and a string prompt passed to `query()` carries none. When you set it, Claude Code echoes it on two kinds of frame: +The `uuid` of the [`SDKUserMessage`](#sdkusermessage) that started the turn, echoed so you can match Claude Code's reply to the message you sent. Claude Code echoes it only if you set `uuid` on that message. The field is optional on `SDKUserMessage`, and a string prompt passed to `query()` carries none. + +When you send several messages close together, Claude Code can merge them into one turn. The field then carries only the last message's `uuid`. To match the reply to any of the merged messages, use [`user_message_uuids`](#user_message_uuids). + +When you set `uuid`, Claude Code echoes it on three kinds of frame: -* **The result**: on the success arm with `is_error` false, together with `request_sent_wall_ms`, which requires Agent SDK v0.3.216 or later. On an error result that answers a message you sent, Claude Code echoes the field alone, which requires Agent SDK v0.3.246 or later. -* **The turn's first reply**: the first [assistant message](#sdkassistantmessage), or with `includePartialMessages` the first [stream event](#sdkpartialassistantmessage) whose `event.type` isn't `ping`, so you can bind the reply before the result arrives. When a turn streams nothing, Claude Code sets it on the first assistant message instead. One frame per turn carries it. Requires Agent SDK v0.3.246 or later. +* **The result**: on the success arm with `is_error` false, together with `request_sent_wall_ms`, which requires Agent SDK v0.3.216 or later. Claude Code also echoes it on an error result that answers a message you sent, which requires Agent SDK v0.3.246 or later. +* **The turn's first reply**: the first [assistant message](#sdkassistantmessage), or with `includePartialMessages` the first [stream event](#sdkpartialassistantmessage) whose `event.type` isn't `ping`, so you can bind the reply before the result arrives. When a turn streams nothing, Claude Code sets it on the first assistant message instead. One reply frame per turn carries it. Requires Agent SDK v0.3.246 or later. +* **Every [`thinking_tokens`](#sdkthinkingtokensmessage) frame of the turn**: so you can attribute thinking progress to the message you sent without waiting for the turn's first reply. Requires Agent SDK v0.3.260 or later. Claude Code omits the field in these cases: * Later assistant messages and stream events of the same turn * Subagent frames * Synthetic turns, such as scheduled ones -* Results with no single triggering message, such as the zeroed result after a crashed worker process +* Results that answer no message you sent, such as the zeroed result after a crashed worker process + +#### `user_message_uuids` + +The `uuid`s of every message you sent that Claude Code answered in this turn. When you send several messages close together, Claude Code can merge them into one turn, and `user_message_uuid` then names only the last of them. To match the reply to any of the merged messages, look for that message's `uuid` anywhere in this list. Requires Agent SDK v0.3.259 or later. + +Claude Code sets the list together with `user_message_uuid` on the turn's first reply and on the result. For the full set of frames that carry `user_message_uuid`, and the version each requires, see [`user_message_uuid`](#user_message_uuid). The list always contains `user_message_uuid` and holds at most 64 entries. A message you send while the turn is running that Claude Code picks up between tool calls appears only in the result's list. + +When a first reply or result carries `user_message_uuid` without the list, it came from an earlier Claude Code version, so fall back to the single field. #### `queued_turn_count` @@ -1409,10 +1435,10 @@ type SDKSystemMessage = { The `capabilities` array names the protocol behaviors this CLI implements, so you can feature-detect instead of comparing `claude_code_version` strings. It is an open set: ignore values you don't recognize, and check for the specific capability whose behavior you rely on. The field requires Claude Code v2.1.205 or later and is absent on earlier CLIs. -| Capability | Meaning | -| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| `interrupt_receipt_v1` | [`interrupt()`](#query-object) resolves with an [`SDKControlInterruptResponse`](#sdkcontrolinterruptresponse) receipt naming the queued messages that survive the interrupt | -| `interrupt_cancel_queued_v1` | The `interrupt` control request honors `cancel_queued: true`, cancelling the queued messages that would otherwise survive the interrupt and listing them on the receipt's `cancelled` field. See [`SDKControlInterruptResponse`](#sdkcontrolinterruptresponse). Requires Claude Code v2.1.219 or later | +| Capability | Meaning | +| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `interrupt_receipt_v1` | [`interrupt()`](#query-object) resolves with an [`SDKControlInterruptResponse`](#sdkcontrolinterruptresponse) receipt listing the messages that were pending when the interrupt arrived | +| `interrupt_cancel_queued_v1` | The `interrupt` control request honors `cancel_queued: true`, cancelling the messages the receipt would otherwise list under `still_queued` and listing them under `cancelled` instead. See [`SDKControlInterruptResponse`](#sdkcontrolinterruptresponse). Requires Claude Code v2.1.219 or later | ### `SDKPartialAssistantMessage` @@ -1427,10 +1453,11 @@ type SDKPartialAssistantMessage = { session_id: string; ttft_ms?: number; // Time to first token in ms, present only on message_start events user_message_uuid?: string; // Present on at most one stream event per turn + user_message_uuids?: string[]; }; ``` -Claude Code sets `user_message_uuid` on one stream event per turn, under the conditions in [`user_message_uuid`](#user_message_uuid). +Claude Code sets `user_message_uuid` and `user_message_uuids` on one stream event per turn, under the conditions in [`user_message_uuid`](#user_message_uuid). ### `SDKCompactBoundaryMessage` @@ -1500,9 +1527,10 @@ type SDKPluginInstallMessage = { Stream event emitted when the permission system denies a tool call without an interactive prompt. Use it to render the denial in your UI as it happens, rather than only observing the `is_error` tool result that follows. Which denials it reports depends on how the run handles permission prompts: -* **With a [`canUseTool`](#canusetool) callback**: permission prompts go to your callback, and this event reports the denials Claude Code decides on its own without calling it. +* **With a [`canUseTool`](#canusetool) callback** and the default [`permissionPrompts: 'host'`](#options): permission prompts go to your callback, and this event reports the denials Claude Code decides on its own without calling it. * **With neither**: a bare `-p` run, or `query()` that sets neither `canUseTool` nor `permissionPromptToolName`, denies any tool call that would have prompted, and this event reports those denials as well as the ones Claude Code decides on its own. Before v2.1.223, Claude Code didn't emit this event in runs without a callback. -* **With an MCP prompt tool**, set with `permissionPromptToolName` or the [`--permission-prompt-tool`](/docs/en/cli-reference#cli-flags) flag: Claude Code doesn't emit this event at all, not even for the rule denials it decides on its own. +* **With an MCP prompt tool**, set with `permissionPromptToolName` or the [`--permission-prompt-tool`](/docs/en/cli-reference#cli-flags) flag, and the default `permissionPrompts: 'host'`: Claude Code doesn't emit this event at all, not even for the rule denials it decides on its own. +* **With [`permissionPrompts: 'none'`](#options)**: Claude Code denies the calls that would have prompted, even when `canUseTool` or an MCP prompt tool is also set, and this event reports those denials as well as the ones Claude Code decides on its own. Requires Claude Code v2.1.259 or later. In every configuration, this event skips any denial decided on the `PreToolUse` hook path, whether the hook denied the call itself or a deny rule overrode the hook's allow or ask decision. The event is also best-effort: occasionally Claude Code records a denial without emitting this event, so `permission_denials` on the [result message](#sdkresultmessage) is the authoritative record. @@ -4665,7 +4693,7 @@ type SDKStatusMessage = { ### `SDKTaskNotificationMessage` -Notification when a background task completes, fails, or is stopped. Background tasks include `run_in_background` Bash commands, [Monitor](#monitor) watches, and background subagents. `ambient` is `true` for tasks Claude Code starts for its own operation; [`SDKTaskStartedMessage`](#sdktaskstartedmessage) defines the field and its version requirement. +Notification when a background task completes, fails, or is stopped. Background tasks include `run_in_background` Bash commands, [Monitor](#monitor) watches, and background subagents. For the `ambient` field, see [`SDKTaskStartedMessage`](#sdktaskstartedmessage), which defines it and its version requirement. ```typescript theme={null} type SDKTaskNotificationMessage = { @@ -4838,7 +4866,7 @@ type SDKTaskStartedMessage = { }; ``` -`ambient` is `true` for tasks Claude Code starts for its own operation and doesn't display as your work, such as auto-started live-update watchers. Exclude ambient tasks from activity indicators. The field requires Agent SDK v0.3.247 or later. +`ambient` is `true` for tasks that aren't part of the session's work, such as tasks Claude Code runs for its own operation. Live-update watchers are also ambient, including watchers the user asked for. Exclude ambient tasks from activity indicators. The field requires Agent SDK v0.3.247 or later. `ambient` also appears on [`SDKTaskNotificationMessage`](#sdktasknotificationmessage) and on [`SDKBackgroundTasksChangedMessage`](#sdkbackgroundtaskschangedmessage) entries. @@ -4897,7 +4925,9 @@ type SDKTaskUpdatedMessage = { ### `SDKBackgroundTasksChangedMessage` -Emitted whenever the set of live background tasks changes: a task starts, completes, is killed, a foreground agent is backgrounded, or a task's `ambient` flag changes. The `tasks` array is the full live set. Replace any cached set with each payload instead of pairing `task_started` and `task_notification` events, so the next membership change corrects any event you missed. +Emitted whenever the set of live background tasks changes: a task starts, completes, is killed, a foreground agent is backgrounded, or a task's `description` or `ambient` field changes. + +The `tasks` array is the full live set. Replace any cached set with each payload instead of pairing `task_started` and `task_notification` events, so the next membership change corrects any event you missed. Ordering relative to those per-task events is unspecified, so don't correlate the two streams. @@ -4936,6 +4966,7 @@ type SDKThinkingTokensMessage = { subtype: "thinking_tokens"; estimated_tokens: number; estimated_tokens_delta: number; + user_message_uuid?: string; uuid: UUID; session_id: string; }; diff --git a/content/en/docs/claude-code/agent-sdk/user-input.md b/content/en/docs/claude-code/agent-sdk/user-input.md index 52dfd0e8b..b434b767a 100644 --- a/content/en/docs/claude-code/agent-sdk/user-input.md +++ b/content/en/docs/claude-code/agent-sdk/user-input.md @@ -58,7 +58,9 @@ You can also use the [`PermissionRequest` hook](/docs/en/agent-sdk/hooks#availab ## Handle tool approval requests -Once you've passed a `canUseTool` callback in your query options, it fires when Claude wants to use a tool that nothing earlier in the permission flow has approved. Your callback receives three arguments: +Once you've passed a `canUseTool` callback in your query options, it fires when Claude wants to use a tool that nothing earlier in the permission flow has approved. In some configurations, such as `dontAsk` mode, Claude Code doesn't call it; the last step of [How permissions are evaluated](/docs/en/agent-sdk/permissions#how-permissions-are-evaluated) lists them and says what happens to the call instead. + +Your callback receives three arguments: | Argument | Description | | ----------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | diff --git a/content/en/docs/claude-code/changelog.md b/content/en/docs/claude-code/changelog.md index 337350ade..fd584ed62 100644 --- a/content/en/docs/claude-code/changelog.md +++ b/content/en/docs/claude-code/changelog.md @@ -10,6 +10,76 @@ This page is generated from the [CHANGELOG.md on GitHub](https://github.com/anth Run `claude --version` to check your installed version. + + * Added an "Organization policy" line to `/status` and `claude doctor` that says why your organization's policy could not be loaded, such as a proxy not passing the endpoint through + * Added `bashOutputMaxChars` and `taskOutputMaxChars` settings to raise how much command and background-task output Claude receives inline before it is saved to a file, up to 128K characters + * Added `--append-subagent-system-prompt-file` to read the subagent system prompt from a file, for prompts too large to pass on the command line + * Added `/skill-doctor` to show which loaded skills go unused and what they cost in context, so you can prune them + * Fixed typed or pasted characters occasionally landing out of order or being dropped during fast input or key repeat + * Fixed `/add-dir ` printing a false "couldn't be resolved" error when the working directory is on a `/net` automount + * Fixed the Bedrock setup wizard hanging when AWS or an AWS credential helper never responds (it now times out with a clear error), and its model checks failing behind a TLS-inspecting proxy + * Fixed cloud sessions discarding a plugin synced from claude.ai when managed settings force-enable it in `enabledPlugins`, then falling back to a marketplace clone that could fail + * Fixed being unable to delete the character immediately before an inline `[Image #N]` chip in the prompt input + * Fixed resuming a session losing hook output and other context around parallel tool calls, which changed the resumed request + * Fixed Remote Control showing a stale permission mode when a phone, browser, or claude.ai app attaches to a terminal session or after the mode changes in the terminal + * Fixed Remote Control sessions showing as still working (stuck spinner and Stop button) after stopping a turn from a connected phone or browser, or after a local slash command like `/clear` + * Fixed SDK and cloud sessions ignoring a Stop or interrupt sent just after the first prompt, before the turn had started; the turn now stops instead of running to completion + * Fixed Remote Control uploading a session pulled with `/teleport` into the connected session, which appeared appended to the original on phone and web + * Fixed Remote Control's inbound event stream failing behind TLS-inspecting corporate proxies on native Windows + * Fixed Remote Control sessions showing the default effort level on claude.ai when the effort comes from settings + * Fixed `gcpAuthRefresh` opening a browser at startup when the Google credential check was slow, even though the credential was still valid + * Fixed claude.ai connectors staying absent for the whole session when the startup connector fetch timed out — the CLI now retries in the background + * Fixed sustained high CPU usage when a background agent could not be resumed and its wake-up was retried in a tight loop + * Fixed feature flags gated to a newer version occasionally applying to an older Claude Code version running on the same machine + * Fixed `/usage` and the VS Code usage panel dropping a model-specific weekly limit row when the usage endpoint is rate limited or when opened right after startup + * Fixed `claude -p --resume ` adopting a malformed session ID recorded in the transcript; it now resumes under a fresh session ID instead + * Fixed the terminal progress indicator (iTerm2, Ghostty, ConEmu) showing the session as finished while a background workflow or agent was still running + * Fixed a rare layout glitch where a box could render with the wrong height after its container switched between row and column direction + * Fixed Claude apps gateway client IP when a trusted proxy appends a port to `X-Forwarded-For`; with an access list set, an unreadable entry now gets 403 + * Fixed Claude apps gateway telling Claude Desktop to export OpenTelemetry as JSON even when the terminal CLI uses protobuf, so protobuf-only collectors rejected Desktop's data + * Fixed Desktop and web showing a session as busy while it only watches an artifact for updates + * Fixed Claude in Chrome `file_upload` failing with "paths: expected array, received undefined" in local Cowork sessions run from the Claude Desktop app + * Fixed `SendMessage` to an offline Remote Control session on another machine reading as delivered; the result now says delivery is queued until that machine reconnects + * Fixed plugin install hints from CLIs run in background Bash commands: they are now detected, and the raw `` tag no longer leaks into the conversation + * Fixed in-process agent-team teammates re-sending their first-turn tool and skill announcements on the second turn, which changed the request prefix and missed the prompt cache + * Improved the `/model` picker and the VS Code model pill to show a model's name instead of its raw Bedrock, Vertex AI, or LLM gateway ID when Claude Code recognizes it + * Improved startup on Google Vertex AI when `GOOGLE_APPLICATION_CREDENTIALS` is set: API client creation no longer re-runs Google Cloud project discovery or spawns extra `gcloud` processes + * Improved streaming performance: already-rendered blocks are no longer re-checked by layout on each update + * Improved the dangerous-`rm` safety prompt to also catch `rm -rf` on positional parameters and inside double-quoted `sh -c` scripts + * Improved handling when the API sends no response headers: the retry now waits up to `API_TIMEOUT_MS` (10 minutes by default) instead of another 3 minutes, and the messages say what to change + * Changed a Claude apps gateway 403 on the managed settings load (at startup or after `/login`) to say Claude Code may not be enabled for the organization, instead of advising a new sign-in + * Changed machines whose managed settings pin `forceLoginMethod: "gateway"` to ignore a leftover API key or claude.ai login and ask for `/login`; Bedrock, Vertex AI, and Foundry sessions are unaffected + * Changed auto mode to treat a link that packs content into a public diagram renderer's URL as an upload to that site: no longer auto-approved unless you asked for it + * Changed the prompt's word-editing keys to match Bash: Ctrl+W deletes back to whitespace, Alt+F and Alt+D stop at word end, punctuation separates words; `keybindingFlavor` no longer has any effect + * Changed `/context` token counting to use a local estimate when the token-counting API is unavailable, instead of extra small-model requests + * \[VSCode] Added a "Build a custom style" walkthrough to the Output styles menu that writes a custom output style file and lists it right away + * \[VSCode] Added an Add server form and a Remove action to the MCP servers dialog, so MCP servers can be added and removed without leaving the IDE + * \[VSCode] Added a hollow ring in the session list for sessions open in a terminal, another VS Code window, or Claude Desktop, so they no longer look closed + * \[VSCode] Added a fold button to permission and question prompts so the conversation behind them can be read without dismissing them; the space beside the prompt now scrolls the conversation + * \[VSCode] Added "Archive session" to the session list's right-click menu and gave Unarchive its own icon + * \[VSCode] Fixed a session teleported from Claude Code on the web treating a question that was cut off when the cloud session shut down as declined + * \[VSCode] Fixed the session tab's Rename box opening empty for a tab restored with the window; it now starts with the current name + * \[VSCode] Fixed collapsed sections in the session list panel briefly showing expanded each time the panel loaded + * \[VSCode] Fixed Focus view showing a tool call as still running after Claude had moved on, such as while a question waited for your answer + * \[VSCode] Fixed the session list's active-row highlight going stale when an unfocused Claude tab's session ID is corrected + * \[VSCode] Fixed Cmd/Ctrl+Shift+T reopen and deep-link opens placing the Claude tab outside the Claude editor group when a Claude tab has focus + * \[VSCode] Fixed the session tab's "Add to group" putting a session opened from Claude Code on the Web in two groups; it now moves the entry the session list shows + * \[VSCode] Fixed the model picker showing models an organization has since disabled until the window was reloaded twice + * \[VSCode] Fixed a tab opened from the session list jumping back to that session, and a tab opened from a Web session restarting its teleport or staying empty, after VS Code reloads the tab's view + * \[VSCode] Fixed `/btw` side-question history from earlier sessions being overwritten when a question is asked right after a window reload or while a settings file has errors + * \[VSCode] Fixed the pending question card not reappearing after the Claude panel reloads when signed in with a Claude.ai or Console account + * \[VSCode] Fixed claude.ai-only features staying visible in a window's other Claude panels after one panel picked up a third-party provider from a settings file + * \[VSCode] Fixed the sign-in screen appearing despite the Disable Login Prompt setting when Claude Code reports no login or a request fails for lack of one + * \[VSCode] Fixed the next queued permission prompt keeping text typed on the previous prompt and accepting an immediate second click + * \[VSCode] Fixed install-plugin links opening the Claude sidebar without the install dialog in a window where only the session list had been shown + * \[VSCode] Fixed the sidebar usage meter staying empty on a new window until the Account & usage dialog was opened, and a 0% usage limit being left out of the meter + * \[VSCode] Fixed "Start new session in this group" losing the group after New conversation, and a missing unread dot for a session that finished before the sidebar's unread list loaded + * \[VSCode] Fixed the editor tab badge showing unread during a running turn or missing on a tab opened from the session list, and "Add Session Tab to Group" doing nothing for an archived session + * \[VSCode] Fixed "Enable Remote Control for all sessions" so flipping it also applies right away to sessions open in other VS Code windows + * \[VSCode] Fixed the session list's Open filter for sessions continued from claude.ai whose tab was still recorded under the web session, and labeled the filter menu's sections for screen readers + * \[VSCode] Changed the model picker to one flat list of every model, with rows kept for older model spellings listed last + + * Added a diff panel that opens beside the conversation in fullscreen mode and shows your uncommitted changes as Claude edits; toggle it with `/diff` * Added a likely cause for prompt-cache misses (e.g. tool definitions or system prompt changed, idle past the TTL) to `/cost` and the status line's `prompt_cache` field diff --git a/content/en/docs/claude-code/checkpointing.md b/content/en/docs/claude-code/checkpointing.md index 6123f8a67..dee80716a 100644 --- a/content/en/docs/claude-code/checkpointing.md +++ b/content/en/docs/claude-code/checkpointing.md @@ -19,7 +19,7 @@ Claude Code tracks all changes made by its file editing tools: * Every user prompt creates a new checkpoint * Claude Code keeps file snapshots for the 100 most recent checkpoints in a session. Discarding an older checkpoint deletes the snapshot files that no remaining checkpoint references, except each file's first snapshot, which the VS Code extension uses as the baseline for its session diffs. * Claude Code saves checkpoints with the conversation, so you can still run `/rewind` after you resume a session -* Claude Code deletes checkpoints along with sessions after 30 days, following the [retention sweep rules](/docs/en/claude-directory#cleaned-up-automatically); change the period with [`cleanupPeriodDays`](/docs/en/settings-reference#cleanupperioddays) +* Claude Code deletes a session's file snapshots in the [retention sweep](/docs/en/claude-directory#cleaned-up-automatically), by default about 30 days after the session last saved one. Rewinding to a checkpoint whose snapshots are gone can fail with [`No files were restored`](/docs/en/errors#no-files-were-restored). To keep snapshots longer, set [`cleanupPeriodDays`](/docs/en/settings-reference#cleanupperioddays). ### Rewind and summarize diff --git a/content/en/docs/claude-code/claude-directory.md b/content/en/docs/claude-code/claude-directory.md index 64ea834ff..6f0795900 100644 --- a/content/en/docs/claude-code/claude-directory.md +++ b/content/en/docs/claude-code/claude-directory.md @@ -1526,12 +1526,12 @@ Claude Code deletes the files in the paths below once they're older than [`clean | `projects///tool-results/` | Large tool outputs spilled to separate files | | `file-history//` | Pre-edit snapshots of files Claude changed, used for [checkpoint restore](/docs/en/checkpointing). Holds snapshots for the 100 most recent checkpoints; snapshot files that no retained checkpoint references are deleted, except each file's first snapshot | | `plans/` | Plan files written during [plan mode](/docs/en/permission-modes#analyze-before-you-edit-with-plan-mode) | -| `debug/` | Per-session debug logs, written only when you start with `--debug` or run `/debug` | +| `debug/` | Per-session debug logs, written while debug logging is on, such as when you start with [`--debug`](/docs/en/cli-reference#cli-flags) or run `/debug` | | `paste-cache/` | Contents of large pastes | | `image-cache//` | Attached images. On each sweep, Claude Code removes the directories of all other sessions, whatever their age. | | `uploads//` | Files you attach from the web or mobile app, and photos you attach from the mobile app, when messaging a [Remote Control](/docs/en/remote-control) session. An attachment to a [cloud session](/docs/en/claude-code-on-the-web) is saved in that session's own cloud environment instead, not on your machine. | | `session-env/` | Per-session environment metadata | -| `tasks/` | Per-session task lists written by the task tools | +| `tasks/` | Task lists written by the task tools, one directory per list | | `shell-snapshots/` | Aliases, functions, and shell options captured at startup and applied by the [Bash tool](/docs/en/tools-reference#bash-tool-behavior) to each command. Removed on clean exit. The sweep clears any left after a crash. | | `backups/` | Earlier versions of `~/.claude.json`, copied when Claude Code rewrites the file. Claude Code keeps the five newest, plus a copy of any version it couldn't parse. | | `feedback-bundles/` | Redacted transcript archives written by `/feedback` on third-party providers or when no Anthropic credentials are configured, for sending to your Anthropic account team | @@ -1542,7 +1542,7 @@ Claude Code deletes the files in the paths below once they're older than [`clean Session files in `sessions/`, auto memory, and Claude Desktop and Cowork transcripts each follow their own retention rule: * **`sessions/`**: holds one small file per running session, used to detect concurrent sessions and crashes. It isn't part of the age-based sweep: Claude Code removes each file when its session exits and clears crash leftovers on the next launch. -* **Auto memory**: Claude Code excludes a project's [auto memory](/docs/en/memory#auto-memory) directory, `projects//memory/`, from this sweep, and removes the directory itself only after it has been empty for the whole retention period. Before v2.1.228, the sweep treated folders inside the memory directory as session data and could delete old files beneath it. +* **Auto memory**: the sweep doesn't delete the memory files in a project's [auto memory](/docs/en/memory#auto-memory) directory, `projects//memory/`. Claude Code removes that directory only if it has been empty for the whole retention period. Before v2.1.228, the sweep treated folders inside the memory directory as session data and could delete old files beneath it. * **Claude Desktop and Cowork transcripts**: Claude Code keeps the transcript of a session you started or most recently continued in Claude Desktop or Cowork at any age. To give these transcripts an age limit, set [`desktopSessionCleanupPeriodDays`](/docs/en/settings-reference#desktopsessioncleanupperioddays). When [managed settings](/docs/en/managed-settings) set `cleanupPeriodDays`, Claude Code deletes these transcripts after that period instead. Requires Claude Code v2.1.248 or later; earlier versions delete them after `cleanupPeriodDays`. Claude Code skips the sweep entirely in these cases: @@ -1552,17 +1552,23 @@ Claude Code skips the sweep entirely in these cases: ### Kept until you delete them -The retention cleanup sweep doesn't cover the following paths. Claude Code keeps them until you delete them, apart from the two caches whose rows say that logging out deletes them. +The retention cleanup sweep doesn't remove the paths below. Claude Code keeps them until you delete them, apart from the two caches it deletes when you log out. | Path under `~/.claude/` | Contents | | ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `history.jsonl` | Every prompt you've typed, with timestamp and project path. Used for up-arrow recall. | +| `history.jsonl` | Every prompt you've typed, with timestamp and project path. Used for up-arrow recall, `Ctrl+R` history search, and `!` shell-command completion. | | `stats-cache.json` | Aggregated token and cost counts shown by `/usage` | | `remote-settings.json` | Cached copy of [server-managed settings](/docs/en/server-managed-settings) for your organization, or `{}` when your organization has configured none. Only present when the session [fetches them](/docs/en/server-managed-settings#platform-availability). Claude Code checks for updates at startup and hourly during a session. Claude Code deletes it when you log out. | | `cache/changelog.md` | Cached copy of the Claude Code changelog, shown by `/release-notes`. Refreshed in the background. | | `policy-limits.json` | Cached feature policy settings for your organization. Only present for some account types. Refreshed automatically. Claude Code deletes it when you log out. | -Other small cache and lock files appear depending on which features you use and are safe to delete. + + +Other files appear depending on which features you use. Caches and lock files are safe to delete. Keep these state files: + +* `.credentials.json`: your [login credentials](/docs/en/authentication#credential-management) +* `agent-memory/`: [subagent memory](/docs/en/sub-agents#enable-persistent-memory) +* `jobs/` and `daemon/`: [background session](/docs/en/agent-view#where-state-is-stored) state ### Plaintext storage @@ -1629,24 +1635,25 @@ Pass `--all` instead of a path to purge state for every project at once, which d The command leaves `shell-snapshots/` and `backups/` alone because those are not project-scoped, and warns about them in the plan output. -You can also delete any of the application-data paths above by hand. New sessions are unaffected. The table below shows what you lose for past sessions. - -| Delete | You lose | -| ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------- | -| `~/.claude/projects/` | Resume, continue, and rewind for past sessions, and auto memory for every project | -| `~/.claude/history.jsonl` | Up-arrow prompt recall | -| `~/.claude/paste-cache/` | Pasted text in recalled prompts; see [paste large content](/docs/en/terminal-config#paste-large-content) | -| `~/.claude/uploads/` | Attachments that past [Remote Control](/docs/en/remote-control) sessions refer to by path | -| `~/.claude/file-history/` | Checkpoint restore for past sessions | -| `~/.claude/stats-cache.json` | Historical totals shown by `/usage` | -| `~/.claude/usage-data/` | Past [`/insights`](/docs/en/costs#analyze-your-usage-patterns) reports and the cached analysis data used to build them | -| `~/.claude/feedback-bundles/` | Feedback and bug-report archives you haven't yet sent to your Anthropic account team | -| `~/.claude/feedback/drafts/` | [Claude-drafted feedback](/docs/en/tools-reference#sendfeedback-tool-behavior) you haven't sent | -| `~/.claude/remote-settings.json` | Nothing. Re-fetched on next launch. | -| `~/.claude/cache/changelog.md` | Nothing. Refreshed in the background. | -| `~/.claude/policy-limits.json` | Nothing. Refreshed automatically. | -| `~/.claude/debug/`, `~/.claude/plans/`, `~/.claude/image-cache/`, `~/.claude/session-env/`, `~/.claude/tasks/`, `~/.claude/shell-snapshots/`, `~/.claude/backups/` | Nothing user-facing | -| `~/.claude/todos/`, `~/.claude/statsig/`, `~/.claude/logs/` | Nothing. Legacy directories not written by current versions. | +You can also delete any of the application-data paths above by hand, apart from the [state files to keep](#state-files-to-keep). New sessions are unaffected. The table below shows what you lose for past sessions. + +| Delete | You lose | +| ---------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------- | +| `~/.claude/projects/` | Resume, continue, and rewind for past sessions, and auto memory for every project | +| `~/.claude/history.jsonl` | Up-arrow prompt recall, `Ctrl+R` history search, and `!` shell-command completion | +| `~/.claude/paste-cache/` | Pasted text in recalled prompts; see [paste large content](/docs/en/terminal-config#paste-large-content) | +| `~/.claude/uploads/` | Attachments that past [Remote Control](/docs/en/remote-control) sessions refer to by path | +| `~/.claude/file-history/` | Checkpoint restore for past sessions | +| `~/.claude/stats-cache.json` | Historical totals shown by `/usage` | +| `~/.claude/usage-data/` | Past [`/insights`](/docs/en/costs#analyze-your-usage-patterns) reports and the cached analysis data used to build them | +| `~/.claude/feedback-bundles/` | Feedback and bug-report archives you haven't yet sent to your Anthropic account team | +| `~/.claude/feedback/drafts/` | [Claude-drafted feedback](/docs/en/tools-reference#sendfeedback-tool-behavior) you haven't sent | +| `~/.claude/remote-settings.json` | Nothing. Re-fetched on next launch. | +| `~/.claude/cache/changelog.md` | Nothing. Refreshed in the background. | +| `~/.claude/policy-limits.json` | Nothing. Refreshed automatically. | +| `~/.claude/tasks/` | Task lists that a resumed session would pick up | +| `~/.claude/debug/`, `~/.claude/plans/`, `~/.claude/image-cache/`, `~/.claude/session-env/`, `~/.claude/shell-snapshots/`, `~/.claude/backups/` | Nothing user-facing | +| `~/.claude/todos/`, `~/.claude/statsig/`, `~/.claude/logs/` | Nothing. Legacy directories not written by current versions. | Don't delete `~/.claude.json`, `~/.claude/settings.json`, or `~/.claude/plugins/`: those hold your auth, preferences, and installed plugins. diff --git a/content/en/docs/claude-code/cli-reference.md b/content/en/docs/claude-code/cli-reference.md index 55ffe42c6..965e1343d 100644 --- a/content/en/docs/claude-code/cli-reference.md +++ b/content/en/docs/claude-code/cli-reference.md @@ -57,7 +57,7 @@ Customize Claude Code's behavior with these command-line flags. `claude --help` | Flag | Description | Example | | :---------------------------------------------- | :----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :-------------------------------------------------------------------------------------------------- | -| `--add-dir` | Add additional working directories for Claude to read and edit files. Grants file access; most `.claude/` configuration is [not discovered](/docs/en/permissions#additional-directories-grant-file-access-not-configuration) from these directories. Validates each path exists as a directory. To persist these directories across sessions, set [`permissions.additionalDirectories`](/docs/en/settings-reference#permissions-additionaldirectories) in settings | `claude --add-dir ../apps ../lib` | +| `--add-dir` | Add additional working directories for Claude to read and edit files. Grants file access; Claude Code [doesn't discover](/docs/en/permissions#additional-directories-grant-file-access-not-configuration) most `.claude/` configuration from these directories. Validates that each path exists as a directory. You can't add most [network paths](/docs/en/errors#working-directory-is-a-network-path), such as `\\server\share`. To persist these directories across sessions, set [`permissions.additionalDirectories`](/docs/en/settings-reference#permissions-additionaldirectories) in settings | `claude --add-dir ../apps ../lib` | | `--advisor ` | Enable the server-side [advisor tool](/docs/en/advisor) for this session with a model alias, `fable`, `opus`, or `sonnet`, or a full model ID. Takes precedence over the `advisorModel` setting for the session. `fable` requires [Fable access](/docs/en/advisor#choose-an-advisor-model) | `claude --advisor opus` | | `--agent` | Specify an agent for the current session (overrides the `agent` setting) | `claude --agent my-custom-agent` | | `--agents` | Define custom subagents dynamically via JSON. Accepts the [fields listed for CLI-defined subagents](/docs/en/sub-agents#choose-the-subagent-scope). Claude Code validates the JSON at startup and exits on an invalid value; see [`Invalid --agents configuration`](/docs/en/errors#invalid-agents-configuration) for the message and for the flags and environment variable that skip the validation. Validation requires Claude Code v2.1.242 or later | `claude --agents '{"reviewer":{"description":"Reviews code","prompt":"You are a code reviewer"}}'` | diff --git a/content/en/docs/claude-code/cloud-environments.md b/content/en/docs/claude-code/cloud-environments.md index 679d4fd7d..f6b06b7ea 100644 --- a/content/en/docs/claude-code/cloud-environments.md +++ b/content/en/docs/claude-code/cloud-environments.md @@ -208,7 +208,10 @@ registry.example.com Sessions in this environment can now reach `api.example.com`, any subdomain of `internal.example.com`, and `registry.example.com`, and no other domains through the session's network. [GitHub traffic](#github-proxy), [MCP connector traffic](#network-access), and requests to the hosts of the environment's [API credentials](#add-api-credentials), other than the [hosts the agent proxy skips](#requests-that-never-get-the-credential), don't go through this allowlist. A leading `*.` matches every subdomain. To keep the [Trusted domains](#default-allowed-domains) too, check **Also include default list of common package managers**; leave it unchecked to allow only what you list. -If sessions in the environment work with [artifacts](/docs/en/artifacts), include `*.frame.claudeusercontent.com` in your list. Claude Code fetches artifact content from that host. If you leave it out, Claude can't read artifacts in sessions that run in the environment. +If your organization uses [artifacts](/docs/en/artifacts#availability), you don't need `*.frame.claudeusercontent.com` in the list for sessions to read them. When the list leaves that host out, Claude Code reads artifact content through the session's connection to Anthropic instead. Keep the host in an allowlist in two situations: + +* **Sessions in this environment open another organization's public artifacts**: Claude Code fetches those from the host directly, so add it to this list. +* **You're configuring the local CLI or a self-hosted runner**: keep the host in that allowlist. See [network access requirements](/docs/en/network-config#network-access-requirements) and the self-hosted [network requirements](/docs/en/self-hosted-environments-deploy#network-requirements). Each environment has its own allowed-domains list; there's no organization-level allowlist that admins can push to every member's environments. [Server-managed settings](/docs/en/server-managed-settings) still apply inside cloud sessions, but none of them adds domains to the environment's network allowlist. diff --git a/content/en/docs/claude-code/commands.md b/content/en/docs/claude-code/commands.md index 694ebd0fb..ff890a8df 100644 --- a/content/en/docs/claude-code/commands.md +++ b/content/en/docs/claude-code/commands.md @@ -49,7 +49,7 @@ In the table below, `` indicates a required argument and `[arg]` indicates | Command | Purpose | | :-------------------------------------------------------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `/add-dir ` | Add a working directory for file access during the current session. Type a partial path to see matching directory suggestions; press `Tab` to accept one. Most `.claude/` configuration is [not discovered](/docs/en/permissions#additional-directories-grant-file-access-not-configuration) from the added directory. A successful add runs your [`DirectoryAdded` hooks](/docs/en/hooks#directoryadded). When you run it while Claude is responding, Claude Code asks you to confirm the directory right away, and once you confirm, Claude's next tool call in the same turn can access it. Before v2.1.234, Claude Code queued the command until the turn finished | +| `/add-dir ` | Add a working directory for file access during the current session. Type a partial path to see matching directory suggestions; press `Tab` to accept one. Most `.claude/` configuration [isn't discovered](/docs/en/permissions#additional-directories-grant-file-access-not-configuration) from the added directory. You can't add most [network paths](/docs/en/errors#working-directory-is-a-network-path), such as `\\server\share`. After a successful add, your [`DirectoryAdded` hooks](/docs/en/hooks#directoryadded) run. When you run it while Claude is responding, Claude Code asks you to confirm the directory right away, and once you confirm, Claude's next tool call in the same turn can access it. Before v2.1.234, Claude Code queued the command until the turn finished | | `/advisor [model\|off]` | Enable or disable the [advisor tool](/docs/en/advisor), which consults a second model for guidance at key moments during a task. Accepts `fable`, `opus`, `sonnet`, or a full model ID. `fable` requires [Fable access](/docs/en/advisor#choose-an-advisor-model). Without an argument, opens a picker | | `/agents` | As of v2.1.198, running `/agents` prints a reminder to ask Claude to create or manage [subagents](/docs/en/sub-agents), or to edit `.claude/agents/` or `~/.claude/agents/` directly. On v2.1.197 and earlier, opens an interactive interface for creating and managing subagent configurations | | `/artifacts` | List the [artifacts](/docs/en/artifacts#find-an-artifact-again) you own or that are shared with you, then attach one to the session, open it in your browser, or copy its link. Available where [artifacts](/docs/en/artifacts#availability) are. Requires Claude Code v2.1.208 or later; attaching with `Enter` requires v2.1.216 | @@ -136,6 +136,7 @@ In the table below, `` indicates a required argument and `[arg]` indicates | `/setup-bedrock` | Configure [Amazon Bedrock](/docs/en/amazon-bedrock) authentication, region, and model pins through an interactive wizard. [Hidden from the command menu](#how-the-command-menu-matches-what-you-type) until `CLAUDE_CODE_USE_BEDROCK=1` is set; type it in full. First-time Amazon Bedrock users can also access this wizard from the login screen | | `/setup-vertex` | Configure [Google Cloud's Agent Platform](/docs/en/google-vertex-ai) authentication, project, region, and model pins through an interactive wizard. [Hidden from the command menu](#how-the-command-menu-matches-what-you-type) until `CLAUDE_CODE_USE_VERTEX=1` is set; type it in full. First-time Google Cloud's Agent Platform users can also access this wizard from the login screen | | `/simplify [target]` | **[Skill](/docs/en/skills#bundled-skills).** Review the changed code for cleanup opportunities and apply the fixes. Four review [agents](/docs/en/sub-agents) run in parallel, covering reuse of existing helpers, simplification, efficiency, and whether the change is at the right level of abstraction. The review doesn't look for correctness bugs. Use `/code-review` to find bugs. Pass a path or PR reference to review a specific target | +| `/skill-doctor` | Show what each of your [skills](/docs/en/skills) costs in context and how often it gets used, so you can [find skills to turn off](/docs/en/skills#find-unused-skills). Requires Claude Code v2.1.252 or later and [feature-flag fetching](/docs/en/env-vars#features-that-need-feature-flag-fetching) | | `/skills` | List available [skills](/docs/en/skills). Type to filter the list by name, description, or source. Press `t` to sort by token count, `Space` or `Enter` to [cycle a skill's visibility to Claude and the `/` menu](/docs/en/skills#override-skill-visibility-from-settings), and `Esc` to save and close. You can't cycle plugin skills, skills whose frontmatter sets `disable-model-invocation: true`, or skills with a `skillOverrides` entry in managed settings or the `--settings` flag | | `/stats` | Alias for `/usage`. Opens on the Stats tab | | `/status` | Open the Settings interface on the Status tab, showing version, model, account, and connectivity. A `Session kind` row reads `background job · attached` or `background job · unattended` in a [background session](/docs/en/agent-view), depending on whether a terminal is attached, and `interactive` in any other session. Before v2.1.221, `/status` didn't show this row. Works while Claude is responding | diff --git a/content/en/docs/claude-code/costs.md b/content/en/docs/claude-code/costs.md index 4ab3dbb6f..a81ddad89 100644 --- a/content/en/docs/claude-code/costs.md +++ b/content/en/docs/claude-code/costs.md @@ -45,7 +45,7 @@ Prompt cache (main): 14 requests · 91% of input tokens from cache · 2 misses The misses, expected rebuilds, and warm or cold parts of the line mean the following: -* **Misses**: requests that re-processed content the cache already held, with the time of the last miss and how many tokens those requests wrote back to the cache. Claude Code counts a request as a miss when the request re-processed more than 5% and at least 2,000 tokens of what it could have read from cache. [Actions that invalidate the cache](/docs/en/prompt-caching#actions-that-invalidate-the-cache) lists the usual causes. +* **Misses**: requests that re-processed content the cache already held, with the time of the last miss and how many tokens those requests wrote back to the cache. Claude Code counts a request as a miss when the request re-processed more than 5% and at least 2,000 tokens of what it could have read from cache. [Actions that invalidate the cache](/docs/en/prompt-caching#actions-that-invalidate-the-cache) lists the usual causes. When Claude Code can identify a likely cause for the last miss, the line names it too, for example `likely cause: tool definitions changed`. The likely-cause text requires Claude Code v2.1.260 or later. * **Expected rebuilds**: when Claude Code has itself just rewritten the conversation, by [compaction](/docs/en/prompt-caching#compacting-the-conversation) or by clearing old tool results from context, it counts the same kind of miss as an expected rebuild instead. This part appears only after at least one expected rebuild has happened. * **Warm or cold**: whether the cached prefix is still within its [cache lifetime](/docs/en/prompt-caching#cache-lifetime), with the TTL in effect. When the cache is cold, the line shows how long the session has been idle. When no response has reported cache tokens, the line ends with `no prompt caching reported by the API` instead. diff --git a/content/en/docs/claude-code/deep-links.md b/content/en/docs/claude-code/deep-links.md index 311a02681..836808a2e 100644 --- a/content/en/docs/claude-code/deep-links.md +++ b/content/en/docs/claude-code/deep-links.md @@ -53,7 +53,7 @@ Add parameters to control where the session starts and what the prompt box conta | Parameter | Description | | --------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `q` | Text to pre-fill in the prompt box. [URL-encode](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/encodeURIComponent) the value. Use `%0A` for line breaks in multi-line prompts. Maximum 5,000 characters. | -| `cwd` | Absolute path to use as the working directory. Network and UNC paths are rejected, and so are paths that contain invisible or bidirectional control characters. | +| `cwd` | Absolute path to use as the working directory. Network and UNC paths are rejected, and so are paths that contain `..` segments or invisible or bidirectional control characters. | | `repo` | A GitHub `owner/name` slug. Claude Code resolves it to a local clone it has seen before and starts there. If you have no matching clone, the session opens in your home directory instead. | `cwd` and `repo` are [two ways to set the working directory](#choose-between-cwd-and-repo). If you pass both, `cwd` takes precedence and `repo` is ignored, even if the `cwd` path does not exist. diff --git a/content/en/docs/claude-code/discover-plugins.md b/content/en/docs/claude-code/discover-plugins.md index e991bafbc..5e20c05a6 100644 --- a/content/en/docs/claude-code/discover-plugins.md +++ b/content/en/docs/claude-code/discover-plugins.md @@ -149,12 +149,13 @@ Anthropic also maintains a [demo plugins marketplace](https://github.com/anthrop - Run `/plugin` to open the plugin manager. This opens a tabbed interface with four tabs you can cycle through using **Tab**, or **Shift+Tab** to go backward: + Run `/plugin` to open the plugin manager. This opens a tabbed interface you can cycle through using **Tab**, or **Shift+Tab** to go backward: * **Discover**: browse available plugins from all your marketplaces * **Installed**: view and manage your installed plugins * **Marketplaces**: add, remove, or update your added marketplaces * **Errors**: view any plugin loading errors + * **Stats**: see [what each of your skills costs in context and how often it gets used](/docs/en/skills#find-unused-skills), in sessions where `/skill-doctor` is available Go to the **Discover** tab to see plugins from the marketplace you just added. When your administrator has allowlisted the marketplace via the [`pluginSuggestionMarketplaces`](/docs/en/settings-reference#pluginsuggestionmarketplaces) managed setting, plugins marked as relevant to your current working directory are pinned at the top with a **suggested for this directory** label. diff --git a/content/en/docs/claude-code/env-vars.md b/content/en/docs/claude-code/env-vars.md index 4e05d5f01..30e4425f2 100644 --- a/content/en/docs/claude-code/env-vars.md +++ b/content/en/docs/claude-code/env-vars.md @@ -131,360 +131,360 @@ Numeric variables such as timeouts, token budgets, and retry counts accept scien One other variable has its own rule: `FORCE_HYPERLINK` reads a number, so only `0` turns it off. Each variable's row also states its own rule. -| Variable | Purpose | -| :------------------------------------------------------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `ANTHROPIC_API_KEY` | API key sent as `X-Api-Key` header. When set, this key is used instead of your Claude Pro, Max, Team, or Enterprise subscription even if you are logged in. In non-interactive mode (`-p`), the key is always used when present. In interactive mode, you are prompted to approve the key once before it overrides your subscription. To use your subscription instead, run `unset ANTHROPIC_API_KEY` | -| `ANTHROPIC_AUTH_TOKEN` | Custom value for the `Authorization` header (the value you set here will be prefixed with `Bearer `) | -| `ANTHROPIC_AWS_API_KEY` | Workspace API key for [Claude Platform on AWS](/docs/en/claude-platform-on-aws), generated in the AWS Console. Sent as `x-api-key` and takes precedence over AWS SigV4 | -| `ANTHROPIC_AWS_BASE_URL` | Override the [Claude Platform on AWS](/docs/en/claude-platform-on-aws) endpoint URL. Use for custom regions or when routing through an [LLM gateway](/docs/en/llm-gateway). Defaults to `https://aws-external-anthropic.{region}.api.aws`. Claude Code resolves the region with the [same precedence as on Amazon Bedrock](/docs/en/amazon-bedrock#3-configure-claude-code) | -| `ANTHROPIC_AWS_WORKSPACE_ID` | Required for [Claude Platform on AWS](/docs/en/claude-platform-on-aws). Sent on every request as the `anthropic-workspace-id` header | -| `ANTHROPIC_BASE_URL` | Override the API endpoint to route requests through a proxy or gateway. When set to a non-first-party host, [MCP tool search](/docs/en/mcp#scale-with-mcp-tool-search) is disabled by default. Set `ENABLE_TOOL_SEARCH=true` if your proxy forwards `tool_reference` blocks. As of v2.1.196, [Remote Control](/docs/en/remote-control#requirements) is disabled when this points at a host other than `api.anthropic.com`, matching its behavior on Amazon Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry | -| `ANTHROPIC_BEDROCK_BASE_URL` | Override the Amazon Bedrock endpoint URL. Use for custom Amazon Bedrock endpoints or when routing through an [LLM gateway](/docs/en/llm-gateway). See [Amazon Bedrock](/docs/en/amazon-bedrock) | -| `ANTHROPIC_BEDROCK_MANTLE_BASE_URL` | Override the Amazon Bedrock Mantle endpoint URL. See [Mantle endpoint](/docs/en/amazon-bedrock#use-the-mantle-endpoint) | -| `ANTHROPIC_BEDROCK_REGION_PREFIX` | Cross-region inference profile prefix (`us`, `eu`, `apac`, `jp`, `au`, or `global`) Claude Code tries first instead of the one derived from the AWS region. Ignored in AWS GovCloud regions. Requires Claude Code v2.1.224 or later. See [Amazon Bedrock](/docs/en/amazon-bedrock#cross-region-inference-profile-prefixes) | -| `ANTHROPIC_BEDROCK_SERVICE_TIER` | Amazon Bedrock [service tier](https://docs.aws.amazon.com/bedrock/latest/userguide/service-tiers-inference.html) (`default`, `flex`, or `priority`). Sent as the `X-Amzn-Bedrock-Service-Tier` header. See [Amazon Bedrock](/docs/en/amazon-bedrock#service-tiers) | -| `ANTHROPIC_BETAS` | Comma-separated list of additional `anthropic-beta` header values to include in API requests. Claude Code already sends the beta headers it needs; use this to opt into an [Anthropic API beta](https://platform.claude.com/docs/en/api/beta-headers) before Claude Code adds native support. Unlike the [`--betas` flag](/docs/en/cli-reference#cli-flags), which requires API key authentication, this variable works with all auth methods including Claude.ai subscription | -| `ANTHROPIC_CUSTOM_HEADERS` | Custom headers to add to requests (`Name: Value` format, newline-separated for multiple headers). If a name or value contains a character an HTTP header can't carry, such as a curly quote or a zero-width space, the request fails with an error that identifies the pair by position. Requires Claude Code v2.1.227 or later. [Invalid request header value](/docs/en/errors#invalid-request-header-value) lists the exact character set and where the check runs. A value that sets a credential, org or tenant, routing, or API-behavior header, such as `Authorization` or `Host`, counts as a [setting that needs approval](/docs/en/server-managed-settings#environment-variables-and-the-approval-dialog) when server-managed settings deliver it. From project or local settings, such a value follows the [rules for when `env` values apply](/docs/en/settings-reference#when-claude-code-applies-env-values) | -| `ANTHROPIC_CUSTOM_MODEL_OPTION` | Model ID to add as a custom entry in the `/model` picker. Use this to make a non-standard or gateway-specific model selectable without replacing built-in aliases. See [Model configuration](/docs/en/model-config#add-a-custom-model-option) | -| `ANTHROPIC_CUSTOM_MODEL_OPTION_DESCRIPTION` | Display description for the custom model entry in the `/model` picker. Defaults to `Custom model ()` when not set | -| `ANTHROPIC_CUSTOM_MODEL_OPTION_NAME` | Display name for the custom model entry in the `/model` picker. Defaults to the model ID when not set | -| `ANTHROPIC_CUSTOM_MODEL_OPTION_SUPPORTED_CAPABILITIES` | Comma-separated list of [capabilities](/docs/en/model-config#customize-pinned-model-display-and-capabilities) the custom model supports, for example `effort,thinking`. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_DEFAULT_FABLE_MODEL` | Model ID that the `fable` alias resolves to, and the ID Claude Code recognizes as a Fable model for [automatic model fallback](/docs/en/model-config#automatic-model-fallback) on third-party providers. See [Model configuration](/docs/en/model-config#environment-variables) | -| `ANTHROPIC_DEFAULT_FABLE_MODEL_DESCRIPTION` | Display description for the pinned Fable model in the `/model` picker. Defaults to `Custom Fable model` when not set. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_DEFAULT_FABLE_MODEL_NAME` | Display name for the pinned Fable model in the `/model` picker. Defaults to the model ID when not set. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_DEFAULT_FABLE_MODEL_SUPPORTED_CAPABILITIES` | Comma-separated list of [capabilities](/docs/en/model-config#customize-pinned-model-display-and-capabilities) the pinned Fable model supports, for example `effort,thinking`. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_DEFAULT_HAIKU_MODEL` | Model ID that the `haiku` alias resolves to, also used for [background functionality](/docs/en/costs#background-token-usage). See [Model configuration](/docs/en/model-config#environment-variables) | -| `ANTHROPIC_DEFAULT_HAIKU_MODEL_DESCRIPTION` | Display description for the pinned Haiku model in the `/model` picker. Defaults to `Custom Haiku model` when not set. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_DEFAULT_HAIKU_MODEL_NAME` | Display name for the pinned Haiku model in the `/model` picker. Defaults to the model ID when not set. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_DEFAULT_HAIKU_MODEL_SUPPORTED_CAPABILITIES` | Comma-separated list of [capabilities](/docs/en/model-config#customize-pinned-model-display-and-capabilities) the pinned Haiku model supports, for example `effort,thinking`. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_DEFAULT_MODEL` | Model that new sessions start on by default. Requires Claude Code v2.1.236 or later. See [Set a default model for new sessions](/docs/en/model-config#set-a-default-model-for-new-sessions) | -| `ANTHROPIC_DEFAULT_OPUS_MODEL` | Model ID that the `opus` alias resolves to, and that `opusplan` uses while Plan Mode is active. See [Model configuration](/docs/en/model-config#environment-variables) | -| `ANTHROPIC_DEFAULT_OPUS_MODEL_DESCRIPTION` | Display description for the pinned Opus model in the `/model` picker. When not set, defaults to `Custom Opus model`, or `Custom Opus model (1M context)` if the pinned model ID has the `[1m]` suffix and `CLAUDE_CODE_DISABLE_1M_CONTEXT` isn't turned on. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_DEFAULT_OPUS_MODEL_NAME` | Display name for the pinned Opus model in the `/model` picker. Defaults to the model ID when not set. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_DEFAULT_OPUS_MODEL_SUPPORTED_CAPABILITIES` | Comma-separated list of [capabilities](/docs/en/model-config#customize-pinned-model-display-and-capabilities) the pinned Opus model supports, for example `effort,thinking`. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_DEFAULT_SONNET_MODEL` | Model ID that the `sonnet` alias resolves to, and that `opusplan` uses when Plan Mode is not active. See [Model configuration](/docs/en/model-config#environment-variables) | -| `ANTHROPIC_DEFAULT_SONNET_MODEL_DESCRIPTION` | Display description for the pinned Sonnet model in the `/model` picker. When not set, defaults to `Custom Sonnet model`, or `Custom Sonnet model (1M context)` if the pinned model ID has the `[1m]` suffix and `CLAUDE_CODE_DISABLE_1M_CONTEXT` isn't turned on. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_DEFAULT_SONNET_MODEL_NAME` | Display name for the pinned Sonnet model in the `/model` picker. Defaults to the model ID when not set. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_DEFAULT_SONNET_MODEL_SUPPORTED_CAPABILITIES` | Comma-separated list of [capabilities](/docs/en/model-config#customize-pinned-model-display-and-capabilities) the pinned Sonnet model supports, for example `effort,thinking`. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | -| `ANTHROPIC_FEDERATION_RULE_ID` | Federation rule ID for [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation). When you set it together with `ANTHROPIC_ORGANIZATION_ID`, Claude Code selects federation credentials, which rank above your `/login` credential. See [authentication precedence](/docs/en/authentication#authentication-precedence) | -| `ANTHROPIC_FOUNDRY_API_KEY` | API key for Microsoft Foundry authentication (see [Microsoft Foundry](/docs/en/microsoft-foundry)) | -| `ANTHROPIC_FOUNDRY_AUTH_TOKEN` | Bearer token for Microsoft Foundry authentication, such as a Microsoft Entra access token. Claude Code sends it as the `Authorization: Bearer` header. Takes precedence over `ANTHROPIC_FOUNDRY_API_KEY` and over the Azure default credential chain. See [Microsoft Foundry](/docs/en/microsoft-foundry). Requires Claude Code v2.1.203 or later | -| `ANTHROPIC_FOUNDRY_BASE_URL` | Full base URL for the Microsoft Foundry resource (for example, `https://my-resource.services.ai.azure.com/anthropic`). Alternative to `ANTHROPIC_FOUNDRY_RESOURCE` (see [Microsoft Foundry](/docs/en/microsoft-foundry)) | -| `ANTHROPIC_FOUNDRY_RESOURCE` | Microsoft Foundry resource name (for example, `my-resource`). Required if `ANTHROPIC_FOUNDRY_BASE_URL` is not set (see [Microsoft Foundry](/docs/en/microsoft-foundry)) | -| `ANTHROPIC_MODEL` | Name of the model setting to use (see [Model Configuration](/docs/en/model-config#environment-variables)) | -| `ANTHROPIC_ORGANIZATION_ID` | Organization ID for [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation). Set it together with `ANTHROPIC_FEDERATION_RULE_ID`. See [authentication precedence](/docs/en/authentication#authentication-precedence) | -| `ANTHROPIC_PROFILE` | Name of the Anthropic profile to authenticate with, such as one created by [`ant auth login`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/authentication) or by [signing in to a Console account without an API key](/docs/en/authentication#sign-in-without-an-api-key). See [authentication precedence](/docs/en/authentication#authentication-precedence) | -| `ANTHROPIC_SMALL_FAST_MODEL` | \[DEPRECATED] Name of [Haiku-class model for background tasks](/docs/en/costs) | -| `ANTHROPIC_SMALL_FAST_MODEL_AWS_REGION` | Override AWS region for the Haiku-class model when using Amazon Bedrock or Amazon Bedrock Mantle. On Amazon Bedrock, this only takes effect when `ANTHROPIC_DEFAULT_HAIKU_MODEL` or the deprecated `ANTHROPIC_SMALL_FAST_MODEL` is also set, since Amazon Bedrock otherwise runs background tasks on the [default Sonnet model or the primary model](/docs/en/amazon-bedrock#4-pin-model-versions) in the session region | -| `ANTHROPIC_VERTEX_BASE_URL` | Override Google Cloud's Agent Platform endpoint URL. Use for custom Google Cloud's Agent Platform endpoints or when routing through an [LLM gateway](/docs/en/llm-gateway). See [Google Cloud's Agent Platform](/docs/en/google-vertex-ai) | -| `ANTHROPIC_VERTEX_PROJECT_ID` | GCP project ID for Google Cloud's Agent Platform requests. Overridden by `GCLOUD_PROJECT`, `GOOGLE_CLOUD_PROJECT`, or the project in your `GOOGLE_APPLICATION_CREDENTIALS` credential file. See [Google Cloud's Agent Platform](/docs/en/google-vertex-ai) | -| `ANTHROPIC_WORKSPACE_ID` | Workspace ID for [workload identity federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation). Set this when your federation rule is scoped to more than one workspace so the token exchange knows which workspace to target | -| `API_FORCE_IDLE_TIMEOUT` | Override the 5-minute body idle timeout that aborts a streaming model response when no bytes arrive. Set to `0` to turn the timeout off, for example when a slow [gateway](/docs/en/llm-gateway) or local model pauses longer than 5 minutes between chunks, or `1` to keep it on for every provider. When unset, the timeout is active on providers other than the direct Anthropic API and [Claude Platform on AWS](/docs/en/claude-platform-on-aws). The [stream watchdogs](/docs/en/network-config#streaming-idle-watchdogs) run independently of it and abort a long silent pause even when you set `0` here. Requires Claude Code v2.1.169 or later | -| `API_TIMEOUT_MS` | Timeout for API requests in milliseconds (default: 600000, or 10 minutes; maximum: 2147483647). Increase this when requests time out on slow networks or when routing through a proxy. Values above the maximum overflow the underlying timer and cause requests to fail immediately | -| `AWS_BEARER_TOKEN_BEDROCK` | Amazon Bedrock API key for authentication (see [Amazon Bedrock API keys](https://aws.amazon.com/blogs/machine-learning/accelerate-ai-development-with-amazon-bedrock-api-keys/)) | -| `BASH_DEFAULT_TIMEOUT_MS` | Default timeout for long-running bash commands (default: 120000, or 2 minutes) | -| `BASH_MAX_OUTPUT_LENGTH` | Maximum number of characters of bash output that Claude Code reads back into a command's result (default: 30000; maximum: 150000). See [Output limits](/docs/en/tools-reference#output-limits) | -| `BASH_MAX_TIMEOUT_MS` | Maximum timeout the model can set for long-running bash commands (default: 600000, or 10 minutes). The effective ceiling is the larger of this and `BASH_DEFAULT_TIMEOUT_MS` | -| `BETA_TRACING_ENDPOINT` | OTLP endpoint for [detailed beta tracing](/docs/en/monitoring-usage#traces-beta): with `ENABLE_BETA_TRACING_DETAILED=1`, logs and traces go there instead of to the configured exporters. Set it in your shell, user settings, or managed settings. Ignored in [project and local settings](/docs/en/settings-reference#variables-claude-code-ignores-in-env) | -| `CCR_FORCE_BUNDLE` | Set to `1` to force [`claude --cloud`](/docs/en/claude-code-on-the-web#send-local-repositories-without-github) to bundle and upload your local repository even when GitHub access is available | -| `CLAUDECODE` | Set to `1` in subprocesses Claude Code spawns (Bash and PowerShell tools, tmux sessions, [hook](/docs/en/hooks) commands, [status line](/docs/en/statusline) commands, stdio [MCP server](/docs/en/mcp) subprocesses). IDE extensions also set this in their integrated terminals. Use to detect when a script is running inside a subprocess spawned by Claude Code. To check whether the current process was spawned directly by a tool call or hook, rather than inside a stdio MCP server that Claude Code started, use `CLAUDE_CODE_CHILD_SESSION` instead | -| `CLAUDE_AFK_COUNTDOWN_MS` | How many milliseconds before auto-continue the on-screen countdown appears on an unanswered [`AskUserQuestion`](/docs/en/tools-reference) dialog. Default `20000` (20 seconds), capped at the auto-continue timeout. Has no effect unless auto-continue is on; see the [`askUserQuestionTimeout`](/docs/en/settings-reference#askuserquestiontimeout) setting and `CLAUDE_AFK_TIMEOUT_MS`. Requires Claude Code v2.1.198 or later | -| `CLAUDE_AFK_TIMEOUT_MS` | How many milliseconds of idle time before an unanswered [`AskUserQuestion`](/docs/en/tools-reference) dialog auto-continues without you. Auto-continue is off by default; opt in with the [`askUserQuestionTimeout`](/docs/en/settings-reference#askuserquestiontimeout) setting. This variable is an override for demos and automated tests: when set, it takes precedence over that setting and turns auto-continue on even when the setting is unset or `never`. Setting `0` doesn't turn the timeout off; it closes the dialog immediately. In v2.1.198 and v2.1.199, auto-continue was on by default with a `60000` (60 seconds) timeout. Requires Claude Code v2.1.198 or later | -| `CLAUDE_AGENT_SDK_DISABLE_BUILTIN_AGENTS` | Set to `1` to disable all built-in [subagent](/docs/en/sub-agents) types such as Explore and Plan. Only applies in non-interactive mode (the `-p` flag). Useful for SDK users who want a blank slate. This also removes `general-purpose`, the subagent Claude Code runs when an Agent tool call omits `subagent_type`. Such a call then fails with [`subagent_type is required`](/docs/en/errors#subagent-type-is-required) | -| `CLAUDE_AGENT_SDK_MCP_NO_PREFIX` | Set to `1` to skip the `mcp____` prefix on tool names from SDK-created MCP servers. Tools use their original names. SDK usage only | -| `CLAUDE_ASYNC_AGENT_STALL_TIMEOUT_MS` | Stall timeout in milliseconds for subagents. Default `600000` (10 minutes); if you raise `CLAUDE_STREAM_IDLE_TIMEOUT_MS` while the stream watchdog is on, the default rises with it, as [Handle slow or stalled API responses](/docs/en/agent-sdk/typescript#handle-slow-or-stalled-api-responses) describes. The timer resets on each streaming progress event; if no progress arrives within the window, Claude Code aborts the subagent and reports the stall to the parent | -| `CLAUDE_AUTOCOMPACT_PCT_OVERRIDE` | Set the percentage (1-100) of the auto-compact window at which auto-compaction triggers. Use lower values like `50` to compact earlier; the variable can't raise the threshold, so values above the default percentage are ignored. It applies only in sessions that [compact before the model's context limit](/docs/en/model-config#context-window-and-auto-compaction). Applies to both main conversations and subagents | -| `CLAUDE_AUTO_BACKGROUND_TASKS` | Set to `1` to force-enable automatic backgrounding of long-running agent tasks. When enabled, subagents are moved to the background after running for approximately two minutes. Also enables [automatic backgrounding of long MCP tool calls](/docs/en/mcp#automatic-backgrounding-of-long-tool-calls) in non-interactive mode on Claude Code v2.1.212 or later | -| `CLAUDE_AX_PREPARK_MS` | In [screen reader mode](/docs/en/accessibility#what-your-screen-reader-hears), how many milliseconds Claude Code waits, with the cursor at the start of the line, before it writes a new or changed line. Default `50`. Set `0` to write immediately. Claude Code caps the wait at `5000`. Requires Claude Code v2.1.233 or later | -| `CLAUDE_AX_SCREEN_READER` | Set to `1` to render screen-reader friendly output: flat text without decorative borders or animations. Set to `0` to force screen-reader mode off even when [`axScreenReader`](/docs/en/settings-reference#axscreenreader) is `true`. The [`--ax-screen-reader`](/docs/en/cli-reference#cli-flags) flag takes precedence. Requires Claude Code v2.1.181 or later | -| `CLAUDE_AX_STARTUP_QUIET_MS` | In [screen reader mode](/docs/en/accessibility), how many milliseconds Claude Code holds the first interface render after the startup confirmation line, so your screen reader can speak the line in full before new output interrupts it. Default `3000`. Set `0` to render immediately. Claude Code caps the hold at `600000` (10 minutes). Your first keystroke ends the hold early. Requires Claude Code v2.1.217 or later | -| `CLAUDE_BASH_MAINTAIN_PROJECT_WORKING_DIR` | Return to the original working directory after each Bash or PowerShell command in the main session | -| `CLAUDE_BYTE_STREAM_IDLE_TIMEOUT_MS` | Timeout in milliseconds for the byte-level streaming idle watchdog; when set, it takes precedence over `CLAUDE_STREAM_IDLE_TIMEOUT_MS` for that watchdog and leaves the event-level watchdog unchanged. Claude Code clamps this variable to between 10 seconds and 30 minutes. Requires Claude Code v2.1.210 or later | -| `CLAUDE_CLIENT_PRESENCE_FILE` | Path to a file that an external tool, such as a screen-lock listener, creates when you unlock your screen and deletes when you lock it. While the file exists, Claude Code skips [Remote Control mobile push notifications](/docs/en/remote-control#mobile-push-notifications), so you stop getting pushes while you are actively using the computer. When the file is absent or unreadable, notifications are sent as normal. Claude Code checks the file once per push-triggering event rather than polling it. Requires Claude Code v2.1.181 or later | -| `CLAUDE_CODE_ACCESSIBILITY` | Set to `1` to keep the native terminal cursor visible and disable the inverted-text cursor indicator. Allows screen magnifiers like macOS Zoom to track cursor position | -| `CLAUDE_CODE_ADDITIONAL_DIRECTORIES_CLAUDE_MD` | Set to `1` to load memory files from directories specified with `--add-dir`. Loads `CLAUDE.md`, `.claude/CLAUDE.md`, `.claude/rules/*.md`, and `CLAUDE.local.md`. By default, additional directories do not load memory files | -| `CLAUDE_CODE_ALT_SCREEN_FULL_REPAINT` | Set to `1` to repaint the entire screen on every frame in [fullscreen rendering](/docs/en/fullscreen) instead of sending incremental updates. Use this if fullscreen mode shows stale or misplaced text fragments. Claude Code enables this automatically for background sessions and [agent view](/docs/en/agent-view) on Windows | -| `CLAUDE_CODE_ALWAYS_ENABLE_EFFORT` | Set to `1` to send the [effort](/docs/en/model-config#adjust-effort-level) parameter with every request, even when Claude Code does not recognize the model ID as effort-capable. Use this when routing through an [LLM gateway](/docs/en/llm-gateway) or third-party provider that serves models under custom identifiers. Models that reject the effort parameter at the API, including Claude 3 models, Sonnet 4.0 and 4.5, Opus 4.0 and 4.1, and Haiku 4.5, are still excluded so requests do not fail | -| `CLAUDE_CODE_API_KEY_HELPER_TTL_MS` | Interval in milliseconds at which credentials should be refreshed (when using [`apiKeyHelper`](/docs/en/settings-reference#apikeyhelper)) | -| `CLAUDE_CODE_ARTIFACT_AUTO_OPEN` | Set to `0` to stop Claude Code from opening the browser automatically when a new [artifact](/docs/en/artifacts) is published. Republishing an existing artifact does not open the browser regardless of this setting | -| `CLAUDE_CODE_ARTIFACT_COMMENTS` | Set to `0` to stop Claude reading and replying to [comments on an artifact](/docs/en/artifacts#collect-comments-on-an-artifact). Has no effect when `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC` has [turned artifacts off](/docs/en/artifacts#availability). Requires Claude Code v2.1.221 or later | -| `CLAUDE_CODE_ARTIFACT_COMMENTS_AUTOREACT` | Set to `0` to stop Claude [replying on its own to comments sent to it](/docs/en/artifacts#let-claude-reply-to-comments-on-its-own). Requires Claude Code v2.1.228 or later | -| `CLAUDE_CODE_ATTRIBUTION_HEADER` | Set to `0` to omit the [attribution block](/docs/en/llm-gateway-protocol#system-prompt-attribution-block), which carries the client version and a prompt fingerprint, from the start of the system prompt. Caching on a direct connection to the Anthropic API is unaffected either way. In some direct-connection setups, Claude Code keeps the block on [auto mode](/docs/en/permission-modes#eliminate-prompts-with-auto-mode) classifier requests even when you set `0`. In [System prompt attribution block](/docs/en/llm-gateway-protocol#system-prompt-attribution-block), check which connections and credentials this covers. Before v2.1.181 the block included a per-request token on custom base URLs and Microsoft Foundry connections, so on those versions set it to `0` when your LLM gateway caches on the request body or forwards requests to a third-party provider, or when you connect to Microsoft Foundry directly | -| `CLAUDE_CODE_AUTO_BACKGROUND_WORKER_CHECKIN_SECONDS` | When `CLAUDE_AUTO_BACKGROUND_TASKS` is enabled, seconds between reminders to Claude to check on [background subagents](/docs/en/sub-agents#run-subagents-in-foreground-or-background) that are still running. Accepts a plain integer from `1` to `86400` only; any other value or spelling reads as unset. When unset, there are no check-in reminders. Requires Claude Code v2.1.248 or later | -| `CLAUDE_CODE_AUTO_COMPACT_WINDOW` | Set the [auto-compact window](/docs/en/model-config#set-the-auto-compact-window) in tokens, from `100000` to `1000000`. Accepts a plain integer such as `500000` only: a value like `500k` reads as `500` and clamps to the 100K minimum. The effective window is also capped at the model's context window. Takes precedence over the `/autocompact` command, the `--autocompact` flag, and the `autoCompactWindow` setting. The status line's `used_percentage` always measures against the model's full context window, so once this variable is set, that percentage no longer indicates when compaction will run | -| `CLAUDE_CODE_AUTO_CONNECT_IDE` | Override automatic [IDE connection](/docs/en/vs-code). By default, Claude Code connects automatically when launched inside a supported IDE's integrated terminal. Set to `false` to prevent this. Set to `true` to force a connection attempt when auto-detection fails, such as when tmux obscures the parent terminal. Takes precedence over the [`autoConnectIde`](/docs/en/settings-reference#autoconnectide) global config setting | -| `CLAUDE_CODE_AWS_CHAIN_RESOLVE_TIMEOUT_MS` | Time in milliseconds Claude Code waits for the AWS default credential provider chain to produce credentials before the request fails with [`AWS default-chain credential resolve timed out`](/docs/en/errors#aws-default-chain-credential-resolve-timed-out) (default: `60000`). Raise it when a step in your chain legitimately needs longer, such as a browser-based SSO sign-in with MFA through a wrapper like `aws-vault`. Applies wherever Claude Code signs with the default chain: [Amazon Bedrock](/docs/en/amazon-bedrock#credential-caching-and-resolution-timeout), [Claude Platform on AWS](/docs/en/claude-platform-on-aws), and the [Mantle endpoint](/docs/en/amazon-bedrock#use-the-mantle-endpoint). Requires Claude Code v2.1.207 or later | -| `CLAUDE_CODE_BRIDGE_SESSION_ID` | Set automatically in Bash tool and [hook command](/docs/en/hooks) subprocesses while the session has an active [Remote Control](/docs/en/remote-control) connection, and removed when the connection ends. The value is the session's ID in `session_` form, the same identifier that appears in the session's `claude.ai/code` URL, so a script can link back to the session that ran it. Requires Claude Code v2.1.199 or later. In [cloud sessions](/docs/en/claude-code-on-the-web), read `CLAUDE_CODE_REMOTE_SESSION_ID` instead | -| `CLAUDE_CODE_BS_AS_CTRL_BACKSPACE` | Set to `0` to make Claude Code read the `0x08` byte, also written `^H`, as plain Backspace, or `1` to read it as Ctrl+Backspace. Either value replaces the platform default. By default, Claude Code reads it as Ctrl+Backspace on Windows, except when `TERM_PROGRAM` is `mintty` or `TERM` is `cygwin`, and as plain Backspace on macOS and Linux. Set `0` in a Windows terminal where [Backspace deletes a whole word](/docs/en/terminal-config#fix-backspace-deleting-a-whole-word-on-windows) | -| `CLAUDE_CODE_CERT_STORE` | Comma-separated list of CA certificate sources for TLS connections. `bundled` is the Mozilla CA set shipped with Claude Code. `system` is the operating system trust store, read only on runtimes with `tls.getCACertificates`: the native binary, or Node 22.15 or later for npm installs. See [CA certificate store](/docs/en/network-config#ca-certificate-store). Default is `bundled,system` | -| `CLAUDE_CODE_CHILD_SESSION` | Set to `1` in subprocesses Claude Code spawns via the Bash, PowerShell, and Monitor tools, [hook](/docs/en/hooks) commands, and [status line](/docs/en/statusline) commands. Not set for stdio [MCP server](/docs/en/mcp) subprocesses, which are long-lived and outlive the session that spawned them. Unlike `CLAUDECODE`, this is only set by Claude Code itself when it launches a subprocess and not by IDE extensions, so it reliably distinguishes a nested session from a top-level `claude` launched in an IDE-integrated terminal. A nested interactive `claude` TUI started this way is automatically excluded from `--resume`, `--continue`, up-arrow history, and the `claude agents` list. Non-interactive `claude -p` sessions still persist. Set `CLAUDE_CODE_FORCE_SESSION_PERSISTENCE=1` to override this exclusion. Requires Claude Code v2.1.172 or later | -| `CLAUDE_CODE_CLIENT_CERT` | Path to client certificate file for mTLS authentication | -| `CLAUDE_CODE_CLIENT_KEY` | Path to client private key file for mTLS authentication | -| `CLAUDE_CODE_CLIENT_KEY_PASSPHRASE` | Passphrase for encrypted CLAUDE\_CODE\_CLIENT\_KEY (optional) | -| `CLAUDE_CODE_CONNECT_TIMEOUT_MS` | Removed in v2.1.186 and now a no-op. Previously set a separate timeout for the connect, TLS, and response-header phase of a streaming API request. Use `API_TIMEOUT_MS` for the per-request timeout. For the response-header phase of a streaming request, see `CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS` | -| `CLAUDE_CODE_DEBUG_LOGS_DIR` | Override the debug log file path. Despite the name, this is a file path, not a directory. Requires debug mode to be enabled separately via `--debug`, `/debug`, or the `DEBUG` environment variable: setting this variable alone does not enable logging. The [`--debug-file`](/docs/en/cli-reference#cli-flags) flag does both at once. Defaults to `~/.claude/debug/.txt` | -| `CLAUDE_CODE_DEBUG_LOG_LEVEL` | Minimum log level written to the debug log file. Values: `verbose`, `debug` (default), `info`, `warn`, `error`. Set to `verbose` to include high-volume diagnostics like full status line command output, or raise to `error` to reduce noise | -| `CLAUDE_CODE_DISABLE_1M_CONTEXT` | Set to `1` to disable [1M context window](/docs/en/model-config#extended-context) support. When set, 1M model variants are unavailable in the model picker, and Claude Code holds sessions on models with a native 1M window, such as [Sonnet 5](/docs/en/model-config#sonnet-5-context-window) and the Fable models, to a 200K window; see [Extended context](/docs/en/model-config#extended-context) for how the hold is enforced. Useful for enterprise environments with compliance requirements. For its role in correcting the window for an unrecognized `[1m]` model ID, see [Correct the window for a gateway or custom model ID](/docs/en/model-config#correct-the-window-for-a-gateway-or-custom-model-id) | -| `CLAUDE_CODE_DISABLE_ADAPTIVE_THINKING` | Set to `1` to disable [adaptive reasoning](/docs/en/model-config#adjust-effort-level) on Opus 4.6 and Sonnet 4.6 and fall back to the fixed thinking budget controlled by `MAX_THINKING_TOKENS`. Has no effect on [Fable models](/docs/en/model-config#extended-thinking), Sonnet 5, or Opus 4.7 and later, which always use adaptive reasoning | -| `CLAUDE_CODE_DISABLE_ADMIN_ENV_UNION` | Set to `1` to stop Claude Code from merging [managed settings](/docs/en/managed-settings#precedence-within-the-managed-tier) `env` blocks per key across admin sources, so only the highest-priority source's whole `env` block applies, as before v2.1.223. Set it in the environment that launches Claude Code, since Claude Code ignores a copy delivered through a settings `env` block. Requires Claude Code v2.1.223 or later | -| `CLAUDE_CODE_DISABLE_ADVISOR_TOOL` | Set to `1` to disable the [advisor tool](/docs/en/advisor). The `/advisor` command becomes unavailable, any configured `advisorModel` is ignored, and the `--advisor` flag is accepted but has no effect, so existing scripts that pass it continue to work without errors | -| `CLAUDE_CODE_DISABLE_AGENT_VIEW` | Set to `1` to turn off [background agents and agent view](/docs/en/agent-view): `claude agents`, `--bg`, `/background`, and the on-demand supervisor. Equivalent to the [`disableAgentView`](/docs/en/settings-reference#disableagentview) setting | -| `CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN` | Set to `1` to disable [fullscreen rendering](/docs/en/fullscreen) and use the classic main-screen renderer. The conversation stays in your terminal's native scrollback so `Cmd+f` and tmux copy mode work as usual. Takes precedence over `CLAUDE_CODE_NO_FLICKER` and the [`tui`](/docs/en/settings-reference#tui) setting. You can also switch with `/tui default`. Does not apply to background sessions opened from [agent view](/docs/en/agent-view), which always use fullscreen rendering | -| `CLAUDE_CODE_DISABLE_ARTIFACT` | Set to `1` to turn off the [Artifact](/docs/en/artifacts) tool, which publishes session output as a private web page on claude.ai. Once you set it, no settings file turns the tool back on. To turn the tool off from a settings file instead, set [`enableArtifact`](/docs/en/settings-reference#enableartifact) to `false`; the deprecated [`disableArtifact`](/docs/en/settings-reference#disableartifact) key also turns it off | -| `CLAUDE_CODE_DISABLE_ATTACHMENTS` | Set to `1` to disable attachment processing. File mentions with `@` syntax are sent as plain text instead of being expanded into file content | -| `CLAUDE_CODE_DISABLE_AUTO_MEMORY` | Set to `1` to disable [auto memory](/docs/en/memory#auto-memory). Set to `0` to force auto memory on even when `--bare` mode or [`autoMemoryEnabled: false`](/docs/en/settings-reference#automemoryenabled) would otherwise disable it. When disabled, Claude does not create or load auto memory files | -| `CLAUDE_CODE_DISABLE_BACKGROUND_TASKS` | Set to `1` to disable all background task functionality, including the `run_in_background` parameter on Bash and subagent tools, auto-backgrounding, and the Ctrl+B shortcut | -| `CLAUDE_CODE_DISABLE_BEDROCK_CONTENT_TYPE_DEFAULT` | Set to `1` to stop Claude Code from treating an [Amazon Bedrock](/docs/en/amazon-bedrock) streaming response with a missing or empty `Content-Type` header as Amazon Bedrock's binary event stream. By default, Claude Code assumes a gateway dropped the header from an otherwise unmodified response, so it decodes the body and streaming keeps working. Set this only for a gateway that also re-emits the stream as server-sent events; Claude Code then reads the header-less body as server-sent events instead. Requires Claude Code v2.1.239 or later | -| `CLAUDE_CODE_DISABLE_BEDROCK_CONTENT_TYPE_GUARD` | Set to `1` to skip the check that an [Amazon Bedrock](/docs/en/amazon-bedrock) streaming response carries the `application/vnd.amazon.eventstream` content-type. Without this variable, when a response carries a different content-type, Claude Code fails the request with an error naming that type, which means a [gateway or proxy is transforming the response](/docs/en/amazon-bedrock#streaming-errors-behind-a-gateway-or-proxy). Configure the gateway to forward the `Content-Type` header and body unmodified rather than setting this variable. Requires Claude Code v2.1.208 or later | -| `CLAUDE_CODE_DISABLE_BG_EXIT_HANDOFF` | Set to `1` to stop a [background session's](/docs/en/agent-view) running background shell commands, dynamic workflows, and, as of v2.1.198, background subagents when the [supervisor](/docs/en/agent-view#the-supervisor-process) stops, restarts, or updates that session's process, instead of handing them to the session's next process. Affects only that handoff: backgrounding a session with `←` or [`/background`](/docs/en/agent-view#from-inside-a-session) still carries in-flight work over, and `CLAUDE_DISABLE_ADOPT` turns off both. Requires Claude Code v2.1.196 or later | -| `CLAUDE_CODE_DISABLE_BG_SHELL_PRESSURE_REAP` | Set to `1` to stop Claude Code from terminating [background shell commands](/docs/en/interactive-mode#background-bash-commands) when the operating system reports memory pressure. By default, on macOS and Linux, Claude Code terminates a background shell started in the main session on a memory-pressure signal once the session has been idle for 30 minutes and no turn or subagent is running. Windows has no memory-pressure signal, so this variable has no effect there. Requires Claude Code v2.1.193 or later | -| `CLAUDE_CODE_DISABLE_BUNDLED_SKILLS` | Set to `1` to disable the [skills](/docs/en/skills) and workflows included with Claude Code: bundled skills and workflows are removed entirely, while built-in commands like `/init` stay typable but are hidden from the model. `/doctor` stays typable like the built-in commands; hide it with `DISABLE_DOCTOR_COMMAND` instead. Skills from plugins, `.claude/skills/`, and `.claude/commands/` are unaffected. Equivalent to the [`disableBundledSkills`](/docs/en/settings-reference#disablebundledskills) setting | -| `CLAUDE_CODE_DISABLE_CFC_PROMPT` | Set to `1` to keep the [Claude in Chrome](/docs/en/chrome) browser tools available while omitting the Chrome section of the system prompt and the `/claude-in-chrome` [bundled skill](/docs/en/skills#bundled-skills). For hosts that embed Claude Code and supply their own browser guidance. Requires Claude Code v2.1.257 or later | -| `CLAUDE_CODE_DISABLE_CLAUDE_MDS` | Set to `1` to prevent loading any CLAUDE.md memory files into context, including user, project, and auto memory files | -| `CLAUDE_CODE_DISABLE_CRON` | Set to `1` to disable [scheduled tasks](/docs/en/scheduled-tasks). The `/loop` skill and cron tools become unavailable and any already-scheduled tasks stop firing, including tasks that are already running mid-session | -| `CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS` | Set to `1` to strip Anthropic-specific `anthropic-beta` request headers and beta tool-schema fields (such as `defer_loading` and `eager_input_streaming`) from API requests. Use this when a proxy gateway rejects requests with errors like "Unexpected value(s) for the `anthropic-beta` header" or "Extra inputs are not permitted". Standard fields (`name`, `description`, `input_schema`, `cache_control`) are preserved. [MCP tool search](/docs/en/mcp#scale-with-mcp-tool-search) is disabled and all MCP tools load upfront, even when you set `ENABLE_TOOL_SEARCH`. On Claude Code v2.1.227 or later, [managed settings](/docs/en/managed-settings) can keep tool search on. [Disable pre-release capabilities](/docs/en/llm-gateway-protocol#disable-pre-release-capabilities) covers where the override applies | -| `CLAUDE_CODE_DISABLE_EXPLORE_PLAN_AGENTS` | Set to `1` to disable the built-in [Explore and Plan subagents](/docs/en/sub-agents#built-in-subagents). Claude explores with its search tools or the general-purpose subagent instead, and [plan mode](/docs/en/permission-modes#analyze-before-you-edit-with-plan-mode) reads files directly rather than launching Explore and Plan agents. Custom subagents named `Explore` or `Plan` are unaffected. To remove every built-in subagent type in the Agent SDK or non-interactive mode, use `CLAUDE_AGENT_SDK_DISABLE_BUILTIN_AGENTS` instead. Requires Claude Code v2.1.198 or later | -| `CLAUDE_CODE_DISABLE_FAST_MODE` | Set to `1` to disable [fast mode](/docs/en/fast-mode) | -| `CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY` | Set to `1` to disable the "How is Claude doing?" session quality surveys. Surveys are also disabled when `DISABLE_TELEMETRY`, `DO_NOT_TRACK`, or `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC` is set, unless `CLAUDE_CODE_ENABLE_FEEDBACK_SURVEY_FOR_OTEL` opts back in. To set a sample rate instead of disabling outright, use the [`feedbackSurveyRate`](/docs/en/settings-reference#feedbacksurveyrate) setting. See [Session quality surveys](/docs/en/data-usage#session-quality-surveys) | -| `CLAUDE_CODE_DISABLE_FILE_CHECKPOINTING` | Set to `1` to disable file [checkpointing](/docs/en/checkpointing). The `/rewind` command will not be able to restore code changes. Overrides the [`fileCheckpointingEnabled`](/docs/en/settings-reference#filecheckpointingenabled) setting | -| `CLAUDE_CODE_DISABLE_GIT_INSTRUCTIONS` | Set to `1` to remove built-in commit and PR workflow instructions and the git status snapshot from Claude's system prompt. Useful when using your own git workflow skills. Takes precedence over the [`includeGitInstructions`](/docs/en/settings-reference#includegitinstructions) setting when set | -| `CLAUDE_CODE_DISABLE_LEGACY_MODEL_REMAP` | Set to `1` to prevent automatic remapping of Opus 4.0 and 4.1 to the current Opus version on the Anthropic API. Use when you intentionally want to pin an older model. The remap does not run on Amazon Bedrock, Google Cloud's Agent Platform, or Microsoft Foundry | -| `CLAUDE_CODE_DISABLE_MOUSE` | Set to `1` to disable mouse tracking in [fullscreen rendering](/docs/en/fullscreen). Keyboard scrolling with `PgUp` and `PgDn` still works. Use this to keep your terminal's native copy-on-select behavior | -| `CLAUDE_CODE_DISABLE_MOUSE_CLICKS` | Set to `1` to disable click, drag, and hover handling in [fullscreen rendering](/docs/en/fullscreen) while keeping mouse-wheel scrolling. Use this when you want wheel scroll to work inside Claude Code but don't want clicks to position the cursor, expand tool output, or open links. `CLAUDE_CODE_DISABLE_MOUSE` takes precedence when both are set. Requires Claude Code v2.1.195 or later | -| `CLAUDE_CODE_DISABLE_MTLS_RELOAD_ON_STALE_CONNECTION` | Set to `1` to stop Claude Code from re-reading the [mTLS client certificate and key](/docs/en/network-config#mtls-authentication) when an API request fails with a connection-level error, such as a connection reset or a TLS handshake error. With the reload disabled, Claude Code loads rotated files only when it next applies settings or at the next startup. Requires Claude Code v2.1.232 or later | -| `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC` | Set to any non-empty value, such as `1`, to disable nonessential network traffic: auto-updates, telemetry, error reporting, the `/feedback` command, [Claude-drafted feedback](/docs/en/tools-reference#sendfeedback-tool-behavior), release notes, the [PR and MR status badge](/docs/en/interactive-mode#pr-review-status) checks, [gateway model discovery](/docs/en/llm-gateway-connect#add-gateway-models-to-the-model-picker) refreshes, and availability checks such as the [fast mode](/docs/en/fast-mode#use-fast-mode-behind-proxies-and-llm-gateways) check. It also stops the [background runs of plugin `command` sources](/docs/en/plugin-marketplaces#when-claude-code-re-runs-the-command), which are local commands rather than network traffic, because they can trigger dependency installs. **Setting it to `0` or `false` still disables this traffic**, unlike most on/off variables; unset the variable to allow it again. Also disables feature-flag fetching, which makes [Remote Control](/docs/en/remote-control#requirements) and the other [features that need feature-flag fetching](#features-that-need-feature-flag-fetching) unavailable. Official plugin marketplace auto-install isn't covered; disable it with `CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL` | -| `CLAUDE_CODE_DISABLE_NONSTREAMING_FALLBACK` | Set to `1` to disable the non-streaming fallback when a streaming request fails mid-stream. Streaming errors propagate to the retry layer instead. Useful when a proxy or gateway causes the fallback to produce duplicate tool execution | -| `CLAUDE_CODE_DISABLE_NOTIFICATION_PRESENCE_CHECK` | Set to `1` to send the `PushNotification` tool's desktop notification even while you are typing in or focused on the terminal. By default the tool skips both the desktop notification and the [mobile push](/docs/en/remote-control#mobile-push-notifications) when it detects recent keyboard activity or terminal focus. This variable disables only that local check, so the server can still suppress the mobile push when it detects that you are active. Requires Claude Code v2.1.193 or later | -| `CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL` | Set to `1` to disable automatic registration of the official plugin marketplace. Claude Code reads the variable when it is about to register the marketplace, usually during a machine's first interactive launch. If the variable is set at that point, Claude Code skips the registration permanently. Unsetting the variable later doesn't undo the skip. Run `claude plugin marketplace add anthropics/claude-plugins-official` to register the marketplace at any time | -| `CLAUDE_CODE_DISABLE_PERMISSION_PROMPT_NOTIFY_HOOKS` | Set to `1` to stop Claude Code from running your [`Notification` hooks for unanswered permission requests](/docs/en/hooks#notification) in sessions where Claude Code sends them to the Agent SDK's `canUseTool` callback, which is how Claude Desktop and the VS Code extension host Claude Code. Has no effect in terminal sessions. Requires Claude Code v2.1.233 or later | -| `CLAUDE_CODE_DISABLE_POLICY_SKILLS` | Set to `1` to skip loading skills from the system-wide managed skills directory. Useful for container or CI sessions that should not load operator-provisioned skills | -| `CLAUDE_CODE_DISABLE_TERMINAL_TITLE` | Set to `1` to disable automatic terminal title updates based on conversation context. In Agent SDK and `claude -p` sessions, this also skips the background small/fast-model request that generates the session title | -| `CLAUDE_CODE_DISABLE_THINKING` | Set to `1` to omit the `thinking` parameter from API requests entirely. This is a compatibility option for proxies and gateways that reject the parameter. The variable's behavior is unchanged from earlier versions; on models that think by default, omitting the parameter means the model may still think. To explicitly disable [extended thinking](https://platform.claude.com/docs/en/build-with-claude/extended-thinking) on the Anthropic API, use `MAX_THINKING_TOKENS=0` instead, which is also ineffective on [Fable models](/docs/en/model-config#extended-thinking) since they can't have thinking turned off. On [third-party providers](/docs/en/third-party-integrations), `0` likewise omits the parameter, so the two variables behave the same there | -| `CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT` | Set to `1` to skip proactive [auto-compaction](/docs/en/costs#reduce-token-usage) when Claude Code doesn't recognize the model ID, such as an [LLM gateway](/docs/en/llm-gateway) alias. Without this variable, Claude Code compacts at the context window it assumes for the ID. `CLAUDE_CODE_MAX_CONTEXT_TOKENS` can correct the assumed window instead; see [Correct the window for a gateway or custom model ID](/docs/en/model-config#correct-the-window-for-a-gateway-or-custom-model-id) for when each variable applies. Requires Claude Code v2.1.223 or later | -| `CLAUDE_CODE_DISABLE_VIRTUAL_SCROLL` | Set to `1` to disable virtual scrolling in [fullscreen rendering](/docs/en/fullscreen) and render every message in the transcript. Use this if scrolling in fullscreen mode shows blank regions where messages should appear | -| `CLAUDE_CODE_DISABLE_WORKFLOWS` | Set to `1` to disable [workflows](/docs/en/workflows#turn-workflows-off). Equivalent to the [`disableWorkflows`](/docs/en/settings-reference#disableworkflows) setting | -| `CLAUDE_CODE_EFFORT_LEVEL` | Set the effort level for supported models. Values: `low`, `medium`, `high`, `xhigh`, `max`, or `auto` to use the model default. Available levels depend on the model. Takes precedence over `--effort`, `/effort`, and the `modelSettings` and `effortLevel` settings. See [Adjust effort level](/docs/en/model-config#adjust-effort-level) | -| `CLAUDE_CODE_ENABLE_APPEND_SUBAGENT_PROMPT` | Set to `1` to enable appending extra text to the end of the system prompt of every [subagent](/docs/en/sub-agents) other than a [forked subagent](/docs/en/sub-agents#fork-the-current-conversation). The [`--append-subagent-system-prompt`](/docs/en/cli-reference#cli-flags) flag supplies the appended text and sets this variable automatically, so you don't need to set it yourself. Requires Claude Code v2.1.205 or later | -| `CLAUDE_CODE_ENABLE_AUTO_MODE` | Accepted for compatibility with older releases and has no effect. Auto mode is available by default on every provider, including Amazon Bedrock, Google Cloud's Agent Platform, Microsoft Foundry, and signed-in [Claude apps gateway](/docs/en/claude-apps-gateway) sessions. In v2.1.158 through v2.1.206, setting this to `1` was required to make [auto mode](/docs/en/permission-modes#eliminate-prompts-with-auto-mode) available on those providers | -| `CLAUDE_CODE_ENABLE_AWAY_SUMMARY` | Override [session recap](/docs/en/interactive-mode#session-recap) availability. Set to `0` to force recaps off regardless of the `/config` toggle. Set to `1` to force recaps on when [`awaySummaryEnabled`](/docs/en/settings-reference#awaysummaryenabled) is `false`. Takes precedence over the setting and `/config` toggle | -| `CLAUDE_CODE_ENABLE_BACKGROUND_PLUGIN_REFRESH` | Set to `1` to refresh plugin state at turn boundaries in [non-interactive mode](/docs/en/headless) after a background install completes. Off by default because the refresh changes the system prompt mid-session, which invalidates [prompt caching](/docs/en/prompt-caching) for that turn | -| `CLAUDE_CODE_ENABLE_FEEDBACK_SURVEY_FOR_OTEL` | Set to `1` to route the "How is Claude doing?" session quality survey to your own [OpenTelemetry collector](/docs/en/monitoring-usage) when Anthropic-bound nonessential traffic is blocked. Survey ratings are emitted only as OTEL events to your configured collector. No survey data is sent to Anthropic in this mode. Applies when `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC`, `DISABLE_TELEMETRY`, or `DO_NOT_TRACK` is set, and has no effect otherwise. `CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY` and the organization product feedback policy take precedence | -| `CLAUDE_CODE_ENABLE_FINE_GRAINED_TOOL_STREAMING` | Controls whether tool call inputs stream from the API as Claude generates them. With this off, a large tool input such as a long file write arrives only after Claude finishes generating it, which can look like it's hanging. Enabled by default on the Anthropic API. On Amazon Bedrock and Google Cloud's Agent Platform, enabled per model where the deployed container supports it. Set to `0` to opt out. Set to `1` to force on when routing through a proxy via `ANTHROPIC_BASE_URL`, `ANTHROPIC_VERTEX_BASE_URL`, or `ANTHROPIC_BEDROCK_BASE_URL`. Off by default on Microsoft Foundry and [gateway](/docs/en/llm-gateway) connections | -| `CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY` | Set to `1` to populate the `/model` picker from your gateway's `/v1/models` endpoint when `ANTHROPIC_BASE_URL` points at an Anthropic-compatible gateway such as LiteLLM, Kong, or an internal proxy. Off by default because gateways backed by a shared API key would otherwise show every user every model the key can access. Discovered models are still filtered by an [`availableModels`](/docs/en/settings-reference#availablemodels) allowlist the session receives; deliver the list through [MDM or a managed settings file](/docs/en/managed-settings#delivery-mechanisms), since [server-managed delivery is not available on gateway configurations](/docs/en/server-managed-settings#platform-availability) | -| `CLAUDE_CODE_ENABLE_OPUS_4_7_FAST_MODE` | Removed in v2.1.142, when the [fast mode](/docs/en/fast-mode) default moved from Opus 4.6 to Opus 4.7 | -| `CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION` | Set to `false` to turn off prompt suggestions, the grayed-out predictions that appear in your prompt input. Takes precedence over the [`promptSuggestionEnabled`](/docs/en/settings-reference#promptsuggestionenabled) setting, which is what the **Prompt suggestions** toggle in `/config` writes. Claude Code also [pauses suggestions while your account is close to or at its usage limit](/docs/en/interactive-mode#when-claude-code-skips-suggestions). Set to `true` to keep them on until you reach the limit. Requires Claude Code v2.1.238 or later. See [Prompt suggestions](/docs/en/interactive-mode#prompt-suggestions) | -| `CLAUDE_CODE_ENABLE_TASKS` | Selects which task-tracking tools Claude Code provides in [sessions that have them](/docs/en/tools-reference#task-tool-availability). By default, Claude Code provides the Task tools `TaskCreate`, `TaskUpdate`, `TaskGet`, and `TaskList`. Set to `0` to get the legacy `TodoWrite` tool instead. See [Task list](/docs/en/interactive-mode#task-list) | -| `CLAUDE_CODE_ENABLE_TELEMETRY` | Set to `1` to enable OpenTelemetry data collection for metrics and logging. Required before configuring OTel exporters. See [Monitoring](/docs/en/monitoring-usage) | -| `CLAUDE_CODE_ENABLE_TODO_TOOLS` | Set to `1` to get the task-tracking tools on the models listed under [Task tool availability](/docs/en/tools-reference#task-tool-availability), where Claude Code otherwise leaves them out. `CLAUDE_CODE_ENABLE_TASKS` still selects the Task tools or `TodoWrite`. Requires Claude Code v2.1.233 or later | -| `CLAUDE_CODE_EXIT_AFTER_STOP_DELAY` | Time in milliseconds to wait after the query loop becomes idle before automatically exiting. Useful for automated workflows and scripts using SDK mode | -| `CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS` | Set to `1` to enable [agent teams](/docs/en/agent-teams). Agent teams are experimental and disabled by default | -| `CLAUDE_CODE_EXTRA_BODY` | JSON object to merge into the top level of every API request body. Useful for passing provider-specific parameters that Claude Code doesn't expose directly. A value exported in your shell also applies to the [background sessions](/docs/en/agent-view) you dispatch with `claude agents` or `--bg`. Before v2.1.206, background sessions ignored a shell-exported value and used whatever copy the background supervisor process inherited | -| `CLAUDE_CODE_FILE_READ_MAX_OUTPUT_TOKENS` | Override the default token limit for file reads. Useful when you need to read larger files in full | -| `CLAUDE_CODE_FORCE_SESSION_PERSISTENCE` | Set to `1` to force transcript persistence, prompt history, and `claude agents` registration even when this `claude` was launched from inside another Claude Code session. Use when an inherited `CLAUDE_CODE_CHILD_SESSION` value, for example from a `screen` session or a background launcher first started by Claude Code's Bash tool, causes a genuine top-level session to be misclassified as nested. As of v2.1.178, Claude Code detects the tmux case automatically and ignores the inherited marker, so tmux no longer needs this variable. Also honored on v2.1.169 and earlier; has no effect on v2.1.170 and v2.1.171, where the nested-session detection it overrides was removed | -| `CLAUDE_CODE_FORCE_STRIKETHROUGH` | Set to `1` to force strikethrough rendering for `~~text~~` in Claude's responses when your terminal supports it but is not auto-detected, such as over SSH without `TERM_PROGRAM` forwarded. Without this, undetected terminals show the literal `~~` markers instead of rendering the text as strikethrough. Requires Claude Code v2.1.186 or later | -| `CLAUDE_CODE_FORCE_SYNC_OUTPUT` | Set to `1` to force-enable DEC private mode 2026 [synchronized output](https://gist.github.com/christianparpart/d8a62cc1ab659194337d73e399004036) when your terminal supports it but is not auto-detected. Useful for emulators such as Emacs `eat` that implement BSU/ESU but do not reply to the capability probe. Has no effect under tmux. Unlike `CLAUDE_CODE_NO_FLICKER`, which switches to [fullscreen rendering](/docs/en/fullscreen), this doesn't change the renderer | -| `CLAUDE_CODE_FORK_SUBAGENT` | Controls [fork mode](/docs/en/sub-agents#turn-fork-mode-on-or-off), which lets Claude spawn [forked subagents](/docs/en/sub-agents#fork-the-current-conversation) itself and is on by default in interactive sessions only. Set to `1` to turn it on in `claude -p` and the Agent SDK as well, or `0` to turn it off in every kind of session. You can run `/subtask` whether or not fork mode is on. The interactive default requires Claude Code v2.1.232 or later; on earlier versions, set the variable to `1` to turn fork mode on | -| `CLAUDE_CODE_FORWARD_SUBAGENT_TEXT` | Set to `1` to emit [subagent](/docs/en/sub-agents) text and thinking blocks in `claude -p --output-format stream-json` output, the same behavior as the [`--forward-subagent-text`](/docs/en/cli-reference#cli-flags) flag. Use the variable when a harness invokes `claude` and can't pass the flag itself. Unlike the flag, which exits with an error outside non-interactive mode with stream-json output, the variable is ignored there so that nested invocations keep working when it's set process-wide. Requires Claude Code v2.1.211 or later | -| `CLAUDE_CODE_GIT_BASH_PATH` | Windows only: path to the Git Bash executable (`bash.exe`). Use when Git Bash is installed but not in your PATH. If the path doesn't exist or the file isn't named `bash.exe`, `sh.exe`, `bash`, or `sh`, Claude Code ignores the variable and auto-detects Git Bash as if it were unset, logging a warning visible with `--debug`. Before v2.1.219, Claude Code exited at startup when the path didn't exist, and used any existing file as the shell without checking that it was bash or sh. See [Windows setup](/docs/en/setup#set-up-on-windows) | -| `CLAUDE_CODE_GLOB_HIDDEN` | Set to `false` to exclude dotfiles from results when Claude invokes the [Glob tool](/docs/en/tools-reference#glob-tool-behavior). Included by default. Does not affect `@` file autocomplete, `ls`, Grep, or Read | -| `CLAUDE_CODE_GLOB_NO_IGNORE` | Set to `false` to make the [Glob tool](/docs/en/tools-reference#glob-tool-behavior) respect `.gitignore` patterns. By default, Glob returns all matching files including gitignored ones. Does not affect `@` file autocomplete, which has its own [`respectGitignore` setting](/docs/en/settings-reference#respectgitignore) | -| `CLAUDE_CODE_GLOB_TIMEOUT_SECONDS` | Timeout in seconds for Glob tool file discovery. Defaults to 20 seconds on most platforms and 60 seconds on WSL | -| `CLAUDE_CODE_GOAL_CHECKIN_MINUTES` | How many minutes background work can keep an active goal waiting before Claude Code [asks Claude to check on it](/docs/en/goal#background-work-defers-evaluation). Default `30`. Set `0` to turn check-ins off. Give whole minutes in plain digits, at most `10080`, which is one week. Claude Code treats any other value as unset and uses the default. Requires Claude Code v2.1.234 or later | -| `CLAUDE_CODE_HIDE_CWD` | Set to `1` to hide the working directory in the startup logo. Useful for screenshares or recordings where the path exposes your OS username | -| `CLAUDE_CODE_IDE_HOST_OVERRIDE` | Override the host address used to connect to the IDE extension. By default Claude Code auto-detects the correct address, including WSL-to-Windows routing | -| `CLAUDE_CODE_IDE_SKIP_AUTO_INSTALL` | Set to `1` to skip auto-installation of IDE extensions. Equivalent to setting [`autoInstallIdeExtension`](/docs/en/settings-reference#autoinstallideextension) to `false` | -| `CLAUDE_CODE_IDE_SKIP_VALID_CHECK` | Set to `1` to skip validation of IDE lockfile entries during connection. Use when auto-connect fails to find your IDE despite it running | -| `CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS` | How many [subagents](/docs/en/sub-agents#concurrent-subagent-limit) can be running in one session before the Agent tool refuses to spawn another (default: 20). Accepts a positive whole number in plain digits; anything else is ignored, so the variable can adjust the cap but can't disable it. Requires Claude Code v2.1.217 or later | -| `CLAUDE_CODE_MAX_CONTEXT_TOKENS` | Override the context window size Claude Code assumes for the active model. As of v2.1.193, how it applies depends on how Claude Code resolves the model ID; see [Correct the window for a gateway or custom model ID](/docs/en/model-config#correct-the-window-for-a-gateway-or-custom-model-id). Use this when routing to a model through `ANTHROPIC_BASE_URL` whose context window does not match the built-in size for its name | -| `CLAUDE_CODE_MAX_OUTPUT_TOKENS` | Set the maximum number of output tokens for most requests. Defaults and caps vary by model; see [max output tokens](https://platform.claude.com/docs/en/about-claude/models/overview#latest-models-comparison). Claude Code defaults to 32000 for model IDs it doesn't recognize, such as gateway-specific names, and lowers values above a model's cap to the cap. Increasing this value reduces the effective context window available before [auto-compaction](/docs/en/costs#reduce-token-usage) triggers | -| `CLAUDE_CODE_MAX_RETRIES` | Override the number of times to retry failed API requests (default: 10). Capped at 15 as of v2.1.186; as of v2.1.199, `CLAUDE_CODE_RETRY_WATCHDOG` raises the default and removes the cap. For unattended sessions that need to wait through longer outages, set `CLAUDE_CODE_RETRY_WATCHDOG` instead | -| `CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION` | Removed in v2.1.224 and now a no-op. Previously capped the total number of [subagents](/docs/en/sub-agents) Claude could spawn with the Agent tool in one session (default: 200); spawning past the cap failed with `Subagent spawn limit reached`. The [concurrent subagent limit](/docs/en/sub-agents#concurrent-subagent-limit) and the [depth limit](/docs/en/sub-agents#let-subagents-spawn-their-own-subagents) still apply | -| `CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH` | Number of [subagent layers](/docs/en/sub-agents#let-subagents-spawn-their-own-subagents) allowed below the main conversation (default: 3). At the default, subagents can spawn their own subagents, and a subagent at the third layer can't spawn further; set `1` to turn nesting off. In v2.1.217 through v2.1.218, the default was 1, so a subagent couldn't spawn its own unless you raised the limit; v2.1.219 raised the default to 3. Accepts a positive whole number in plain digits; anything else is ignored, so the limit can be adjusted but not removed. Requires Claude Code v2.1.217 or later | -| `CLAUDE_CODE_MAX_TOOL_USE_CONCURRENCY` | Maximum number of read-only tools and subagents that can execute in parallel (default: 10). Higher values increase parallelism but consume more resources | -| `CLAUDE_CODE_MAX_TURNS` | Cap the number of agentic turns when no explicit limit is passed. Equivalent to passing [`--max-turns`](/docs/en/cli-reference#cli-flags), which takes precedence when both are set. A value that is not a positive integer is rejected at startup with an error rather than treated as no cap | -| `CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION` | Cap on the total number of [WebSearch](/docs/en/tools-reference#websearch-tool-behavior) calls one session can make (default: 200). When Claude reaches the cap, further WebSearch calls return a notice telling it to continue with the information it already gathered. Accepts a positive whole number with no upper bound. Anything else is ignored and the default applies, so the cap can be raised but not turned off. Requires Claude Code v2.1.212 or later | -| `CLAUDE_CODE_MCP_ALLOWLIST_ENV` | Set to `1` to spawn stdio MCP servers with only a safe baseline environment plus the server's configured `env`, instead of inheriting your shell environment | -| `CLAUDE_CODE_MCP_AUTO_BACKGROUND_MS` | Elapsed time in milliseconds before a still-running MCP tool call [moves to a background task](/docs/en/mcp#automatic-backgrounding-of-long-tool-calls) (default: 120000, or 2 minutes). Set to `0` to turn automatic backgrounding off. Requires Claude Code v2.1.212 or later | -| `CLAUDE_CODE_MCP_TOOL_IDLE_TIMEOUT` | Idle timeout in milliseconds for MCP tool calls. When a stdio, HTTP, SSE, WebSocket, or [claude.ai connector](/docs/en/mcp#use-mcp-servers-from-claude-ai) MCP server sends no response and no progress notification for this long, the tool call aborts with an error instead of waiting for the overall `MCP_TOOL_TIMEOUT`. Overrides the per-transport defaults of 300000 (5 minutes) for network servers and 1800000 (30 minutes) for stdio servers. Set to `0` to disable the idle check. Values below 1000 are raised to one second, and the value is capped at the effective `MCP_TOOL_TIMEOUT`. A per-server `timeout` in `.mcp.json` of at least 1000 raises that server's idle window to at least the `timeout` value. Doesn't apply to IDE servers or SDK in-process servers. Requires Claude Code v2.1.187 or later. Before v2.1.203, stdio servers were exempt from the idle timeout | -| `CLAUDE_CODE_MESSAGING_SOCKET` | Set by Claude Code, not by you: in sessions that bind an [inbox socket](/docs/en/cross-session-messaging#the-sessions-inbox-socket), Claude Code exports that socket's path to hooks and Bash commands when it binds the socket. In a session that starts with messaging on, Claude Code binds the socket before any hook runs. Other sessions on the machine deliver messages to this path. Each session exports its own socket rather than one inherited from a parent, and messages arriving on it go through the session's [inbound controls](/docs/en/cross-session-messaging#control-inbound-messages). Settings `env` blocks can't set it. Requires Claude Code v2.1.224 or later | -| `CLAUDE_CODE_MESSAGING_TOKEN` | Set by Claude Code, not by you: in sessions that bind an [inbox socket](/docs/en/cross-session-messaging#the-sessions-inbox-socket), Claude Code exports this per-session token to hooks and Bash commands alongside `CLAUDE_CODE_MESSAGING_SOCKET`. A script posting to the socket can send `{"type":"auth","token":""}` as its first line to prove it belongs to the session. On native Windows, Claude Code requires this line and closes any connection that doesn't open with a valid one. The [own-child rules](/docs/en/cross-session-messaging#the-sessions-inbox-socket) say when Claude Code consults the token. Each session exports its own token, never one inherited from a parent session. Settings `env` blocks can't set it. Requires Claude Code v2.1.228 or later | -| `CLAUDE_CODE_NATIVE_CURSOR` | Set to `1` to show the terminal's own cursor at the input caret instead of a drawn block. The cursor respects the terminal's blink, shape, and focus settings | -| `CLAUDE_CODE_NEW_INIT` | Set to `1` to make `/init` run an interactive setup flow. The flow asks which files to generate, including CLAUDE.md, skills, and hooks, before exploring the codebase and writing them. Without this variable, `/init` generates a CLAUDE.md automatically without prompting | -| `CLAUDE_CODE_NO_FLICKER` | Set to `1` to enable [fullscreen rendering](/docs/en/fullscreen), a research preview that reduces flicker and keeps memory flat in long conversations. Overrides the [`tui`](/docs/en/settings-reference#tui) setting; you can also switch with `/tui fullscreen` | -| `CLAUDE_CODE_OAUTH_REFRESH_TOKEN` | OAuth refresh token for Claude.ai authentication. When set, `claude auth login` exchanges this token directly instead of opening a browser. Requires `CLAUDE_CODE_OAUTH_SCOPES`. Useful for provisioning authentication in automated environments | -| `CLAUDE_CODE_OAUTH_SCOPES` | Space-separated OAuth scopes the refresh token was issued with, such as `"user:profile user:inference user:sessions:claude_code"`. Required when `CLAUDE_CODE_OAUTH_REFRESH_TOKEN` is set | -| `CLAUDE_CODE_OAUTH_TOKEN` | OAuth access token for claude.ai authentication. Alternative to `/login` for SDK and automated environments. Takes precedence over keychain-stored credentials. Generate one with [`claude setup-token`](/docs/en/authentication#generate-a-long-lived-token). Unless you run [`/login`](/docs/en/authentication#authentication-precedence), Claude Code uses the token you set for the whole session. To replace an expired token, generate a new one and restart | -| `CLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE` | Removed in v2.1.160 and now a no-op. Previously pinned [fast mode](/docs/en/fast-mode) to Claude Opus 4.6 instead of the current default. Opus 4.6 no longer supports fast mode | -| `CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH` | Maximum length of content-bearing OpenTelemetry attributes (model responses, tool content, system prompts, raw API bodies), truncation marker included, in UTF-16 code units (default: 61440, i.e. 60 KB). Raise it only if your telemetry backend accepts attribute values larger than 64 KB, or lower it to cut telemetry volume. Requires Claude Code v2.1.214 or later. See [Monitoring](/docs/en/monitoring-usage) | -| `CLAUDE_CODE_OTEL_DIAG_STDERR` | Set to `1` to write OpenTelemetry exporter diagnostic errors to stderr. By default these errors only appear with `--debug`, so a misconfigured exporter such as a Prometheus port collision otherwise fails silently. Requires Claude Code v2.1.179 or later. See [Monitoring](/docs/en/monitoring-usage) | -| `CLAUDE_CODE_OTEL_FLUSH_TIMEOUT_MS` | Timeout in milliseconds for flushing pending OpenTelemetry spans (default: 5000). See [Monitoring](/docs/en/monitoring-usage) | -| `CLAUDE_CODE_OTEL_HEADERS_HELPER_DEBOUNCE_MS` | Interval for refreshing dynamic OpenTelemetry headers in milliseconds (default: 1740000 / 29 minutes). See [Dynamic headers](/docs/en/monitoring-usage#dynamic-headers) | -| `CLAUDE_CODE_OTEL_SHUTDOWN_TIMEOUT_MS` | Timeout in milliseconds for the OpenTelemetry exporter to finish on shutdown (default: 2000). Increase if metrics are dropped at exit. See [Monitoring](/docs/en/monitoring-usage) | -| `CLAUDE_CODE_PACKAGE_MANAGER_AUTO_UPDATE` | Set to `1` to let Claude Code run your package manager's upgrade command in the background when a new version is available. Applies to Homebrew and WinGet installations. Other package managers continue to show the upgrade command without running it. See [Auto updates](/docs/en/setup#auto-updates) | -| `CLAUDE_CODE_PERFORCE_MODE` | Set to `1` to enable Perforce-aware write protection. When set, Edit, Write, and NotebookEdit fail with a `p4 edit ` hint if the target file lacks the owner-write bit, which Perforce clears on synced files until `p4 edit` opens them. This prevents Claude Code from bypassing Perforce change tracking | -| `CLAUDE_CODE_PLUGIN_CACHE_DIR` | Override the plugins root directory. Despite the name, this sets the parent directory, not the cache itself: marketplaces and the plugin cache live in subdirectories under this path. Defaults to `~/.claude/plugins` | -| `CLAUDE_CODE_PLUGIN_GIT_TIMEOUT_MS` | Timeout in milliseconds for git operations when installing or updating plugins (default: 120000). Increase this value for large repositories or slow network connections. See [Git operations time out](/docs/en/plugin-marketplaces#git-operations-time-out) | -| `CLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILURE` | Set to `1` to skip the re-clone attempt and keep using the existing marketplace cache when a `git pull` fails. Useful in offline or airgapped environments where re-cloning would fail the same way. See [Marketplace updates fail in offline environments](/docs/en/plugin-marketplaces#marketplace-updates-fail-in-offline-environments) | -| `CLAUDE_CODE_PLUGIN_PREFER_HTTPS` | Set to `1` to clone GitHub `owner/repo` shorthand sources over HTTPS instead of SSH. Applies to plugin install and update, and to `/plugin marketplace add` and `update`. Useful in CI runners, containers, or any environment without a configured SSH key for `github.com` | -| `CLAUDE_CODE_PLUGIN_SEED_DIR` | Path to one or more read-only plugin seed directories, separated by `:` on Unix or `;` on Windows. Use this to bundle a pre-populated plugins directory into a container image. Claude Code registers marketplaces from these directories at startup and uses pre-cached plugins without re-cloning. See [Pre-populate plugins for containers](/docs/en/plugin-marketplaces#pre-populate-plugins-for-containers) | -| `CLAUDE_CODE_POWERSHELL_RESPECT_EXECUTION_POLICY` | Set to `1` to stop Claude Code from passing `-ExecutionPolicy Bypass` when spawning PowerShell for tool calls, hooks, and status line commands, and respect the machine's effective execution policy instead. By default Claude Code bypasses execution policy at process scope so `.ps1` scripts and module imports work on default-Restricted Windows installs. Process-scope bypass never overrides Group Policy `MachinePolicy` or `UserPolicy` regardless of this setting | -| `CLAUDE_CODE_PRINT_BG_WAIT_CEILING_MS` | Ceiling in milliseconds on continuous idle waiting after the final turn in [non-interactive mode](/docs/en/headless#background-tasks-at-exit) with the `-p` flag, while background subagents and workflows whose result is part of the output finish. Each turn that handles queued background results starts the count again. Default: `600000`, or 10 minutes. When idle waiting reaches the ceiling, Claude Code stops waiting for the remaining background tasks and exits. Set to `0` to wait indefinitely. This cap is separate from the five-second grace period that applies to plain background shells. Requires Claude Code v2.1.182 or later | -| `CLAUDE_CODE_PROCESS_WRAPPER` | Launch the processes Claude Code starts from its own binary, such as the background service that hosts [agent view](/docs/en/agent-view) sessions, through a corporate launcher given as an argv prefix like `/opt/corp/launcher`. Set it in the `env` block of user or [managed settings](/docs/en/managed-settings), not as a shell export, so the detached background service inherits it; project and local settings can't set it. Equivalent to the [`processWrapper` setting](/docs/en/settings-reference#processwrapper), which requires Claude Code v2.1.210 or later; this variable takes precedence when both are set. The VS Code extension configures its own launcher separately through its `claudeProcessWrapper` setting. Ignored on Windows. See [Run Claude Code behind a corporate launcher](/docs/en/corporate-launcher) for the value format, what the launcher covers, and the contract the launcher must satisfy. Requires Claude Code v2.1.208 or later | -| `CLAUDE_CODE_PROJECT_DIR_NAME` | Set together with `CLAUDE_CONFIG_DIR` to choose the `projects/` directory name Claude Code stores that session's transcripts and auto memory under, in place of one derived from the working directory path. For example, starting Claude Code with `CLAUDE_CONFIG_DIR=/srv/tenant-a CLAUDE_CODE_PROJECT_DIR_NAME=work claude` stores them under `/srv/tenant-a/projects/work/`. Claude Code ignores this variable when `CLAUDE_CONFIG_DIR` is unset, and reads it only from the environment you start `claude` from, never from a [settings file `env` block](#in-settings-files). See [Name the project directory yourself](/docs/en/sessions#name-the-project-directory-yourself). Requires Claude Code v2.1.234 or later | -| `CLAUDE_CODE_PROMPT_CACHE_TTL` | Set `5m` or `1h`, the only values Claude Code accepts, to choose the [prompt cache TTL](/docs/en/prompt-caching#cache-lifetime) for the main conversation: your interactive, `-p`, and SDK turns, plus the helpers that run inline with them. Takes precedence over the `promptCacheTtl` setting and over `ENABLE_PROMPT_CACHING_1H`, and `FORCE_PROMPT_CACHING_5M` overrides it. The API bills 1-hour cache writes at a higher rate. Requires Claude Code v2.1.242 or later | -| `CLAUDE_CODE_PROPAGATE_TRACEPARENT` | Set to `1` to propagate W3C trace context when `ANTHROPIC_BASE_URL` points at a custom proxy. Propagation covers the `traceparent` header on model and HTTP MCP requests and the `TRACEPARENT` environment variable for Bash, PowerShell, and hook subprocesses. By default, propagation is enabled only when connected directly to the Anthropic API. Added in v2.1.152. See [Traces (beta)](/docs/en/monitoring-usage#traces-beta) | -| `CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST` | Set by host platforms that embed Claude Code and manage model provider routing on its behalf. When set, Claude Code ignores provider-selection, endpoint, and authentication variables such as `CLAUDE_CODE_USE_BEDROCK`, `ANTHROPIC_BASE_URL`, and `ANTHROPIC_API_KEY` in settings files, so user settings can't override the host's routing. Claude Code also ignores model-selection keys such as `model`, `fallbackModel`, and `modelOverrides` in [managed settings](/docs/en/managed-settings), whichever managed source delivers them, so the host's model configuration takes precedence over an out-of-date managed model pin. Claude Code also ignores model-selection variables such as `ANTHROPIC_MODEL` and the `ANTHROPIC_DEFAULT_*_MODEL` family in a managed `env` block; an [`availableModels`](/docs/en/model-config#restrict-model-selection) allowlist in managed settings still applies unless the host supplies its own. Claude Code also skips the automatic telemetry opt-out it otherwise applies on third-party providers such as Amazon Bedrock, Claude Platform on AWS, Google Cloud's Agent Platform, and Microsoft Foundry, so telemetry follows the standard `DISABLE_TELEMETRY` opt-out. See [Default behaviors by API provider](/docs/en/data-usage#default-behaviors-by-api-provider) | -| `CLAUDE_CODE_PROXY_RESOLVES_HOSTS` | Set to `1` to allow the proxy to perform DNS resolution instead of the caller. Opt-in for environments where the proxy should handle hostname resolution | -| `CLAUDE_CODE_REMOTE` | Set automatically to `true` when Claude Code is running as a [cloud session](/docs/en/claude-code-on-the-web). Read this from a hook or setup script to detect whether you are in a cloud session | -| `CLAUDE_CODE_REMOTE_SESSION_ID` | Set automatically in [cloud sessions](/docs/en/claude-code-on-the-web) to the current session's ID. Read this to construct a link back to the session transcript. See [Link output back to the session](/docs/en/cloud-environments#link-output-back-to-the-session) | -| `CLAUDE_CODE_RESTRICTED` | Set to `1` to start the session in restricted mode, the same as passing [`--restricted`](/docs/en/cli-reference#cli-flags). Claude Code ignores this variable in a settings file's `env` block. Requires Claude Code v2.1.248 or later | -| `CLAUDE_CODE_RESUME_INTERRUPTED_TURN` | Set to `1` to automatically resume if the previous session ended mid-turn. Used in SDK mode so the model continues without requiring the SDK to re-send the prompt. To turn this off, unset the variable or set it to `0`. Before v2.1.221, Claude Code ignored `0` and other falsy values, so setting `0` still triggered the resume in non-interactive mode and unsetting the variable was the only way to turn it off | -| `CLAUDE_CODE_RESUME_INTERRUPTED_TURN_MAX_AGE_MS` | Maximum age in milliseconds of the last transcript message for a session that ended mid-turn to continue automatically on resume. When the last message is older than this bound, Claude Code skips both the `CLAUDE_CODE_RESUME_INTERRUPTED_TURN` automatic resume and the injected `CLAUDE_CODE_RESUME_PROMPT` continuation message, and the session starts idle so you continue explicitly. Unset or `0` means no bound; a negative or non-numeric value applies a one-hour bound. Spawn scripts for long-running agents can set this so a restart against an old transcript doesn't re-run a stale prompt. Claude Code sets a one-hour bound itself when it restarts a crashed [agent view](/docs/en/agent-view) session that inherited its conversation from an interactive session. Requires Claude Code v2.1.211 or later | -| `CLAUDE_CODE_RESUME_PROMPT` | Override the continuation message injected when resuming a session that ended mid-turn. Defaults to `Continue from where you left off.`. Spawn scripts for long-running agents can set this to a more directive boot message. An empty string uses the default | -| `CLAUDE_CODE_RETRY_WATCHDOG` | Set to `1` for unattended sessions such as eval harnesses, CI jobs, or remote workers. Retries `429` and `529` capacity errors indefinitely instead of failing after `CLAUDE_CODE_MAX_RETRIES` attempts. Claude Code fails at once on a `429` that reports a spend limit or exhausted usage credits, even one from a [gateway spend cap](/docs/en/errors#spend-limit-reached) that resets on a schedule. Before v2.1.239, the watchdog retried these indefinitely. The watchdog backs off up to 5 minutes between attempts, or until the limit resets when the response carries a rate-limit reset time, so a session that hits a usage limit waits out the remaining window. On v2.1.199 or later it also raises the default retry count for other transient errors, such as server errors, timeouts, and dropped connections, to 300, roughly three hours of backoff, and removes the cap of 15 on `CLAUDE_CODE_MAX_RETRIES` if you set that variable explicitly. Requires Claude Code v2.1.186 or later | -| `CLAUDE_CODE_SAFE_MODE` | Set to `1` to start in safe mode: CLAUDE.md, skills, plugins, hooks, MCP servers, custom commands and agents, output styles, workflows, custom themes, custom keybindings, status line and file-suggestion commands, LSP servers, and auto memory do not load, for troubleshooting a broken configuration. Managed settings policy still applies, including policy-configured hooks, status line, and file-suggestion commands; managed plugins, managed skills, managed CLAUDE.md, and policy-configured MCP servers do not. Equivalent to passing [`--safe-mode`](/docs/en/cli-reference#cli-flags). Directly spawned child processes inherit the variable | -| `CLAUDE_CODE_SCRIPT_CAPS` | JSON object limiting how many times specific scripts may be invoked per session when `CLAUDE_CODE_SUBPROCESS_ENV_SCRUB` is set. Keys are substrings matched against the command text; values are integer call limits. For example, `{"deploy.sh": 2}` allows `deploy.sh` to be called at most twice. Matching is substring-based so shell-expansion tricks like `./scripts/deploy.sh $(evil)` still count against the cap. Runtime fan-out via `xargs` or `find -exec` is not detected; this is a defense-in-depth control | -| `CLAUDE_CODE_SCROLL_SPEED` | Set the mouse wheel scroll multiplier in [fullscreen rendering](/docs/en/fullscreen#mouse-wheel-scrolling). Accepts any positive value up to 20, including fractional values below 1 such as `0.5` to slow accelerated trackpad and wheel scrolling in terminals that already amplify wheel events. Set to `3` to match `vim` if your terminal sends one wheel event per notch without amplification. Ignored in the JetBrains IDE terminal, where Claude Code uses its own scroll handling | -| `CLAUDE_CODE_SEND_FEEDBACK` | Set to `0` to turn off [Claude-drafted feedback](/docs/en/tools-reference#sendfeedback-tool-behavior) for a session. Set to `1` to turn it on where your account already has access; the variable can't grant access itself, and the other switches that turn feedback off, such as `DISABLE_FEEDBACK_COMMAND` and the [`feedbackDrafts`](/docs/en/settings-reference#feedbackdrafts) setting's `off` value, still apply | -| `CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS` | Override the time budget in milliseconds for [SessionEnd](/docs/en/hooks#sessionend) hooks. Applies to session exit, `/clear`, and switching sessions via interactive `/resume`. By default the budget is 1.5 seconds, automatically raised to the highest per-hook `timeout` configured in settings files, up to 60 seconds. Timeouts on plugin-provided hooks do not raise the budget | -| `CLAUDE_CODE_SESSION_ID` | Set automatically to the current session ID in Bash and PowerShell tool subprocesses, [hook command](/docs/en/hooks) subprocesses, and stdio [MCP server](/docs/en/mcp) subprocesses. For Bash, PowerShell, and hooks this matches the `session_id` field in the hook JSON input and is updated on `/clear`. An MCP server subprocess retains the ID it was spawned with. On `--resume ` it receives the resumed ID, matching hooks and Bash. On `--continue` or `--resume` without an explicit ID it may receive the initial startup ID instead. Use to correlate scripts and external tools with the Claude Code session that launched them | -| `CLAUDE_CODE_SHELL` | Set the shell Claude Code uses to run Bash tool commands. Accepts a path to a `bash` or `zsh` binary, for example `/opt/homebrew/bin/bash`. Other shells such as `fish` are not supported. If the value is not a working `bash` or `zsh` path, Claude Code ignores it and falls back to auto-detection. Auto-detection uses your `$SHELL` when it points to `bash` or `zsh`, otherwise it picks the first working `zsh` then `bash` found on your `PATH` and standard install locations | -| `CLAUDE_CODE_SHELL_PREFIX` | Command prefix that wraps shell commands Claude Code spawns: Bash tool calls, [hook](/docs/en/hooks) commands, [status line](/docs/en/statusline) commands, and stdio [MCP server](/docs/en/mcp) startup commands. PowerShell hooks and exec-form hooks run without the prefix. Useful for logging or auditing. Setting a bare executable path such as `/path/to/logger.sh` runs each command as `/path/to/logger.sh ''`. The wrapper receives the command line as a single shell-quoted argument in `$1`, so the wrapper must re-evaluate `$1` with a shell, for example `exec bash -c "$1"`. Treating `$1` as a bare executable path breaks stdio MCP servers that pass arguments such as `npx -y `. For Bash tool calls, `$1` contains the full shell invocation Claude Code assembles, including environment setup, not only the command Claude ran | -| `CLAUDE_CODE_SIMPLE` | Set to `1` to run with a minimal system prompt and only the Bash, file read, and file edit tools. MCP tools from `--mcp-config` are still available. Disables auto-discovery of hooks, skills, custom commands, subagents, plugins, MCP servers, auto memory, and CLAUDE.md. Skills in a directory you pass with `--add-dir` still load. OAuth tokens and keychain credentials are not read, so Anthropic authentication must come from `ANTHROPIC_API_KEY` or an `apiKeyHelper` in `--settings`. Equivalent to passing [`--bare`](/docs/en/headless#start-faster-with-bare-mode) | -| `CLAUDE_CODE_SIMPLE_SYSTEM_PROMPT` | Set to `1` to use a shorter system prompt and abbreviated tool descriptions on any model. Set to `0`, `false`, `no`, or `off` to opt out even on models where the experiment or server configuration would otherwise enable it. The full tool set, hooks, MCP servers, and CLAUDE.md discovery remain enabled | -| `CLAUDE_CODE_SKIP_ANTHROPIC_AWS_AUTH` | Skip client-side authentication for [Claude Platform on AWS](/docs/en/claude-platform-on-aws), for gateways that sign requests themselves | -| `CLAUDE_CODE_SKIP_AWS_CRED_CACHE` | Set to `1` to turn off the in-process cache of credentials resolved from the AWS default credential provider chain, so Claude Code resolves the chain on every API request. With the cache off, an SSO-backed profile requests credentials from IAM Identity Center on every request. See [credential caching and resolution timeout](/docs/en/amazon-bedrock#credential-caching-and-resolution-timeout). Requires Claude Code v2.1.207 or later | -| `CLAUDE_CODE_SKIP_BEDROCK_AUTH` | Skip AWS authentication for Amazon Bedrock (for example, when using an LLM gateway) | -| `CLAUDE_CODE_SKIP_FAST_MODE_NETWORK_ERRORS` | Set to `1` to treat a failed [fast mode](/docs/en/fast-mode#use-fast-mode-behind-proxies-and-llm-gateways) availability check as available, for networks that block the check's direct request to `api.anthropic.com`. Claude Code still honors a "disabled by your organization" response | -| `CLAUDE_CODE_SKIP_FAST_MODE_ORG_CHECK` | Set to `1` to skip the client-side [fast mode](/docs/en/fast-mode#use-fast-mode-behind-proxies-and-llm-gateways) availability check, for proxies that intercept the check's request rather than refuse it. The API still rejects fast mode requests when your organization has fast mode disabled | -| `CLAUDE_CODE_SKIP_FOUNDRY_AUTH` | Skip Azure authentication for Microsoft Foundry, for a proxy or gateway that injects its own `Authorization` header. Claude Code sends requests without an Azure credential and preserves the `Authorization` header you supply, for example through `ANTHROPIC_CUSTOM_HEADERS`. Ignored when `ANTHROPIC_FOUNDRY_API_KEY` or `ANTHROPIC_FOUNDRY_AUTH_TOKEN` is set. Before v2.1.203, this variable left the Microsoft Foundry client unable to send requests unless an API key was also set | -| `CLAUDE_CODE_SKIP_MANTLE_AUTH` | Skip AWS authentication for Amazon Bedrock Mantle (for example, when using an LLM gateway) | -| `CLAUDE_CODE_SKIP_PROMPT_HISTORY` | Set to `1` to skip writing prompt history and session transcripts to disk. Sessions started with this variable set do not appear in `--resume`, `--continue`, or up-arrow history. Useful for ephemeral scripted sessions | -| `CLAUDE_CODE_SKIP_VERTEX_AUTH` | Skip Google authentication for Google Cloud's Agent Platform (for example, when using an LLM gateway) | -| `CLAUDE_CODE_STOP_HOOK_BLOCK_CAP` | Maximum number of consecutive times a [Stop](/docs/en/hooks#stop) or [SubagentStop](/docs/en/hooks#subagentstop) hook may block the turn from ending before Claude Code overrides it and ends the turn anyway (default: 8). Set to `0` to disable the cap. Raise this if your hook legitimately needs more iterations to resolve | -| `CLAUDE_CODE_SUBAGENT_MODEL` | The default model for [subagents](/docs/en/sub-agents#choose-a-model), [agent team](/docs/en/agent-teams#specify-teammates-and-models) teammates, and [workflow](/docs/en/workflows) agents that aren't assigned a model another way. Accepts an alias such as `haiku` or a full model name. Two sources take precedence over it: a model Claude passes when it spawns the agent, and a `model` field in the agent's definition, including `inherit`. To change that, set [`CLAUDE_CODE_SUBAGENT_MODEL_FORCE`](/docs/en/sub-agents#run-every-subagent-on-one-model). See [Choose a model](/docs/en/sub-agents#choose-a-model) for the full order. Setting it to `inherit` is the same as leaving it unset. Before v2.1.251, this variable overrode both the per-invocation model and the definition's `model` field | -| `CLAUDE_CODE_SUBAGENT_MODEL_FORCE` | Set to `1` to force one model onto subagents, teammates, and workflow agents. [Run every subagent on one model](/docs/en/sub-agents#run-every-subagent-on-one-model) says which model that is. Requires Claude Code v2.1.257 or later | -| `CLAUDE_CODE_SUBAGENT_PROMPT_CACHE_TTL` | Set `5m` or `1h`, the only values Claude Code accepts, to choose the [prompt cache TTL](/docs/en/prompt-caching#cache-lifetime) for requests outside the main conversation, such as [subagents](/docs/en/sub-agents), workflows, and background work. Takes precedence over the `subagentPromptCacheTtl` setting and over `ENABLE_PROMPT_CACHING_1H`, and `FORCE_PROMPT_CACHING_5M` overrides it. The API bills 1-hour cache writes at a higher rate. Requires Claude Code v2.1.242 or later | -| `CLAUDE_CODE_SUBPROCESS_ENV_SCRUB` | Set to `1` to strip credentials from subprocess environments (Bash tool, hooks, MCP stdio servers): Anthropic and cloud provider credentials, any other variable that Claude Code recognizes as a credential, and credentials embedded in package registry URLs. The parent Claude process keeps these credentials for API calls, but child processes cannot read them, reducing exposure to prompt injection attacks that attempt to exfiltrate secrets via shell expansion. On Linux, this also runs Bash subprocesses in an isolated PID namespace so they cannot read host process environments via `/proc`; as a side effect, `ps`, `pgrep`, and `kill` cannot see or signal host processes. `claude-code-action` sets this automatically when `allowed_non_write_users` is configured | -| `CLAUDE_CODE_SYNC_PLUGIN_INSTALL` | Set to `1` in non-interactive mode (the `-p` flag) to wait for plugin installation to complete before the first query. Without this, plugins install in the background and may not be available on the first turn. Combine with `CLAUDE_CODE_SYNC_PLUGIN_INSTALL_TIMEOUT_MS` to bound the wait | -| `CLAUDE_CODE_SYNC_PLUGIN_INSTALL_TIMEOUT_MS` | Timeout in milliseconds for synchronous plugin installation. When exceeded, Claude Code proceeds without plugins and logs an error. No default: without this variable, synchronous installation waits until complete | -| `CLAUDE_CODE_SYNC_SKILLS` | Set to `1` to download your enabled claude.ai skills into `~/.claude/skills/synced/` and resync every 10 minutes. Before it runs the first query, Claude Code waits up to `CLAUDE_CODE_SYNC_SKILLS_WAIT_TIMEOUT_MS` for the list of your skills. The downloads themselves finish in the background, and Claude waits for a skill's download when it invokes that skill. The `synced` folder name is [reserved for this download](/docs/en/skills#where-skills-live). Before v2.1.227, the skills downloaded into `~/.claude/skills/` directly. Applies only in non-interactive mode with the `-p` flag. Requires claude.ai authentication. [Claude Code on the web](/docs/en/claude-code-on-the-web) sessions receive your enabled claude.ai skills automatically; you don't need to set this there. Claude Code applies [extra rules to the downloaded skills](/docs/en/skills#how-synced-skills-behave), such as not running their `!` commands on your machine | -| `CLAUDE_CODE_SYNC_SKILLS_INSTALL_TIMEOUT_MS` | Timeout in milliseconds for a mid-session skills resync when `CLAUDE_CODE_SYNC_SKILLS` is set (default: 30000). Bounds the download triggered when the host requests a skill reload during the session. When exceeded, the resync stops and remaining downloads continue in the background | -| `CLAUDE_CODE_SYNC_SKILLS_WAIT_TIMEOUT_MS` | Timeout in milliseconds for the first query to wait for the initial skill list when `CLAUDE_CODE_SYNC_SKILLS` is set (default: 5000). When exceeded, the first query runs with whichever skills have arrived. The downloads finish in the background either way, and Claude waits for a skill's download when it invokes that skill | -| `CLAUDE_CODE_SYNTAX_HIGHLIGHT` | Set to `false` to disable syntax highlighting in diff output. Useful when colors interfere with your terminal setup. To also disable highlighting in code blocks and file previews, use the [`syntaxHighlightingDisabled`](/docs/en/settings-reference#syntaxhighlightingdisabled) setting | -| `CLAUDE_CODE_TASK_LIST_ID` | Share a task list across sessions. Set the same ID in multiple Claude Code instances to coordinate on a shared task list, in [sessions that have the Task tools](/docs/en/tools-reference#task-tool-availability). See [Task list](/docs/en/interactive-mode#task-list) | -| `CLAUDE_CODE_TEAM_TEARDOWN_PARK_TIMEOUT_MS` | Override, in milliseconds, how long a non-interactive session waits at exit for its [agent team](/docs/en/agent-teams) to finish tearing down. Accepts 1000 to 60000; an out-of-range value is ignored and the default of 10000 applies. Requires Claude Code v2.1.206 or later | -| `CLAUDE_CODE_TMPDIR` | Override the temp directory used for internal temp files. Claude Code appends `/claude-{uid}/` on Unix or `/claude/` on Windows to this path. Default: `/tmp` on macOS, `os.tmpdir()` on Linux and Windows. As of v2.1.161, on macOS and Linux, [sandboxed](/docs/en/sandboxing) Bash subprocesses receive a short fallback `$TMPDIR` under the system default when your override is a long path, since some tools fail when temp paths get too long. Unsandboxed Bash commands inherit your shell's `$TMPDIR` unchanged. Claude Code's own temp files always use your override. Set it in your shell, user settings, or managed settings. Ignored in [project and local settings](/docs/en/settings-reference#variables-claude-code-ignores-in-env) | -| `CLAUDE_CODE_TMUX_TRUECOLOR` | Set to any non-empty value, such as `1`, to allow 24-bit truecolor output inside tmux. **Setting it to `0` or `false` still allows truecolor**, unlike most on/off variables; unset the variable to restore the 256-color clamp. By default, Claude Code clamps to 256 colors when `$TMUX` is set because tmux does not pass through truecolor escape sequences unless configured to. Set this after adding `set -ga terminal-overrides ',*:Tc'` to your `~/.tmux.conf`. See [Terminal configuration](/docs/en/terminal-config) for other tmux settings | -| `CLAUDE_CODE_TOOL_MEMORY_CGROUP_EXCLUDE` | On Linux and WSL, set to a comma-separated list of the kinds of processes Claude Code [excludes from the tool memory cap](/docs/en/tools-reference#memory-limit-on-linux-and-wsl), such as `mcp` or `lsp`. Set `none` to cap every kind, or `all-new` to cap only Bash, PowerShell, and Monitor tool commands. Claude Code keeps Bash, PowerShell, and Monitor tool commands under the cap whatever you list. Requires Claude Code v2.1.246 or later | -| `CLAUDE_CODE_TOOL_MEMORY_LIMIT` | On Linux and WSL, set to a size such as `4G` to [cap the memory that Bash and PowerShell tool commands can use](/docs/en/tools-reference#memory-limit-on-linux-and-wsl), and Monitor tool commands on v2.1.246 or later. Write the size in plain digits, alone for a number of bytes or with a `K`, `M`, `G`, or `T` suffix. Set `0` or `off` to turn the cap off. Once the first process Claude Code starts has turned the cap on or off, a changed value takes effect the next time you launch `claude`. Requires Claude Code v2.1.233 or later | -| `CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS` | Deadline in milliseconds for dialogs Claude Code forwards to a remote client, such as a [Remote Control](/docs/en/remote-control) or SDK host, and for the approval dialog for a [held cross-session message](/docs/en/cross-session-messaging#control-inbound-messages), before Claude Code cancels them; permission prompts and `AskUserQuestion` questions use their own flows and aren't governed by it. Also bounds the mid-session [Fable usage-credits consent prompt](/docs/en/model-config#fable-and-usage-credits) in a session that may be running unattended. [Control inbound messages](/docs/en/cross-session-messaging#control-inbound-messages) and [non-interactive sessions](/docs/en/cross-session-messaging#non-interactive-sessions) cover the full held-message expiry rules, including the cases where the deadline doesn't apply. Overrides the [`dialogExpiry`](/docs/en/settings-reference#dialogexpiry) setting; `0` or a negative value disables the deadline | -| `CLAUDE_CODE_USE_ANTHROPIC_AWS` | Use [Claude Platform on AWS](/docs/en/claude-platform-on-aws) | -| `CLAUDE_CODE_USE_BEDROCK` | Use [Amazon Bedrock](/docs/en/amazon-bedrock) | -| `CLAUDE_CODE_USE_FOUNDRY` | Use [Microsoft Foundry](/docs/en/microsoft-foundry) | -| `CLAUDE_CODE_USE_MANTLE` | Use the Amazon Bedrock [Mantle endpoint](/docs/en/amazon-bedrock#use-the-mantle-endpoint) | -| `CLAUDE_CODE_USE_NATIVE_FILE_SEARCH` | Set to `1` to discover custom commands, subagents, and output styles using Node.js file APIs instead of ripgrep. Set this if the bundled ripgrep binary is unavailable or blocked in your environment. Does not affect the Grep or file search tools | -| `CLAUDE_CODE_USE_POWERSHELL_TOOL` | Controls the PowerShell tool. On Windows without Git Bash, the tool is enabled automatically; set to `0` to disable it. On Windows with Git Bash installed, the tool is on by default for claude.ai and Console accounts; set to `1` to enable it in Amazon Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry sessions, or `0` to turn it off. On Linux, macOS, and WSL, set to `1` to enable it, which requires `pwsh` on your `PATH`. When enabled on Windows, Claude can run PowerShell commands natively instead of routing through Git Bash. See [PowerShell tool](/docs/en/tools-reference#powershell-tool) | -| `CLAUDE_CODE_USE_VERTEX` | Use [Google Cloud's Agent Platform](/docs/en/google-vertex-ai) | -| `CLAUDE_CODE_WEBFETCH_CACHE_TTL_MS` | Set to the number of milliseconds [WebFetch](/docs/en/tools-reference#webfetch-tool-behavior) keeps each fetched URL's response cached. The default is `900000`, which is 15 minutes. Takes plain digits only; `0`, a decimal, or any other spelling keeps the default. Claude Code reads the value once per launch, so a change in a settings `env` block applies when you next launch `claude`. Requires Claude Code v2.1.233 or later | -| `CLAUDE_CODE_WORKFLOW_PREFIX_STAGGER_MS` | Upper bound in milliseconds on how long a [workflow](/docs/en/workflows) agent waits for a same-prefix sibling's first response to begin before sending its own first request. When a fan-out starts several agents that share a [prompt-cache prefix](/docs/en/workflows#prompt-caching-in-a-fan-out), Claude Code holds all but the first agent for up to this long so the rest read the cached prefix instead of each processing it uncached. Default `5000`. Set to `0` to disable the wait. When `DISABLE_PROMPT_CACHING` is set, agents never wait. Requires Claude Code v2.1.229 or later | -| `CLAUDE_CONFIG_DIR` | Override the configuration directory (default: `~/.claude`). All settings, session history, and plugins are stored under this path. For credentials, see [where Claude Code stores credentials](/docs/en/authentication#credential-management). Useful for running multiple accounts side by side: for example, `alias claude-work='CLAUDE_CONFIG_DIR=~/.claude-work claude'`. Set it in your shell, user settings, or managed settings. Ignored in [project and local settings](/docs/en/settings-reference#variables-claude-code-ignores-in-env) | -| `CLAUDE_DISABLE_ADOPT` | Set to `1` to stop in-flight background work instead of carrying it over when you background a session by pressing `←` or with [`/background`](/docs/en/agent-view#from-inside-a-session). Claude Code asks you to confirm before backgrounding, then stops the tasks that would otherwise carry over. Requires Claude Code v2.1.195 or later | -| `CLAUDE_EFFORT` | Set automatically in Bash tool subprocesses and hook commands to the [effort level](/docs/en/model-config#adjust-effort-level) in effect when the subprocess starts: `low`, `medium`, `high`, `xhigh`, or `max`. Ultracode is not a distinct level and reports as `xhigh`. Matches the `effort.level` field passed to [hooks](/docs/en/hooks). Only set when the current model supports the effort parameter | -| `CLAUDE_ENABLE_BYTE_WATCHDOG` | Set to `1` to force-enable the byte-level streaming idle watchdog, or set to `0` to force-disable it. `0` also turns off the [first-byte deadline](/docs/en/network-config#streaming-idle-watchdogs) on the connections where that deadline runs. When unset, the watchdog is enabled by default for direct Anthropic API and [Claude Platform on AWS](/docs/en/claude-platform-on-aws) connections, and for streaming responses on [gateway](/docs/en/gateways) connections reached through `ANTHROPIC_BASE_URL` or `ANTHROPIC_AWS_BASE_URL`; before v2.1.222 it didn't run on those gateway connections, so the event-level watchdog could report a stall there even while keep-alive pings were arriving. For timeouts and how the timers interact, see [Streaming idle watchdogs](/docs/en/network-config#streaming-idle-watchdogs) | -| `CLAUDE_ENABLE_BYTE_WATCHDOG_BEDROCK` | Set to `1` to enable the byte-level streaming idle watchdog on Amazon Bedrock `vnd.amazon.eventstream` responses, which also enables the [first-byte deadline](/docs/en/network-config#streaming-idle-watchdogs) on Bedrock streaming requests. Off by default. Configure the timeout with `CLAUDE_STREAM_IDLE_TIMEOUT_MS` | -| `CLAUDE_ENABLE_STREAM_WATCHDOG` | Set to `0` to force-disable the event-level streaming idle watchdog, or set to `1` to force-enable it. When unset, the watchdog is on by default for all providers. Before v2.1.196, the unset default was server-controlled on the direct Anthropic API and off on other providers. Configure the timeout with `CLAUDE_STREAM_IDLE_TIMEOUT_MS`; for the other stall timers that run alongside this one, see [Streaming idle watchdogs](/docs/en/network-config#streaming-idle-watchdogs) | -| `CLAUDE_ENV_FILE` | Path to a shell script whose contents Claude Code runs before each Bash command in the same shell process, so exports in the file are visible to the command. Use to persist virtualenv or conda activation across commands. Also populated dynamically by [SessionStart](/docs/en/hooks#persist-environment-variables), [Setup](/docs/en/hooks#setup), [CwdChanged](/docs/en/hooks#cwdchanged), and [FileChanged](/docs/en/hooks#filechanged) hooks | -| `CLAUDE_PID` | Claude Code sets this to its own process ID in the subprocesses it spawns: Bash and PowerShell tool commands and hook commands. On Linux, the Bash tool's shell integration uses it to refuse a `pkill` pattern that would match the Claude Code process itself; see [the error reference](/docs/en/errors#pkill-pattern-matches-the-claude-code-process). Read it from your own scripts to identify or signal the parent Claude Code process deliberately. Requires Claude Code v2.1.214 or later | -| `CLAUDE_REMOTE_CONTROL_SESSION_NAME_PREFIX` | Prefix for auto-generated [Remote Control](/docs/en/remote-control) session names when no explicit name is provided. Defaults to your machine's hostname, producing names like `myhost-graceful-unicorn`. The `--remote-control-session-name-prefix` CLI flag sets the same value for a single invocation | -| `CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS` | Deadline in milliseconds for the first response byte of a streaming request, on the connections where the [first-byte deadline](/docs/en/network-config#streaming-idle-watchdogs) runs. For how Claude Code clamps it, the extra time it adds for large request bodies, and how it picks the deadline when you leave this unset, see [No response from API](/docs/en/errors#no-response-from-api). Requires Claude Code v2.1.242 or later | -| `CLAUDE_STREAM_IDLE_TIMEOUT_MS` | Timeout in milliseconds before the event- and byte-level streaming idle watchdogs close a stalled connection. When you set this variable explicitly, the minimum is `300000` (5 minutes); lower values are silently clamped to absorb extended thinking pauses and proxy buffering, and the byte-level watchdog caps the value at 30 minutes. `CLAUDE_BYTE_STREAM_IDLE_TIMEOUT_MS` takes precedence over this variable for the byte-level watchdog. For the per-watchdog unset defaults, see [Streaming idle watchdogs](/docs/en/network-config#streaming-idle-watchdogs) | -| `CLAUDE_SUBAGENT_BG_SHELL_MAX_MS` | Maximum lifetime in milliseconds for a [background shell command](/docs/en/interactive-mode#background-bash-commands) that a [subagent](/docs/en/sub-agents) started. Default `3600000` (60 minutes). When you set `0`, Claude Code applies the default instead of removing the cap. When the subagent runs in the foreground, Claude Code also ends the command when that subagent gives its final response, regardless of this cap. See [the background command lifetime rules](/docs/en/tools-reference#background-commands). Claude Code doesn't cap main-session background commands this way. For the memory-pressure limit that covers them, see [How backgrounding works](/docs/en/interactive-mode#how-backgrounding-works) | -| `DEBUG` | Set to `1` to enable debug mode, equivalent to launching with [`--debug`](/docs/en/cli-reference#cli-flags). Debug logs are written to `~/.claude/debug/.txt`, or to the path set by `CLAUDE_CODE_DEBUG_LOGS_DIR`. Only the truthy values `1`, `true`, `yes`, and `on` enable debug mode, so namespace patterns like `DEBUG=express:*` set for other tools do not trigger it | -| `DISABLE_AUTOUPDATER` | Set to `1` to disable automatic background updates. Manual `claude update` still works. Use `DISABLE_UPDATES` to block both | -| `DISABLE_AUTO_COMPACT` | Set to `1` to disable automatic compaction when approaching the context limit. The manual `/compact` command remains available. Use when you want explicit control over when compaction occurs. Overrides the [`autoCompactEnabled`](/docs/en/settings-reference#autocompactenabled) setting | -| `DISABLE_COMPACT` | Set to `1` to disable all compaction: both automatic compaction and the manual `/compact` command | -| `DISABLE_COST_WARNINGS` | Set to `1` to disable cost warning messages | -| `DISABLE_DOCTOR_COMMAND` | Set to `1` to hide the [`/doctor`](/docs/en/commands#all-commands) setup checkup skill and its `/checkup` alias. Useful for managed deployments where users shouldn't run setup diagnostics from a session. Doesn't affect the `claude doctor` terminal command. Before v2.1.205, this variable hid the `/doctor` diagnostics screen command | -| `DISABLE_ERROR_REPORTING` | Set to any non-empty value, such as `1`, to opt out of error reporting. **Setting it to `0` or `false` still opts out**, unlike most on/off variables; unset the variable to turn error reporting back on | -| `DISABLE_EXTRA_USAGE_COMMAND` | Set to `1` to hide the `/usage-credits` command that lets users purchase additional usage beyond rate limits | -| `DISABLE_FEEDBACK_COMMAND` | Set to `1` to disable the `/feedback` command and [Claude-drafted feedback](/docs/en/tools-reference#sendfeedback-tool-behavior). Also disables `/bug` and `/share`, which report through the same path; before v2.1.212 they were aliases of `/feedback`, so the command was disabled under every name. The older name `DISABLE_BUG_COMMAND` is also accepted | -| `DISABLE_GROWTHBOOK` | Set to `1` or `true` to disable GrowthBook feature-flag fetching and use code defaults for every flag. This makes [Remote Control](/docs/en/remote-control#requirements) and the other [features that need feature-flag fetching](#features-that-need-feature-flag-fetching) unavailable. Setting it to `0` or `false` leaves fetching on. Telemetry event logging stays on unless `DISABLE_TELEMETRY` is also set | -| `DISABLE_INSTALLATION_CHECKS` | Set to `1` to disable installation warnings. Use only when manually managing the installation location, as this can mask issues with standard installations | -| `DISABLE_INSTALL_GITHUB_APP_COMMAND` | Set to `1` to hide the `/install-github-app` command. Already hidden when using third-party providers (Amazon Bedrock, Google Cloud's Agent Platform, or Microsoft Foundry) | -| `DISABLE_INTERLEAVED_THINKING` | Set to `1` to prevent sending the interleaved-thinking beta header. Useful when your LLM gateway or provider does not support [interleaved thinking](https://platform.claude.com/docs/en/build-with-claude/extended-thinking#interleaved-thinking) | -| `DISABLE_LOGIN_COMMAND` | Set to `1` to hide the `/login` command. Useful when authentication is handled externally via API keys or `apiKeyHelper` | -| `DISABLE_LOGOUT_COMMAND` | Set to `1` to hide the `/logout` command | -| `DISABLE_PROMPT_CACHING` | Set to `1` to disable [prompt caching](/docs/en/prompt-caching#disable-prompt-caching) for all models (takes precedence over per-model settings) | -| `DISABLE_PROMPT_CACHING_FABLE` | Set to `1` to disable prompt caching for Fable models | -| `DISABLE_PROMPT_CACHING_HAIKU` | Set to `1` to disable prompt caching for Haiku models | -| `DISABLE_PROMPT_CACHING_OPUS` | Set to `1` to disable prompt caching for Opus models | -| `DISABLE_PROMPT_CACHING_SONNET` | Set to `1` to disable prompt caching for Sonnet models | -| `DISABLE_TELEMETRY` | Set to any non-empty value, such as `1`, to opt out of telemetry. **Setting it to `0` or `false` still opts out**, unlike most on/off variables; unset the variable to turn telemetry back on. Telemetry events don't include user data like code, file paths, or bash commands. Also disables feature-flag fetching with the same effect as `DISABLE_GROWTHBOOK`, which makes [Remote Control](/docs/en/remote-control#requirements) and the other [features that need feature-flag fetching](#features-that-need-feature-flag-fetching) unavailable. See [Turn telemetry off for your organization](/docs/en/managed-settings#turn-telemetry-off-for-your-organization) | -| `DISABLE_UPDATES` | Set to `1` to block all updates including manual `claude update` and `claude install`. Stricter than `DISABLE_AUTOUPDATER`. Use when distributing Claude Code through your own channels and users should not self-update | -| `DISABLE_UPGRADE_COMMAND` | Set to `1` to hide the `/upgrade` command | -| `DO_NOT_TRACK` | Set to `1` to opt out of telemetry, with the same effect as `DISABLE_TELEMETRY`, including making [Remote Control](/docs/en/remote-control#requirements) and the other [features that need feature-flag fetching](#features-that-need-feature-flag-fetching) unavailable. Claude Code reads this variable as a standard boolean, so `0` leaves telemetry on, and honors it as the cross-tool convention recognized by many developer CLIs | -| `ENABLE_BETA_TRACING_DETAILED` | Set to `1`, together with `BETA_TRACING_ENDPOINT`, to turn on [detailed beta tracing](/docs/en/monitoring-usage#traces-beta), which adds content-bearing span attributes and the `claude_code.hook` span. Interactive CLI sessions also require your organization to be allowlisted for the beta. Both variables are ignored in [project and local settings](/docs/en/settings-reference#variables-claude-code-ignores-in-env) | -| `ENABLE_CLAUDEAI_MCP_SERVERS` | Set to `false` to stop Claude Code from fetching [claude.ai MCP servers](/docs/en/mcp#use-mcp-servers-from-claude-ai). Enabled by default for logged-in users. To disable per-project or per-org, set [`disableClaudeAiConnectors`](/docs/en/settings-reference#disableclaudeaiconnectors) in settings instead | -| `ENABLE_PROMPT_CACHING_1H` | Set to `1` to request a 1-hour [prompt cache TTL](/docs/en/prompt-caching#cache-lifetime) instead of the default 5 minutes. Intended for API key, [Amazon Bedrock](/docs/en/amazon-bedrock), [Google Cloud's Agent Platform](/docs/en/google-vertex-ai), [Microsoft Foundry](/docs/en/microsoft-foundry), and [Claude Platform on AWS](/docs/en/claude-platform-on-aws) users. Subscription users within included usage receive the 1-hour TTL automatically on the [main conversation](/docs/en/prompt-caching#which-ttl-each-request-gets). Subscription users drawing on [usage credits](https://support.claude.com/en/articles/12429409-extra-usage-for-paid-claude-plans) can set it to keep the 1-hour TTL. 1-hour cache writes are billed at a higher rate. To choose the TTL per request bucket instead, use `CLAUDE_CODE_PROMPT_CACHE_TTL` and `CLAUDE_CODE_SUBAGENT_PROMPT_CACHE_TTL`, which take precedence over this variable | -| `ENABLE_PROMPT_CACHING_1H_BEDROCK` | Deprecated. Use `ENABLE_PROMPT_CACHING_1H` instead | -| `ENABLE_TOOL_SEARCH` | Controls [MCP tool search](/docs/en/mcp#scale-with-mcp-tool-search). Unset, Claude Code defers all MCP tools by default. It still loads them upfront on Google Cloud's Agent Platform models earlier than the Claude 4.5 generation, on a Microsoft Foundry deployment hosted on Azure, and when `ANTHROPIC_BASE_URL` points to a non-first-party host. `true` always defers and sends the beta header, except on those same Agent Platform models and Microsoft Foundry deployments; requests fail on proxies that don't support `tool_reference`. `auto` loads upfront when tool definitions fit within 10% of context. `auto:N` sets a custom threshold, such as `auto:5` for 5%. `false` loads all tools upfront. A value you set yourself is ignored when `CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS` is set. Before v2.1.221, Claude Code disabled tool search for all models on Google Cloud's Agent Platform unless you set this variable to `true` | -| `FALLBACK_FOR_ALL_PRIMARY_MODELS` | Set to any non-empty value, such as `1`, to make every model stop retrying with a repeated-overload error when no fallback model is configured. **Setting it to `0` or `false` still enables this**, unlike most on/off variables; unset the variable to restore the default retry behavior. Without it, models Claude Code recognizes as Opus, Fable, or Mythos models stop retrying this way when you authenticate with an API key or a [third-party provider](/docs/en/third-party-integrations) rather than a Claude subscription. As of v2.1.160, a configured [fallback model chain](/docs/en/model-config#fallback-model-chains) triggers on repeated overload errors for any primary model, so this variable does not affect switching to a fallback model | -| `FORCE_AUTOUPDATE_PLUGINS` | Set to `1` to force plugin auto-updates even when the main auto-updater is disabled via `DISABLE_AUTOUPDATER` | -| `FORCE_HYPERLINK` | Set to `1` to enable clickable OSC 8 hyperlinks when your terminal supports them but isn't auto-detected, or `0` to disable them. When unset, Claude Code enables hyperlinks only when it detects terminal support. Claude Code parses this value as a number, not a Boolean, so a value such as `false`, `no`, or `off` enables hyperlinks rather than disabling them. Claude Code renders the footer [PR or merge request badge](/docs/en/interactive-mode#pr-review-status) as a hyperlink even when it can't detect terminal support, such as over SSH. Set `0` to render the badge as plain text | -| `FORCE_PROMPT_CACHING_5M` | Set to `1` to force the 5-minute prompt cache TTL even when 1-hour TTL would otherwise apply. Overrides `CLAUDE_CODE_PROMPT_CACHE_TTL`, `CLAUDE_CODE_SUBAGENT_PROMPT_CACHE_TTL`, `ENABLE_PROMPT_CACHING_1H`, and the `promptCacheTtl` and `subagentPromptCacheTtl` settings | -| `HTTP_PROXY` | Specify HTTP proxy server for network connections | -| `HTTPS_PROXY` | Specify HTTPS proxy server for network connections | -| `IS_DEMO` | Set to any non-empty value, such as `1`, to enable demo mode: hides your email and organization name from the header and `/status` output, and skips onboarding. **Setting it to `0` or `false` still enables demo mode**, unlike most on/off variables; unset the variable to turn it off. Useful when streaming or recording a session | -| `MAX_MCP_OUTPUT_TOKENS` | Maximum number of tokens allowed in MCP tool responses. Claude Code displays a warning when output exceeds 10,000 tokens. Tools that declare [`anthropic/maxResultSizeChars`](/docs/en/mcp#raise-the-limit-for-a-specific-tool) use that character limit for text content instead, but image content from those tools is still subject to this variable (default: 25000) | -| `MAX_STRUCTURED_OUTPUT_RETRIES` | Number of times Claude Code retries when the model's response fails validation against the [`--json-schema`](/docs/en/cli-reference#cli-flags) in non-interactive mode with the `-p` flag. The same retry count applies when a [workflow](/docs/en/workflows) subagent's structured output fails validation. Defaults to 5 | -| `MAX_THINKING_TOKENS` | Fixed token budget for [extended thinking](https://platform.claude.com/docs/en/build-with-claude/extended-thinking). Claude Code caps it at one token below the request's max output tokens and never below 1,024; see `CLAUDE_CODE_MAX_OUTPUT_TOKENS` for how that limit is set. When unset and thinking is enabled, models with [adaptive reasoning](/docs/en/model-config#adjust-effort-level) choose their own thinking depth, and other models use the cap. Set to `0` to disable thinking on the Anthropic API, except on [Fable models](/docs/en/model-config#extended-thinking), which can't have thinking turned off; on [third-party providers](/docs/en/third-party-integrations), `0` omits the `thinking` parameter instead. With thinking turned off on the Anthropic API, Claude Code sends effort `high` instead of a higher level to models it knows [don't accept that combination](/docs/en/errors#effort-isnt-available-with-thinking-turned-off), such as Opus 5. Nonzero values are ignored on adaptive reasoning models unless `CLAUDE_CODE_DISABLE_ADAPTIVE_THINKING` is set | -| `MCP_CLIENT_SECRET` | OAuth client secret for MCP servers that require [pre-configured credentials](/docs/en/mcp#use-pre-configured-oauth-credentials). Avoids the interactive prompt when adding a server with `--client-secret` | -| `MCP_CONNECTION_NONBLOCKING` | Controls whether startup waits for MCP servers to connect before the first query. MCP startup is non-blocking by default: servers connect in the background and their tools become available as they finish. Set to `0` to make Claude Code wait for servers to connect before the first query. Servers configured with [`alwaysLoad: true`](/docs/en/mcp#exempt-a-server-from-deferral) still make startup wait regardless, except when served from the [discovery cache](/docs/en/mcp#server-status-detail), since their tools must be present when the first prompt is built. In non-interactive mode (`-p`), Claude Code also waits for still-pending servers before the first turn regardless of this variable, with a longer deadline when you pass [`--mcp-config`](/docs/en/cli-reference#cli-flags) explicitly; see that flag's entry for the cached-server exception | -| `MCP_CONNECT_TIMEOUT_MS` | How long blocking MCP startup waits, in milliseconds, for the connection batch before snapshotting the tool list (default: 5000). Applies when `MCP_CONNECTION_NONBLOCKING=0` or for servers marked [`alwaysLoad: true`](/docs/en/mcp#exempt-a-server-from-deferral). Servers still pending at the deadline keep connecting in the background. Distinct from `MCP_TIMEOUT`, which bounds an individual server's connect attempt | -| `MCP_DISCOVERY_CACHE` | Turns the [MCP discovery cache](/docs/en/mcp#server-status-detail) on or off. With the cache on, a remote HTTP or SSE server you've used before can show the [`cached` status](/docs/en/mcp#server-status-detail), and Claude Code connects it on its first tool call instead of at startup. The cache is off by default unless a gradual rollout has enabled it for your account. Set to `1` to turn it on, or `0` to keep it off even when the rollout has enabled it. Before v2.1.238, the cache was on by default. The `cached` status requires Claude Code v2.1.221 or later | -| `MCP_DISCOVERY_CACHE_MAX_STALE_S` | Maximum age, in seconds, of a [discovery-cache](/docs/en/mcp#server-status-detail) entry (default: 14400, or 4 hours). At a start where the entry is older than that, Claude Code discards it and connects the server at startup, as it does with the cache off. Claude Code caps the value at 7 days. Before v2.1.238, the default was 86400, or 24 hours, and Claude Code didn't cap the value | -| `MCP_DISCOVERY_CACHE_STRIKES` | At a start where a [discovery-cache](/docs/en/mcp#server-status-detail) entry is older than `MCP_DISCOVERY_CACHE_TTL_S`, Claude Code refreshes it in the background. This variable sets how many refreshes in a row can fail before Claude Code discards the entry and connects the server at the next start instead (default: 1). Raise it if your network connection drops occasionally, so that one failed refresh doesn't discard the entry. Requires Claude Code v2.1.238 or later | -| `MCP_DISCOVERY_CACHE_TTL_S` | Seconds for which Claude Code uses a [discovery-cache](/docs/en/mcp#server-status-detail) entry without refreshing it (default: 900). At a start where the entry is older than that, Claude Code still uses it but refreshes it in the background. Once the entry is older than `MCP_DISCOVERY_CACHE_MAX_STALE_S`, Claude Code discards it instead. Claude Code caps the value at `MCP_DISCOVERY_CACHE_MAX_STALE_S`, which is 4 hours by default. Before v2.1.238, Claude Code didn't cap the value | -| `MCP_OAUTH_CALLBACK_PORT` | Fixed port for the OAuth redirect callback, as an alternative to `--callback-port` when adding an MCP server with [pre-configured credentials](/docs/en/mcp#use-pre-configured-oauth-credentials) | -| `MCP_PROTOCOL_NEGOTIATION` | On the [v2 MCP client runtime](/docs/en/mcp#mcp-client-runtimes) only, whether Claude Code probes servers for MCP protocol revision 2026-07-28. Set `auto` to probe HTTP, claude.ai connector, and stdio servers; a server that doesn't answer the probe connects on the earlier protocol instead, as SSE and WebSocket servers always do. Set `legacy` to skip the probe for every server. Without the variable, Claude Code probes HTTP and claude.ai connector servers on Claude Code v2.1.232 or later, with the exceptions the [MCP client runtimes](/docs/en/mcp#mcp-client-runtimes) section lists. Any other value is ignored with a warning in the debug log. Requires Claude Code v2.1.221 or later | -| `MCP_REMOTE_SERVER_CONNECTION_BATCH_SIZE` | Maximum number of remote MCP servers (HTTP/SSE) to connect in parallel during startup (default: 20) | -| `MCP_SDK_GENERATION` | Pin which [MCP client runtime](/docs/en/mcp#mcp-client-runtimes) this process connects to MCP servers with: `v1`, built on MCP TypeScript SDK 1.x, or `v2`, built on [MCP TypeScript SDK 2.0](https://ts.sdk.modelcontextprotocol.io/v2/). Without the variable, Claude Code uses v2 on Claude Code v2.1.232 or later, except where that section says it uses v1. On Claude Code v2.1.221 or later, the v2 runtime checks the issuer an MCP OAuth server returns in its authorization response and fails the sign-in with an error that begins `Issuer mismatch in authorization response` when it doesn't match. The v1 runtime doesn't run this check. If you set an unrecognized value, Claude Code ignores it and writes a warning to the debug log. Claude Code reads the value once per process. Requires Claude Code v2.1.218 or later | -| `MCP_SERVER_CONNECTION_BATCH_SIZE` | Maximum number of local MCP servers (stdio) to connect in parallel during startup (default: 3) | -| `MCP_TIMEOUT` | Timeout in milliseconds for MCP server startup (default: 30000, or 30 seconds) | -| `MCP_TOOL_TIMEOUT` | Timeout in milliseconds for MCP tool execution (default: 100000000, about 28 hours). For an HTTP, SSE, or claude.ai connector server, each request also times out after 60 seconds by default; set this variable, or the per-server `timeout`, above 60000 to raise that per-request limit. A lower value still shortens the overall tool-execution timeout but leaves the per-request limit at 60 seconds. Stdio and WebSocket servers have no per-request timer. A per-server `timeout` field in `.mcp.json` overrides this for that server. A per-server `timeout` of at least 1000 also sets the minimum idle window for that server's tool calls, so `CLAUDE_CODE_MCP_TOOL_IDLE_TIMEOUT` never aborts them sooner; this floor requires Claude Code v2.1.203 or later. For the env variable, values below 1000 are floored to one second; for the per-server field, values below 1000 are ignored | -| `NO_PROXY` | List of domains and IPs to which requests will be directly issued, bypassing proxy | -| `OTEL_ATTRIBUTE_VALUE_LENGTH_LIMIT` | Standard OpenTelemetry SDK limit on attribute value length. Claude Code caps content-bearing telemetry attributes at the smaller of this and `CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH`, so the truncation marker stays within the SDK limit. Claude Code reads the `OTEL_LOGRECORD_ATTRIBUTE_VALUE_LENGTH_LIMIT` and `OTEL_SPAN_ATTRIBUTE_VALUE_LENGTH_LIMIT` variants the same way, and the smallest set value applies to all signals. Requires Claude Code v2.1.214 or later. See [Monitoring](/docs/en/monitoring-usage#common-configuration-variables) | -| `OTEL_LOG_ASSISTANT_RESPONSES` | Set to `1` to include the model's response text on `assistant_response` OpenTelemetry log events. When unset, the value of `OTEL_LOG_USER_PROMPTS` is used instead. Set to `0` to keep responses redacted even when `OTEL_LOG_USER_PROMPTS` is set. Requires Claude Code v2.1.193 or later. See [Monitoring](/docs/en/monitoring-usage#assistant-response-event) | -| `OTEL_LOG_RAW_API_BODIES` | Emit Anthropic Messages API request and response JSON as `api_request_body` / `api_response_body` log events. Set to `1` for inline bodies truncated at the content limit, or `file:` to write untruncated bodies to disk and emit a `body_ref` path instead. `CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH` configures the content limit, 60 KB by default. Disabled by default; bodies include the entire conversation history. Set it in your shell, user settings, or managed settings. Ignored in [project and local settings](/docs/en/settings-reference#variables-claude-code-ignores-in-env). See [Monitoring](/docs/en/monitoring-usage#api-request-body-event) | -| `OTEL_LOG_TOOL_CONTENT` | Set to `1` to include tool input and output content in OpenTelemetry span events. Disabled by default to protect sensitive data. See [Monitoring](/docs/en/monitoring-usage) | -| `OTEL_LOG_TOOL_DETAILS` | Set to `1` to include tool input arguments, MCP server names, user-authored workflow names, raw error strings on tool failures, the refusal `category` on `api_refusal` events, and other tool details in OpenTelemetry traces and logs. Disabled by default to protect PII. See [Monitoring](/docs/en/monitoring-usage) | -| `OTEL_LOG_USER_PROMPTS` | Set to `1` to include user prompt text in OpenTelemetry traces and logs. Disabled by default (prompts are redacted). See [Monitoring](/docs/en/monitoring-usage) | -| `OTEL_METRICS_INCLUDE_ACCOUNT_UUID` | Set to `false` to exclude account UUID from metrics attributes (default: included). See [Monitoring](/docs/en/monitoring-usage) | -| `OTEL_METRICS_INCLUDE_ENTRYPOINT` | Set to `true` to include the session entrypoint in metrics attributes (default: excluded). Added in v2.1.152. See [Monitoring](/docs/en/monitoring-usage) | -| `OTEL_METRICS_INCLUDE_RESOURCE_ATTRIBUTES` | As of v2.1.161, Claude Code attaches `OTEL_RESOURCE_ATTRIBUTES` keys to metric datapoint labels. Set to `false` to exclude them (default: included). See [Monitoring](/docs/en/monitoring-usage#multi-team-organization-support) | -| `OTEL_METRICS_INCLUDE_SESSION_ID` | Set to `false` to exclude session ID from metrics attributes (default: included). See [Monitoring](/docs/en/monitoring-usage) | -| `OTEL_METRICS_INCLUDE_VERSION` | Set to `true` to include Claude Code version in metrics attributes (default: excluded). See [Monitoring](/docs/en/monitoring-usage) | -| `SLASH_COMMAND_TOOL_CHAR_BUDGET` | Override the character budget for skill metadata shown to the [Skill tool](/docs/en/skills#control-who-invokes-a-skill). The budget scales dynamically at 1% of the context window, with a fallback of 8,000 characters. Legacy name kept for backwards compatibility | -| `TASK_MAX_OUTPUT_LENGTH` | Maximum number of characters in [subagent](/docs/en/sub-agents) output before truncation (default: 32000, maximum: 160000). When truncated, the full output is saved to disk and the path is included in the truncated response | -| `USE_BUILTIN_RIPGREP` | Set to `0` to use system-installed `rg` instead of `rg` included with Claude Code | -| `VERTEX_REGION_CLAUDE_3_5_HAIKU` | Override region for Claude 3.5 Haiku when using Google Cloud's Agent Platform | -| `VERTEX_REGION_CLAUDE_3_5_SONNET` | Override region for Claude 3.5 Sonnet when using Google Cloud's Agent Platform | -| `VERTEX_REGION_CLAUDE_3_7_SONNET` | Override region for Claude 3.7 Sonnet when using Google Cloud's Agent Platform | -| `VERTEX_REGION_CLAUDE_4_0_OPUS` | Override region for Claude 4.0 Opus when using Google Cloud's Agent Platform | -| `VERTEX_REGION_CLAUDE_4_0_SONNET` | Override region for Claude 4.0 Sonnet when using Google Cloud's Agent Platform | -| `VERTEX_REGION_CLAUDE_4_1_OPUS` | Override region for Claude 4.1 Opus when using Google Cloud's Agent Platform | -| `VERTEX_REGION_CLAUDE_4_5_OPUS` | Override region for Claude Opus 4.5 when using Google Cloud's Agent Platform | -| `VERTEX_REGION_CLAUDE_4_5_SONNET` | Override region for Claude Sonnet 4.5 when using Google Cloud's Agent Platform | -| `VERTEX_REGION_CLAUDE_4_6_OPUS` | Override region for Claude Opus 4.6 when using Google Cloud's Agent Platform | -| `VERTEX_REGION_CLAUDE_4_6_SONNET` | Override region for Claude Sonnet 4.6 when using Google Cloud's Agent Platform | -| `VERTEX_REGION_CLAUDE_4_7_OPUS` | Override region for Claude Opus 4.7 when using Google Cloud's Agent Platform | -| `VERTEX_REGION_CLAUDE_4_8_OPUS` | Override region for Claude Opus 4.8 when using Google Cloud's Agent Platform. Added in v2.1.154 | -| `VERTEX_REGION_CLAUDE_5_OPUS` | Override region for Claude Opus 5 when using Google Cloud's Agent Platform. Added in v2.1.219 | -| `VERTEX_REGION_CLAUDE_5_SONNET` | Override region for Claude Sonnet 5 when using Google Cloud's Agent Platform. Added in v2.1.197 | -| `VERTEX_REGION_CLAUDE_FABLE_5` | Override region for Claude Fable 5 when using Google Cloud's Agent Platform. Added in v2.1.170 | -| `VERTEX_REGION_CLAUDE_FABLE_5_1` | Override region for Claude Fable 5.1 when using Google Cloud's Agent Platform. Added in v2.1.255 | -| `VERTEX_REGION_CLAUDE_HAIKU_4_5` | Override region for Claude Haiku 4.5 when using Google Cloud's Agent Platform | +| Variable | Purpose | +| :------------------------------------------------------ | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `ANTHROPIC_API_KEY` | API key sent as `X-Api-Key` header. When set, this key is used instead of your Claude Pro, Max, Team, or Enterprise subscription even if you are logged in. In non-interactive mode (`-p`), the key is always used when present. In interactive mode, you are prompted to approve the key once before it overrides your subscription. To use your subscription instead, run `unset ANTHROPIC_API_KEY` | +| `ANTHROPIC_AUTH_TOKEN` | Custom value for the `Authorization` header (the value you set here will be prefixed with `Bearer `) | +| `ANTHROPIC_AWS_API_KEY` | Workspace API key for [Claude Platform on AWS](/docs/en/claude-platform-on-aws), generated in the AWS Console. Sent as `x-api-key` and takes precedence over AWS SigV4 | +| `ANTHROPIC_AWS_BASE_URL` | Override the [Claude Platform on AWS](/docs/en/claude-platform-on-aws) endpoint URL. Use for custom regions or when routing through an [LLM gateway](/docs/en/llm-gateway). Defaults to `https://aws-external-anthropic.{region}.api.aws`. Claude Code resolves the region with the [same precedence as on Amazon Bedrock](/docs/en/amazon-bedrock#3-configure-claude-code) | +| `ANTHROPIC_AWS_WORKSPACE_ID` | Required for [Claude Platform on AWS](/docs/en/claude-platform-on-aws). Sent on every request as the `anthropic-workspace-id` header | +| `ANTHROPIC_BASE_URL` | Override the API endpoint to route requests through a proxy or gateway. When set to a non-first-party host, [MCP tool search](/docs/en/mcp#scale-with-mcp-tool-search) is disabled by default. Set `ENABLE_TOOL_SEARCH=true` if your proxy forwards `tool_reference` blocks. As of v2.1.196, [Remote Control](/docs/en/remote-control#requirements) is disabled when this points at a host other than `api.anthropic.com`, matching its behavior on Amazon Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry | +| `ANTHROPIC_BEDROCK_BASE_URL` | Override the Amazon Bedrock endpoint URL. Use for custom Amazon Bedrock endpoints or when routing through an [LLM gateway](/docs/en/llm-gateway). See [Amazon Bedrock](/docs/en/amazon-bedrock) | +| `ANTHROPIC_BEDROCK_MANTLE_BASE_URL` | Override the Amazon Bedrock Mantle endpoint URL. See [Mantle endpoint](/docs/en/amazon-bedrock#use-the-mantle-endpoint) | +| `ANTHROPIC_BEDROCK_REGION_PREFIX` | Cross-region inference profile prefix (`us`, `eu`, `apac`, `jp`, `au`, or `global`) Claude Code tries first instead of the one derived from the AWS region. Ignored in AWS GovCloud regions. Requires Claude Code v2.1.224 or later. See [Amazon Bedrock](/docs/en/amazon-bedrock#cross-region-inference-profile-prefixes) | +| `ANTHROPIC_BEDROCK_SERVICE_TIER` | Amazon Bedrock [service tier](https://docs.aws.amazon.com/bedrock/latest/userguide/service-tiers-inference.html) (`default`, `flex`, or `priority`). Sent as the `X-Amzn-Bedrock-Service-Tier` header. See [Amazon Bedrock](/docs/en/amazon-bedrock#service-tiers) | +| `ANTHROPIC_BETAS` | Comma-separated list of additional `anthropic-beta` header values to include in API requests. Claude Code already sends the beta headers it needs; use this to opt into an [Anthropic API beta](https://platform.claude.com/docs/en/api/beta-headers) before Claude Code adds native support. Unlike the [`--betas` flag](/docs/en/cli-reference#cli-flags), which requires API key authentication, this variable works with all auth methods including Claude.ai subscription | +| `ANTHROPIC_CUSTOM_HEADERS` | Custom headers to add to requests (`Name: Value` format, newline-separated for multiple headers). If a name or value contains a character an HTTP header can't carry, such as a curly quote or a zero-width space, the request fails with an error that identifies the pair by position. Requires Claude Code v2.1.227 or later. [Invalid request header value](/docs/en/errors#invalid-request-header-value) lists the exact character set and where the check runs. A value that sets a credential, org or tenant, routing, or API-behavior header, such as `Authorization` or `Host`, counts as a [setting that needs approval](/docs/en/server-managed-settings#environment-variables-and-the-approval-dialog) when server-managed settings deliver it. From project or local settings, such a value follows the [rules for when `env` values apply](/docs/en/settings-reference#when-claude-code-applies-env-values) | +| `ANTHROPIC_CUSTOM_MODEL_OPTION` | Model ID to add as a custom entry in the `/model` picker. Use this to make a non-standard or gateway-specific model selectable without replacing built-in aliases. See [Model configuration](/docs/en/model-config#add-a-custom-model-option) | +| `ANTHROPIC_CUSTOM_MODEL_OPTION_DESCRIPTION` | Display description for the custom model entry in the `/model` picker. Defaults to `Custom model ()` when not set | +| `ANTHROPIC_CUSTOM_MODEL_OPTION_NAME` | Display name for the custom model entry in the `/model` picker. Defaults to the model ID when not set | +| `ANTHROPIC_CUSTOM_MODEL_OPTION_SUPPORTED_CAPABILITIES` | Comma-separated list of [capabilities](/docs/en/model-config#customize-pinned-model-display-and-capabilities) the custom model supports, for example `effort,thinking`. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_DEFAULT_FABLE_MODEL` | Model ID that the `fable` alias resolves to, and the ID Claude Code recognizes as a Fable model for [automatic model fallback](/docs/en/model-config#automatic-model-fallback) on third-party providers. See [Model configuration](/docs/en/model-config#environment-variables) | +| `ANTHROPIC_DEFAULT_FABLE_MODEL_DESCRIPTION` | Display description for the pinned Fable model in the `/model` picker. Defaults to `Custom Fable model` when not set. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_DEFAULT_FABLE_MODEL_NAME` | Display name for the pinned Fable model in the `/model` picker. Defaults to the model ID when not set. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_DEFAULT_FABLE_MODEL_SUPPORTED_CAPABILITIES` | Comma-separated list of [capabilities](/docs/en/model-config#customize-pinned-model-display-and-capabilities) the pinned Fable model supports, for example `effort,thinking`. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_DEFAULT_HAIKU_MODEL` | Model ID that the `haiku` alias resolves to, also used for [background functionality](/docs/en/costs#background-token-usage). See [Model configuration](/docs/en/model-config#environment-variables) | +| `ANTHROPIC_DEFAULT_HAIKU_MODEL_DESCRIPTION` | Display description for the pinned Haiku model in the `/model` picker. Defaults to `Custom Haiku model` when not set. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_DEFAULT_HAIKU_MODEL_NAME` | Display name for the pinned Haiku model in the `/model` picker. Defaults to the model ID when not set. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_DEFAULT_HAIKU_MODEL_SUPPORTED_CAPABILITIES` | Comma-separated list of [capabilities](/docs/en/model-config#customize-pinned-model-display-and-capabilities) the pinned Haiku model supports, for example `effort,thinking`. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_DEFAULT_MODEL` | Model that new sessions start on by default. Requires Claude Code v2.1.236 or later. See [Set a default model for new sessions](/docs/en/model-config#set-a-default-model-for-new-sessions) | +| `ANTHROPIC_DEFAULT_OPUS_MODEL` | Model ID that the `opus` alias resolves to, and that `opusplan` uses while Plan Mode is active. See [Model configuration](/docs/en/model-config#environment-variables) | +| `ANTHROPIC_DEFAULT_OPUS_MODEL_DESCRIPTION` | Display description for the pinned Opus model in the `/model` picker. When not set, defaults to `Custom Opus model`, or `Custom Opus model (1M context)` if the pinned model ID has the `[1m]` suffix and `CLAUDE_CODE_DISABLE_1M_CONTEXT` isn't turned on. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_DEFAULT_OPUS_MODEL_NAME` | Display name for the pinned Opus model in the `/model` picker. Defaults to the model ID when not set. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_DEFAULT_OPUS_MODEL_SUPPORTED_CAPABILITIES` | Comma-separated list of [capabilities](/docs/en/model-config#customize-pinned-model-display-and-capabilities) the pinned Opus model supports, for example `effort,thinking`. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_DEFAULT_SONNET_MODEL` | Model ID that the `sonnet` alias resolves to, and that `opusplan` uses when Plan Mode is not active. See [Model configuration](/docs/en/model-config#environment-variables) | +| `ANTHROPIC_DEFAULT_SONNET_MODEL_DESCRIPTION` | Display description for the pinned Sonnet model in the `/model` picker. When not set, defaults to `Custom Sonnet model`, or `Custom Sonnet model (1M context)` if the pinned model ID has the `[1m]` suffix and `CLAUDE_CODE_DISABLE_1M_CONTEXT` isn't turned on. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_DEFAULT_SONNET_MODEL_NAME` | Display name for the pinned Sonnet model in the `/model` picker. Defaults to the model ID when not set. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_DEFAULT_SONNET_MODEL_SUPPORTED_CAPABILITIES` | Comma-separated list of [capabilities](/docs/en/model-config#customize-pinned-model-display-and-capabilities) the pinned Sonnet model supports, for example `effort,thinking`. See [Model configuration](/docs/en/model-config#customize-pinned-model-display-and-capabilities) | +| `ANTHROPIC_FEDERATION_RULE_ID` | Federation rule ID for [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation). When you set it together with `ANTHROPIC_ORGANIZATION_ID`, Claude Code selects federation credentials, which rank above your `/login` credential. See [authentication precedence](/docs/en/authentication#authentication-precedence) | +| `ANTHROPIC_FOUNDRY_API_KEY` | API key for Microsoft Foundry authentication (see [Microsoft Foundry](/docs/en/microsoft-foundry)) | +| `ANTHROPIC_FOUNDRY_AUTH_TOKEN` | Bearer token for Microsoft Foundry authentication, such as a Microsoft Entra access token. Claude Code sends it as the `Authorization: Bearer` header. Takes precedence over `ANTHROPIC_FOUNDRY_API_KEY` and over the Azure default credential chain. See [Microsoft Foundry](/docs/en/microsoft-foundry). Requires Claude Code v2.1.203 or later | +| `ANTHROPIC_FOUNDRY_BASE_URL` | Full base URL for the Microsoft Foundry resource (for example, `https://my-resource.services.ai.azure.com/anthropic`). Alternative to `ANTHROPIC_FOUNDRY_RESOURCE` (see [Microsoft Foundry](/docs/en/microsoft-foundry)) | +| `ANTHROPIC_FOUNDRY_RESOURCE` | Microsoft Foundry resource name (for example, `my-resource`). Required if `ANTHROPIC_FOUNDRY_BASE_URL` is not set (see [Microsoft Foundry](/docs/en/microsoft-foundry)) | +| `ANTHROPIC_MODEL` | Name of the model setting to use (see [Model Configuration](/docs/en/model-config#environment-variables)) | +| `ANTHROPIC_ORGANIZATION_ID` | Organization ID for [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation). Set it together with `ANTHROPIC_FEDERATION_RULE_ID`. See [authentication precedence](/docs/en/authentication#authentication-precedence) | +| `ANTHROPIC_PROFILE` | Name of the Anthropic profile to authenticate with, such as one created by [`ant auth login`](https://platform.claude.com/docs/en/cli-sdks-libraries/cli/authentication) or by [signing in to a Console account without an API key](/docs/en/authentication#sign-in-without-an-api-key). See [authentication precedence](/docs/en/authentication#authentication-precedence) | +| `ANTHROPIC_SMALL_FAST_MODEL` | \[DEPRECATED] Name of [Haiku-class model for background tasks](/docs/en/costs) | +| `ANTHROPIC_SMALL_FAST_MODEL_AWS_REGION` | Override AWS region for the Haiku-class model when using Amazon Bedrock or Amazon Bedrock Mantle. On Amazon Bedrock, this only takes effect when `ANTHROPIC_DEFAULT_HAIKU_MODEL` or the deprecated `ANTHROPIC_SMALL_FAST_MODEL` is also set, since Amazon Bedrock otherwise runs background tasks on the [default Sonnet model or the primary model](/docs/en/amazon-bedrock#4-pin-model-versions) in the session region | +| `ANTHROPIC_VERTEX_BASE_URL` | Override Google Cloud's Agent Platform endpoint URL. Use for custom Google Cloud's Agent Platform endpoints or when routing through an [LLM gateway](/docs/en/llm-gateway). See [Google Cloud's Agent Platform](/docs/en/google-vertex-ai) | +| `ANTHROPIC_VERTEX_PROJECT_ID` | GCP project ID for Google Cloud's Agent Platform requests. Overridden by `GCLOUD_PROJECT`, `GOOGLE_CLOUD_PROJECT`, or the project in your `GOOGLE_APPLICATION_CREDENTIALS` credential file. See [Google Cloud's Agent Platform](/docs/en/google-vertex-ai) | +| `ANTHROPIC_WORKSPACE_ID` | Workspace ID for [workload identity federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation). Set this when your federation rule is scoped to more than one workspace so the token exchange knows which workspace to target | +| `API_FORCE_IDLE_TIMEOUT` | Override the 5-minute body idle timeout that aborts a streaming model response when no bytes arrive. Set to `0` to turn the timeout off, for example when a slow [gateway](/docs/en/llm-gateway) or local model pauses longer than 5 minutes between chunks, or `1` to keep it on for every provider. When unset, the timeout is active on providers other than the direct Anthropic API and [Claude Platform on AWS](/docs/en/claude-platform-on-aws). The [stream watchdogs](/docs/en/network-config#streaming-idle-watchdogs) run independently of it and abort a long silent pause even when you set `0` here. Requires Claude Code v2.1.169 or later | +| `API_TIMEOUT_MS` | Timeout for API requests in milliseconds (default: 600000, or 10 minutes; maximum: 2147483647). Increase this when requests time out on slow networks or when routing through a proxy. Values above the maximum overflow the underlying timer and cause requests to fail immediately | +| `AWS_BEARER_TOKEN_BEDROCK` | Amazon Bedrock API key for authentication (see [Amazon Bedrock API keys](https://aws.amazon.com/blogs/machine-learning/accelerate-ai-development-with-amazon-bedrock-api-keys/)) | +| `BASH_DEFAULT_TIMEOUT_MS` | Default timeout for long-running bash commands (default: 120000, or 2 minutes) | +| `BASH_MAX_OUTPUT_LENGTH` | Maximum number of characters of bash output that Claude Code reads back into a command's result (default: 30000; maximum: 150000). If you set the [`bashOutputMaxChars`](/docs/en/settings-reference#bashoutputmaxchars) setting, Claude Code ignores this variable. See [Output limits](/docs/en/tools-reference#output-limits) | +| `BASH_MAX_TIMEOUT_MS` | Maximum timeout the model can set for long-running bash commands (default: 600000, or 10 minutes). The effective ceiling is the larger of this and `BASH_DEFAULT_TIMEOUT_MS` | +| `BETA_TRACING_ENDPOINT` | OTLP endpoint for [detailed beta tracing](/docs/en/monitoring-usage#traces-beta): with `ENABLE_BETA_TRACING_DETAILED=1`, logs and traces go there instead of to the configured exporters. Set it in your shell, user settings, or managed settings. Ignored in [project and local settings](/docs/en/settings-reference#variables-claude-code-ignores-in-env) | +| `CCR_FORCE_BUNDLE` | Set to `1` to force [`claude --cloud`](/docs/en/claude-code-on-the-web#send-local-repositories-without-github) to bundle and upload your local repository even when GitHub access is available | +| `CLAUDECODE` | Set to `1` in subprocesses Claude Code spawns (Bash and PowerShell tools, tmux sessions, [hook](/docs/en/hooks) commands, [status line](/docs/en/statusline) commands, stdio [MCP server](/docs/en/mcp) subprocesses). IDE extensions also set this in their integrated terminals. Use to detect when a script is running inside a subprocess spawned by Claude Code. To check whether the current process was spawned directly by a tool call or hook, rather than inside a stdio MCP server that Claude Code started, use `CLAUDE_CODE_CHILD_SESSION` instead | +| `CLAUDE_AFK_COUNTDOWN_MS` | How many milliseconds before auto-continue the on-screen countdown appears on an unanswered [`AskUserQuestion`](/docs/en/tools-reference) dialog. Default `20000` (20 seconds), capped at the auto-continue timeout. Has no effect unless auto-continue is on; see the [`askUserQuestionTimeout`](/docs/en/settings-reference#askuserquestiontimeout) setting and `CLAUDE_AFK_TIMEOUT_MS`. Requires Claude Code v2.1.198 or later | +| `CLAUDE_AFK_TIMEOUT_MS` | How many milliseconds of idle time before an unanswered [`AskUserQuestion`](/docs/en/tools-reference) dialog auto-continues without you. Auto-continue is off by default; opt in with the [`askUserQuestionTimeout`](/docs/en/settings-reference#askuserquestiontimeout) setting. This variable is an override for demos and automated tests: when set, it takes precedence over that setting and turns auto-continue on even when the setting is unset or `never`. Setting `0` doesn't turn the timeout off; it closes the dialog immediately. In v2.1.198 and v2.1.199, auto-continue was on by default with a `60000` (60 seconds) timeout. Requires Claude Code v2.1.198 or later | +| `CLAUDE_AGENT_SDK_DISABLE_BUILTIN_AGENTS` | Set to `1` to disable all built-in [subagent](/docs/en/sub-agents) types such as Explore and Plan. Only applies in non-interactive mode (the `-p` flag). Useful for SDK users who want a blank slate. This also removes `general-purpose`, the subagent Claude Code runs when an Agent tool call omits `subagent_type`. Such a call then fails with [`subagent_type is required`](/docs/en/errors#subagent-type-is-required) | +| `CLAUDE_AGENT_SDK_MCP_NO_PREFIX` | Set to `1` to skip the `mcp____` prefix on tool names from SDK-created MCP servers. Tools use their original names. SDK usage only | +| `CLAUDE_ASYNC_AGENT_STALL_TIMEOUT_MS` | Stall timeout in milliseconds for subagents. Default `600000` (10 minutes); if you raise `CLAUDE_STREAM_IDLE_TIMEOUT_MS` while the stream watchdog is on, the default rises with it, as [Handle slow or stalled API responses](/docs/en/agent-sdk/typescript#handle-slow-or-stalled-api-responses) describes. The timer resets on each streaming progress event; if no progress arrives within the window, Claude Code aborts the subagent and reports the stall to the parent | +| `CLAUDE_AUTOCOMPACT_PCT_OVERRIDE` | Set the percentage (1-100) of the auto-compact window at which auto-compaction triggers. Use lower values like `50` to compact earlier; the variable can't raise the threshold, so values above the default percentage are ignored. It applies only in sessions that [compact before the model's context limit](/docs/en/model-config#context-window-and-auto-compaction). Applies to both main conversations and subagents | +| `CLAUDE_AUTO_BACKGROUND_TASKS` | Set to `1` to force-enable automatic backgrounding of long-running agent tasks. When enabled, subagents are moved to the background after running for approximately two minutes. Also enables [automatic backgrounding of long MCP tool calls](/docs/en/mcp#automatic-backgrounding-of-long-tool-calls) in non-interactive mode on Claude Code v2.1.212 or later | +| `CLAUDE_AX_PREPARK_MS` | In [screen reader mode](/docs/en/accessibility#what-your-screen-reader-hears), how many milliseconds Claude Code waits, with the cursor at the start of the line, before it writes a new or changed line. Default `50`. Set `0` to write immediately. Claude Code caps the wait at `5000`. Requires Claude Code v2.1.233 or later | +| `CLAUDE_AX_SCREEN_READER` | Set to `1` to render screen-reader friendly output: flat text without decorative borders or animations. Set to `0` to force screen-reader mode off even when [`axScreenReader`](/docs/en/settings-reference#axscreenreader) is `true`. The [`--ax-screen-reader`](/docs/en/cli-reference#cli-flags) flag takes precedence. Requires Claude Code v2.1.181 or later | +| `CLAUDE_AX_STARTUP_QUIET_MS` | In [screen reader mode](/docs/en/accessibility), how many milliseconds Claude Code holds the first interface render after the startup confirmation line, so your screen reader can speak the line in full before new output interrupts it. Default `3000`. Set `0` to render immediately. Claude Code caps the hold at `600000` (10 minutes). Your first keystroke ends the hold early. Requires Claude Code v2.1.217 or later | +| `CLAUDE_BASH_MAINTAIN_PROJECT_WORKING_DIR` | Return to the original working directory after each Bash or PowerShell command in the main session | +| `CLAUDE_BYTE_STREAM_IDLE_TIMEOUT_MS` | Timeout in milliseconds for the byte-level streaming idle watchdog; when set, it takes precedence over `CLAUDE_STREAM_IDLE_TIMEOUT_MS` for that watchdog and leaves the event-level watchdog unchanged. Claude Code clamps this variable to between 10 seconds and 30 minutes. Requires Claude Code v2.1.210 or later | +| `CLAUDE_CLIENT_PRESENCE_FILE` | Path to a file that an external tool, such as a screen-lock listener, creates when you unlock your screen and deletes when you lock it. While the file exists, Claude Code skips [Remote Control mobile push notifications](/docs/en/remote-control#mobile-push-notifications), so you stop getting pushes while you are actively using the computer. When the file is absent or unreadable, notifications are sent as normal. Claude Code checks the file once per push-triggering event rather than polling it. Requires Claude Code v2.1.181 or later | +| `CLAUDE_CODE_ACCESSIBILITY` | Set to `1` to keep the native terminal cursor visible and disable the inverted-text cursor indicator. Allows screen magnifiers like macOS Zoom to track cursor position | +| `CLAUDE_CODE_ADDITIONAL_DIRECTORIES_CLAUDE_MD` | Set to `1` to load memory files from directories specified with `--add-dir`. Loads `CLAUDE.md`, `.claude/CLAUDE.md`, `.claude/rules/*.md`, and `CLAUDE.local.md`. By default, additional directories do not load memory files | +| `CLAUDE_CODE_ALT_SCREEN_FULL_REPAINT` | Set to `1` to repaint the entire screen on every frame in [fullscreen rendering](/docs/en/fullscreen) instead of sending incremental updates. Use this if fullscreen mode shows stale or misplaced text fragments. Claude Code enables this automatically for background sessions and [agent view](/docs/en/agent-view) on Windows | +| `CLAUDE_CODE_ALWAYS_ENABLE_EFFORT` | Set to `1` to send the [effort](/docs/en/model-config#adjust-effort-level) parameter with every request, even when Claude Code does not recognize the model ID as effort-capable. Use this when routing through an [LLM gateway](/docs/en/llm-gateway) or third-party provider that serves models under custom identifiers. Models that reject the effort parameter at the API, including Claude 3 models, Sonnet 4.0 and 4.5, Opus 4.0 and 4.1, and Haiku 4.5, are still excluded so requests do not fail | +| `CLAUDE_CODE_API_KEY_HELPER_TTL_MS` | Interval in milliseconds at which credentials should be refreshed (when using [`apiKeyHelper`](/docs/en/settings-reference#apikeyhelper)) | +| `CLAUDE_CODE_ARTIFACT_AUTO_OPEN` | Set to `0` to stop Claude Code from opening the browser automatically when a new [artifact](/docs/en/artifacts) is published. Republishing an existing artifact does not open the browser regardless of this setting | +| `CLAUDE_CODE_ARTIFACT_COMMENTS` | Set to `0` to stop Claude reading and replying to [comments on an artifact](/docs/en/artifacts#collect-comments-on-an-artifact). Has no effect when `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC` has [turned artifacts off](/docs/en/artifacts#availability). Requires Claude Code v2.1.221 or later | +| `CLAUDE_CODE_ARTIFACT_COMMENTS_AUTOREACT` | Set to `0` to stop Claude [replying on its own to comments sent to it](/docs/en/artifacts#let-claude-reply-to-comments-on-its-own). Requires Claude Code v2.1.228 or later | +| `CLAUDE_CODE_ATTRIBUTION_HEADER` | Set to `0` to omit the [attribution block](/docs/en/llm-gateway-protocol#system-prompt-attribution-block), which carries the client version and a prompt fingerprint, from the start of the system prompt. Caching on a direct connection to the Anthropic API is unaffected either way. In some direct-connection setups, Claude Code keeps the block on [auto mode](/docs/en/permission-modes#eliminate-prompts-with-auto-mode) classifier requests even when you set `0`. In [System prompt attribution block](/docs/en/llm-gateway-protocol#system-prompt-attribution-block), check which connections and credentials this covers. Before v2.1.181 the block included a per-request token on custom base URLs and Microsoft Foundry connections, so on those versions set it to `0` when your LLM gateway caches on the request body or forwards requests to a third-party provider, or when you connect to Microsoft Foundry directly | +| `CLAUDE_CODE_AUTO_BACKGROUND_WORKER_CHECKIN_SECONDS` | When `CLAUDE_AUTO_BACKGROUND_TASKS` is enabled, seconds between reminders to Claude to check on [background subagents](/docs/en/sub-agents#run-subagents-in-foreground-or-background) that are still running. Accepts a plain integer from `1` to `86400` only; any other value or spelling reads as unset. When unset, there are no check-in reminders. Requires Claude Code v2.1.248 or later | +| `CLAUDE_CODE_AUTO_COMPACT_WINDOW` | Set the [auto-compact window](/docs/en/model-config#set-the-auto-compact-window) in tokens, from `100000` to `1000000`. Accepts a plain integer such as `500000` only: a value like `500k` reads as `500` and clamps to the 100K minimum. The effective window is also capped at the model's context window. Takes precedence over the `/autocompact` command, the `--autocompact` flag, and the `autoCompactWindow` setting. The status line's `used_percentage` always measures against the model's full context window, so once this variable is set, that percentage no longer indicates when compaction will run | +| `CLAUDE_CODE_AUTO_CONNECT_IDE` | Override automatic [IDE connection](/docs/en/vs-code). By default, Claude Code connects automatically when launched inside a supported IDE's integrated terminal. Set to `false` to prevent this. Set to `true` to force a connection attempt when auto-detection fails, such as when tmux obscures the parent terminal. Takes precedence over the [`autoConnectIde`](/docs/en/settings-reference#autoconnectide) global config setting | +| `CLAUDE_CODE_AWS_CHAIN_RESOLVE_TIMEOUT_MS` | Time in milliseconds Claude Code waits for the AWS default credential provider chain to produce credentials before the request fails with [`AWS default-chain credential resolve timed out`](/docs/en/errors#aws-default-chain-credential-resolve-timed-out) (default: `60000`). Raise it when a step in your chain legitimately needs longer, such as a browser-based SSO sign-in with MFA through a wrapper like `aws-vault`. Applies wherever Claude Code signs with the default chain: [Amazon Bedrock](/docs/en/amazon-bedrock#credential-caching-and-resolution-timeout), [Claude Platform on AWS](/docs/en/claude-platform-on-aws), and the [Mantle endpoint](/docs/en/amazon-bedrock#use-the-mantle-endpoint). Requires Claude Code v2.1.207 or later | +| `CLAUDE_CODE_BRIDGE_SESSION_ID` | Set automatically in Bash tool and [hook command](/docs/en/hooks) subprocesses while the session has an active [Remote Control](/docs/en/remote-control) connection, and removed when the connection ends. The value is the session's ID in `session_` form, the same identifier that appears in the session's `claude.ai/code` URL, so a script can link back to the session that ran it. Requires Claude Code v2.1.199 or later. In [cloud sessions](/docs/en/claude-code-on-the-web), read `CLAUDE_CODE_REMOTE_SESSION_ID` instead | +| `CLAUDE_CODE_BS_AS_CTRL_BACKSPACE` | Set to `0` to make Claude Code read the `0x08` byte, also written `^H`, as plain Backspace, or `1` to read it as Ctrl+Backspace. Either value replaces the platform default. By default, Claude Code reads it as Ctrl+Backspace on Windows, except when `TERM_PROGRAM` is `mintty` or `TERM` is `cygwin`, and as plain Backspace on macOS and Linux. Set `0` in a Windows terminal where [Backspace deletes a whole word](/docs/en/terminal-config#fix-backspace-deleting-a-whole-word-on-windows) | +| `CLAUDE_CODE_CERT_STORE` | Comma-separated list of CA certificate sources for TLS connections. `bundled` is the Mozilla CA set shipped with Claude Code. `system` is the operating system trust store, read only on runtimes with `tls.getCACertificates`: the native binary, or Node 22.15 or later for npm installs. See [CA certificate store](/docs/en/network-config#ca-certificate-store). Default is `bundled,system` | +| `CLAUDE_CODE_CHILD_SESSION` | Set to `1` in subprocesses Claude Code spawns via the Bash, PowerShell, and Monitor tools, [hook](/docs/en/hooks) commands, and [status line](/docs/en/statusline) commands. Not set for stdio [MCP server](/docs/en/mcp) subprocesses, which are long-lived and outlive the session that spawned them. Unlike `CLAUDECODE`, this is only set by Claude Code itself when it launches a subprocess and not by IDE extensions, so it reliably distinguishes a nested session from a top-level `claude` launched in an IDE-integrated terminal. A nested interactive `claude` TUI started this way is automatically excluded from `--resume`, `--continue`, up-arrow history, and the `claude agents` list. Non-interactive `claude -p` sessions still persist. Set `CLAUDE_CODE_FORCE_SESSION_PERSISTENCE=1` to override this exclusion. Requires Claude Code v2.1.172 or later | +| `CLAUDE_CODE_CLIENT_CERT` | Path to client certificate file for mTLS authentication | +| `CLAUDE_CODE_CLIENT_KEY` | Path to client private key file for mTLS authentication | +| `CLAUDE_CODE_CLIENT_KEY_PASSPHRASE` | Passphrase for encrypted CLAUDE\_CODE\_CLIENT\_KEY (optional) | +| `CLAUDE_CODE_CONNECT_TIMEOUT_MS` | Removed in v2.1.186 and now a no-op. Previously set a separate timeout for the connect, TLS, and response-header phase of a streaming API request. Use `API_TIMEOUT_MS` for the per-request timeout. For the response-header phase of a streaming request, see `CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS` | +| `CLAUDE_CODE_DEBUG_LOGS_DIR` | Override the debug log file path. Despite the name, this is a file path, not a directory. Requires debug mode to be enabled separately via `--debug`, `/debug`, or the `DEBUG` environment variable: setting this variable alone does not enable logging. The [`--debug-file`](/docs/en/cli-reference#cli-flags) flag does both at once. Defaults to `~/.claude/debug/.txt` | +| `CLAUDE_CODE_DEBUG_LOG_LEVEL` | Minimum log level written to the debug log file. Values: `verbose`, `debug` (default), `info`, `warn`, `error`. Set to `verbose` to include high-volume diagnostics like full status line command output, or raise to `error` to reduce noise | +| `CLAUDE_CODE_DISABLE_1M_CONTEXT` | Set to `1` to disable [1M context window](/docs/en/model-config#extended-context) support. When set, 1M model variants are unavailable in the model picker, and Claude Code holds sessions on models with a native 1M window, such as [Sonnet 5](/docs/en/model-config#sonnet-5-context-window) and the Fable models, to a 200K window; see [Extended context](/docs/en/model-config#extended-context) for how the hold is enforced. Useful for enterprise environments with compliance requirements. For its role in correcting the window for an unrecognized `[1m]` model ID, see [Correct the window for a gateway or custom model ID](/docs/en/model-config#correct-the-window-for-a-gateway-or-custom-model-id) | +| `CLAUDE_CODE_DISABLE_ADAPTIVE_THINKING` | Set to `1` to disable [adaptive reasoning](/docs/en/model-config#adjust-effort-level) on Opus 4.6 and Sonnet 4.6 and fall back to the fixed thinking budget controlled by `MAX_THINKING_TOKENS`. Has no effect on [Fable models](/docs/en/model-config#extended-thinking), Sonnet 5, or Opus 4.7 and later, which always use adaptive reasoning | +| `CLAUDE_CODE_DISABLE_ADMIN_ENV_UNION` | Set to `1` to stop Claude Code from merging [managed settings](/docs/en/managed-settings#precedence-within-the-managed-tier) `env` blocks per key across admin sources, so only the highest-priority source's whole `env` block applies, as before v2.1.223. Set it in the environment that launches Claude Code, since Claude Code ignores a copy delivered through a settings `env` block. Requires Claude Code v2.1.223 or later | +| `CLAUDE_CODE_DISABLE_ADVISOR_TOOL` | Set to `1` to disable the [advisor tool](/docs/en/advisor). The `/advisor` command becomes unavailable, any configured `advisorModel` is ignored, and the `--advisor` flag is accepted but has no effect, so existing scripts that pass it continue to work without errors | +| `CLAUDE_CODE_DISABLE_AGENT_VIEW` | Set to `1` to turn off [background agents and agent view](/docs/en/agent-view): `claude agents`, `--bg`, `/background`, and the on-demand supervisor. Equivalent to the [`disableAgentView`](/docs/en/settings-reference#disableagentview) setting | +| `CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN` | Set to `1` to disable [fullscreen rendering](/docs/en/fullscreen) and use the classic main-screen renderer. The conversation stays in your terminal's native scrollback so `Cmd+f` and tmux copy mode work as usual. Takes precedence over `CLAUDE_CODE_NO_FLICKER` and the [`tui`](/docs/en/settings-reference#tui) setting. You can also switch with `/tui default`. Does not apply to background sessions opened from [agent view](/docs/en/agent-view), which always use fullscreen rendering | +| `CLAUDE_CODE_DISABLE_ARTIFACT` | Set to `1` to turn off the [Artifact](/docs/en/artifacts) tool, which publishes session output as a private web page on claude.ai. Once you set it, no settings file turns the tool back on. To turn the tool off from a settings file instead, set [`enableArtifact`](/docs/en/settings-reference#enableartifact) to `false`; the deprecated [`disableArtifact`](/docs/en/settings-reference#disableartifact) key also turns it off | +| `CLAUDE_CODE_DISABLE_ATTACHMENTS` | Set to `1` to disable attachment processing. File mentions with `@` syntax are sent as plain text instead of being expanded into file content | +| `CLAUDE_CODE_DISABLE_AUTO_MEMORY` | Set to `1` to disable [auto memory](/docs/en/memory#auto-memory). Set to `0` to force auto memory on even when `--bare` mode or [`autoMemoryEnabled: false`](/docs/en/settings-reference#automemoryenabled) would otherwise disable it. When disabled, Claude does not create or load auto memory files | +| `CLAUDE_CODE_DISABLE_BACKGROUND_TASKS` | Set to `1` to disable all background task functionality, including the `run_in_background` parameter on Bash and subagent tools, auto-backgrounding, and the Ctrl+B shortcut | +| `CLAUDE_CODE_DISABLE_BEDROCK_CONTENT_TYPE_DEFAULT` | Set to `1` to stop Claude Code from treating an [Amazon Bedrock](/docs/en/amazon-bedrock) streaming response with a missing or empty `Content-Type` header as Amazon Bedrock's binary event stream. By default, Claude Code assumes a gateway dropped the header from an otherwise unmodified response, so it decodes the body and streaming keeps working. Set this only for a gateway that also re-emits the stream as server-sent events; Claude Code then reads the header-less body as server-sent events instead. Requires Claude Code v2.1.239 or later | +| `CLAUDE_CODE_DISABLE_BEDROCK_CONTENT_TYPE_GUARD` | Set to `1` to skip the check that an [Amazon Bedrock](/docs/en/amazon-bedrock) streaming response carries the `application/vnd.amazon.eventstream` content-type. Without this variable, when a response carries a different content-type, Claude Code fails the request with an error naming that type, which means a [gateway or proxy is transforming the response](/docs/en/amazon-bedrock#streaming-errors-behind-a-gateway-or-proxy). Configure the gateway to forward the `Content-Type` header and body unmodified rather than setting this variable. Requires Claude Code v2.1.208 or later | +| `CLAUDE_CODE_DISABLE_BG_EXIT_HANDOFF` | Set to `1` to stop a [background session's](/docs/en/agent-view) running background shell commands, dynamic workflows, and, as of v2.1.198, background subagents when the [supervisor](/docs/en/agent-view#the-supervisor-process) stops, restarts, or updates that session's process, instead of handing them to the session's next process. Affects only that handoff: backgrounding a session with `←` or [`/background`](/docs/en/agent-view#from-inside-a-session) still carries in-flight work over, and `CLAUDE_DISABLE_ADOPT` turns off both. Requires Claude Code v2.1.196 or later | +| `CLAUDE_CODE_DISABLE_BG_SHELL_PRESSURE_REAP` | Set to `1` to stop Claude Code from terminating [background shell commands](/docs/en/interactive-mode#background-bash-commands) when the operating system reports memory pressure. By default, on macOS and Linux, Claude Code terminates a background shell started in the main session on a memory-pressure signal once the session has been idle for 30 minutes and no turn or subagent is running. Windows has no memory-pressure signal, so this variable has no effect there. Requires Claude Code v2.1.193 or later | +| `CLAUDE_CODE_DISABLE_BUNDLED_SKILLS` | Set to `1` to disable the [skills](/docs/en/skills) and workflows included with Claude Code: bundled skills and workflows are removed entirely, while built-in commands like `/init` stay typable but are hidden from the model. `/doctor` stays typable like the built-in commands; hide it with `DISABLE_DOCTOR_COMMAND` instead. Skills from plugins, `.claude/skills/`, and `.claude/commands/` are unaffected. Equivalent to the [`disableBundledSkills`](/docs/en/settings-reference#disablebundledskills) setting | +| `CLAUDE_CODE_DISABLE_CFC_PROMPT` | Set to `1` to keep the [Claude in Chrome](/docs/en/chrome) browser tools available while omitting the Chrome section of the system prompt and the `/claude-in-chrome` [bundled skill](/docs/en/skills#bundled-skills). For hosts that embed Claude Code and supply their own browser guidance. Requires Claude Code v2.1.257 or later | +| `CLAUDE_CODE_DISABLE_CLAUDE_MDS` | Set to `1` to prevent loading any CLAUDE.md memory files into context, including user, project, and auto memory files | +| `CLAUDE_CODE_DISABLE_CRON` | Set to `1` to disable [scheduled tasks](/docs/en/scheduled-tasks). The `/loop` skill and cron tools become unavailable and any already-scheduled tasks stop firing, including tasks that are already running mid-session | +| `CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS` | Set to `1` to strip Anthropic-specific `anthropic-beta` request headers and beta tool-schema fields (such as `defer_loading` and `eager_input_streaming`) from API requests. Use this when a proxy gateway rejects requests with errors like "Unexpected value(s) for the `anthropic-beta` header" or "Extra inputs are not permitted". Standard fields (`name`, `description`, `input_schema`, `cache_control`) are preserved. [MCP tool search](/docs/en/mcp#scale-with-mcp-tool-search) is disabled and all MCP tools load upfront, even when you set `ENABLE_TOOL_SEARCH`. On Claude Code v2.1.227 or later, [managed settings](/docs/en/managed-settings) can keep tool search on. [Disable pre-release capabilities](/docs/en/llm-gateway-protocol#disable-pre-release-capabilities) covers where the override applies | +| `CLAUDE_CODE_DISABLE_EXPLORE_PLAN_AGENTS` | Set to `1` to disable the built-in [Explore and Plan subagents](/docs/en/sub-agents#built-in-subagents). Claude explores with its search tools or the general-purpose subagent instead, and [plan mode](/docs/en/permission-modes#analyze-before-you-edit-with-plan-mode) reads files directly rather than launching Explore and Plan agents. Custom subagents named `Explore` or `Plan` are unaffected. To remove every built-in subagent type in the Agent SDK or non-interactive mode, use `CLAUDE_AGENT_SDK_DISABLE_BUILTIN_AGENTS` instead. Requires Claude Code v2.1.198 or later | +| `CLAUDE_CODE_DISABLE_FAST_MODE` | Set to `1` to disable [fast mode](/docs/en/fast-mode) | +| `CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY` | Set to `1` to disable the "How is Claude doing?" session quality surveys. Surveys are also disabled when `DISABLE_TELEMETRY`, `DO_NOT_TRACK`, or `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC` is set, unless `CLAUDE_CODE_ENABLE_FEEDBACK_SURVEY_FOR_OTEL` opts back in. To set a sample rate instead of disabling outright, use the [`feedbackSurveyRate`](/docs/en/settings-reference#feedbacksurveyrate) setting. See [Session quality surveys](/docs/en/data-usage#session-quality-surveys) | +| `CLAUDE_CODE_DISABLE_FILE_CHECKPOINTING` | Set to `1` to disable file [checkpointing](/docs/en/checkpointing). The `/rewind` command will not be able to restore code changes. Overrides the [`fileCheckpointingEnabled`](/docs/en/settings-reference#filecheckpointingenabled) setting | +| `CLAUDE_CODE_DISABLE_GIT_INSTRUCTIONS` | Set to `1` to remove built-in commit and PR workflow instructions and the git status snapshot from Claude's system prompt. Useful when using your own git workflow skills. Takes precedence over the [`includeGitInstructions`](/docs/en/settings-reference#includegitinstructions) setting when set | +| `CLAUDE_CODE_DISABLE_LEGACY_MODEL_REMAP` | Set to `1` to prevent automatic remapping of Opus 4.0 and 4.1 to the current Opus version on the Anthropic API. Use when you intentionally want to pin an older model. The remap does not run on Amazon Bedrock, Google Cloud's Agent Platform, or Microsoft Foundry | +| `CLAUDE_CODE_DISABLE_MOUSE` | Set to `1` to disable mouse tracking in [fullscreen rendering](/docs/en/fullscreen). Keyboard scrolling with `PgUp` and `PgDn` still works. Use this to keep your terminal's native copy-on-select behavior | +| `CLAUDE_CODE_DISABLE_MOUSE_CLICKS` | Set to `1` to disable click, drag, and hover handling in [fullscreen rendering](/docs/en/fullscreen) while keeping mouse-wheel scrolling. Use this when you want wheel scroll to work inside Claude Code but don't want clicks to position the cursor, expand tool output, or open links. `CLAUDE_CODE_DISABLE_MOUSE` takes precedence when both are set. Requires Claude Code v2.1.195 or later | +| `CLAUDE_CODE_DISABLE_MTLS_RELOAD_ON_STALE_CONNECTION` | Set to `1` to stop Claude Code from re-reading the [mTLS client certificate and key](/docs/en/network-config#mtls-authentication) when an API request fails with a connection-level error, such as a connection reset or a TLS handshake error. With the reload disabled, Claude Code loads rotated files only when it next applies settings or at the next startup. Requires Claude Code v2.1.232 or later | +| `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC` | Set to any non-empty value, such as `1`, to disable nonessential network traffic: auto-updates, telemetry, error reporting, the `/feedback` command, [Claude-drafted feedback](/docs/en/tools-reference#sendfeedback-tool-behavior), release notes, the [PR and MR status badge](/docs/en/interactive-mode#pr-review-status) checks, and availability checks such as the [fast mode](/docs/en/fast-mode#use-fast-mode-behind-proxies-and-llm-gateways) check. It also stops the [background runs of plugin `command` sources](/docs/en/plugin-marketplaces#when-claude-code-re-runs-the-command), which are local commands rather than network traffic, because they can trigger dependency installs. **Setting it to `0` or `false` still disables this traffic**, unlike most on/off variables; unset the variable to allow it again. Also disables feature-flag fetching, which makes [Remote Control](/docs/en/remote-control#requirements) and the other [features that need feature-flag fetching](#features-that-need-feature-flag-fetching) unavailable. Official plugin marketplace auto-install isn't covered; disable it with `CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL`. Doesn't affect [gateway model discovery](/docs/en/llm-gateway-connect#add-gateway-models-to-the-model-picker), which has its own opt-in | +| `CLAUDE_CODE_DISABLE_NONSTREAMING_FALLBACK` | Set to `1` to disable the non-streaming fallback when a streaming request fails mid-stream. Streaming errors propagate to the retry layer instead. Useful when a proxy or gateway causes the fallback to produce duplicate tool execution | +| `CLAUDE_CODE_DISABLE_NOTIFICATION_PRESENCE_CHECK` | Set to `1` to send the `PushNotification` tool's desktop notification even while you are typing in or focused on the terminal. By default the tool skips both the desktop notification and the [mobile push](/docs/en/remote-control#mobile-push-notifications) when it detects recent keyboard activity or terminal focus. This variable disables only that local check, so the server can still suppress the mobile push when it detects that you are active. Requires Claude Code v2.1.193 or later | +| `CLAUDE_CODE_DISABLE_OFFICIAL_MARKETPLACE_AUTOINSTALL` | Set to `1` to disable automatic registration of the official plugin marketplace. Claude Code reads the variable when it is about to register the marketplace, usually during a machine's first interactive launch. If the variable is set at that point, Claude Code skips the registration permanently. Unsetting the variable later doesn't undo the skip. Run `claude plugin marketplace add anthropics/claude-plugins-official` to register the marketplace at any time | +| `CLAUDE_CODE_DISABLE_PERMISSION_PROMPT_NOTIFY_HOOKS` | Set to `1` to stop Claude Code from running your [`Notification` hooks for unanswered permission requests](/docs/en/hooks#notification) in sessions where Claude Code sends them to the Agent SDK's `canUseTool` callback, which is how Claude Desktop and the VS Code extension host Claude Code. Has no effect in terminal sessions. Requires Claude Code v2.1.233 or later | +| `CLAUDE_CODE_DISABLE_POLICY_SKILLS` | Set to `1` to skip loading skills from the system-wide managed skills directory. Useful for container or CI sessions that should not load operator-provisioned skills | +| `CLAUDE_CODE_DISABLE_TERMINAL_TITLE` | Set to `1` to disable automatic terminal title updates based on conversation context. In Agent SDK and `claude -p` sessions, this also skips the background small/fast-model request that generates the session title | +| `CLAUDE_CODE_DISABLE_THINKING` | Set to `1` to omit the `thinking` parameter from API requests entirely. This is a compatibility option for proxies and gateways that reject the parameter. The variable's behavior is unchanged from earlier versions; on models that think by default, omitting the parameter means the model may still think. To explicitly disable [extended thinking](https://platform.claude.com/docs/en/build-with-claude/extended-thinking) on the Anthropic API, use `MAX_THINKING_TOKENS=0` instead, which is also ineffective on [Fable models](/docs/en/model-config#extended-thinking) since they can't have thinking turned off. On [third-party providers](/docs/en/third-party-integrations), `0` likewise omits the parameter, so the two variables behave the same there | +| `CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT` | Set to `1` to skip proactive [auto-compaction](/docs/en/costs#reduce-token-usage) when Claude Code doesn't recognize the model ID, such as an [LLM gateway](/docs/en/llm-gateway) alias. Without this variable, Claude Code compacts at the context window it assumes for the ID. `CLAUDE_CODE_MAX_CONTEXT_TOKENS` can correct the assumed window instead; see [Correct the window for a gateway or custom model ID](/docs/en/model-config#correct-the-window-for-a-gateway-or-custom-model-id) for when each variable applies. Requires Claude Code v2.1.223 or later | +| `CLAUDE_CODE_DISABLE_VIRTUAL_SCROLL` | Set to `1` to disable virtual scrolling in [fullscreen rendering](/docs/en/fullscreen) and render every message in the transcript. Use this if scrolling in fullscreen mode shows blank regions where messages should appear | +| `CLAUDE_CODE_DISABLE_WORKFLOWS` | Set to `1` to disable [workflows](/docs/en/workflows#turn-workflows-off). Equivalent to the [`disableWorkflows`](/docs/en/settings-reference#disableworkflows) setting | +| `CLAUDE_CODE_EFFORT_LEVEL` | Set the effort level for supported models. Values: `low`, `medium`, `high`, `xhigh`, `max`, or `auto` to use the model default. Available levels depend on the model. Takes precedence over `--effort`, `/effort`, and the `modelSettings` and `effortLevel` settings. See [Adjust effort level](/docs/en/model-config#adjust-effort-level) | +| `CLAUDE_CODE_ENABLE_APPEND_SUBAGENT_PROMPT` | Set to `1` to enable appending extra text to the end of the system prompt of every [subagent](/docs/en/sub-agents) other than a [forked subagent](/docs/en/sub-agents#fork-the-current-conversation). The [`--append-subagent-system-prompt`](/docs/en/cli-reference#cli-flags) flag supplies the appended text and sets this variable automatically, so you don't need to set it yourself. Requires Claude Code v2.1.205 or later | +| `CLAUDE_CODE_ENABLE_AUTO_MODE` | Accepted for compatibility with older releases and has no effect. Auto mode is available by default on every provider, including Amazon Bedrock, Google Cloud's Agent Platform, Microsoft Foundry, and signed-in [Claude apps gateway](/docs/en/claude-apps-gateway) sessions. In v2.1.158 through v2.1.206, setting this to `1` was required to make [auto mode](/docs/en/permission-modes#eliminate-prompts-with-auto-mode) available on those providers | +| `CLAUDE_CODE_ENABLE_AWAY_SUMMARY` | Override [session recap](/docs/en/interactive-mode#session-recap) availability. Set to `0` to force recaps off regardless of the `/config` toggle. Set to `1` to force recaps on when [`awaySummaryEnabled`](/docs/en/settings-reference#awaysummaryenabled) is `false`. Takes precedence over the setting and `/config` toggle | +| `CLAUDE_CODE_ENABLE_BACKGROUND_PLUGIN_REFRESH` | Set to `1` to refresh plugin state at turn boundaries in [non-interactive mode](/docs/en/headless) after a background install completes. Off by default because the refresh changes the system prompt mid-session, which invalidates [prompt caching](/docs/en/prompt-caching) for that turn | +| `CLAUDE_CODE_ENABLE_FEEDBACK_SURVEY_FOR_OTEL` | Set to `1` to route the "How is Claude doing?" session quality survey to your own [OpenTelemetry collector](/docs/en/monitoring-usage) when Anthropic-bound nonessential traffic is blocked. Survey ratings are emitted only as OTEL events to your configured collector. No survey data is sent to Anthropic in this mode. Applies when `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC`, `DISABLE_TELEMETRY`, or `DO_NOT_TRACK` is set, and has no effect otherwise. `CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY` and the organization product feedback policy take precedence | +| `CLAUDE_CODE_ENABLE_FINE_GRAINED_TOOL_STREAMING` | Controls whether tool call inputs stream from the API as Claude generates them. With this off, a large tool input such as a long file write arrives only after Claude finishes generating it, which can look like it's hanging. Enabled by default on the Anthropic API. On Amazon Bedrock and Google Cloud's Agent Platform, enabled per model where the deployed container supports it. Set to `0` to opt out. Set to `1` to force on when routing through a proxy via `ANTHROPIC_BASE_URL`, `ANTHROPIC_VERTEX_BASE_URL`, or `ANTHROPIC_BEDROCK_BASE_URL`. Off by default on Microsoft Foundry and [gateway](/docs/en/llm-gateway) connections | +| `CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY` | Set to `1` to populate the `/model` picker from your gateway's `/v1/models` endpoint when `ANTHROPIC_BASE_URL` points at an Anthropic-compatible gateway such as LiteLLM, Kong, or an internal proxy. Off by default because gateways backed by a shared API key would otherwise show every user every model the key can access. Discovered models are still filtered by an [`availableModels`](/docs/en/settings-reference#availablemodels) allowlist the session receives; deliver the list through [MDM or a managed settings file](/docs/en/managed-settings#delivery-mechanisms), since [server-managed delivery is not available on gateway configurations](/docs/en/server-managed-settings#platform-availability) | +| `CLAUDE_CODE_ENABLE_OPUS_4_7_FAST_MODE` | Removed in v2.1.142, when the [fast mode](/docs/en/fast-mode) default moved from Opus 4.6 to Opus 4.7 | +| `CLAUDE_CODE_ENABLE_PROMPT_SUGGESTION` | Set to `false` to turn off prompt suggestions, the grayed-out predictions that appear in your prompt input. Takes precedence over the [`promptSuggestionEnabled`](/docs/en/settings-reference#promptsuggestionenabled) setting, which is what the **Prompt suggestions** toggle in `/config` writes. Claude Code also [pauses suggestions while your account is close to or at its usage limit](/docs/en/interactive-mode#when-claude-code-skips-suggestions). Set to `true` to keep them on until you reach the limit. Requires Claude Code v2.1.238 or later. See [Prompt suggestions](/docs/en/interactive-mode#prompt-suggestions) | +| `CLAUDE_CODE_ENABLE_TASKS` | Selects which task-tracking tools Claude Code provides in [sessions that have them](/docs/en/tools-reference#task-tool-availability). By default, Claude Code provides the Task tools `TaskCreate`, `TaskUpdate`, `TaskGet`, and `TaskList`. Set to `0` to get the legacy `TodoWrite` tool instead. See [Task list](/docs/en/interactive-mode#task-list) | +| `CLAUDE_CODE_ENABLE_TELEMETRY` | Set to `1` to enable OpenTelemetry data collection for metrics and logging. Required before configuring OTel exporters. See [Monitoring](/docs/en/monitoring-usage) | +| `CLAUDE_CODE_ENABLE_TODO_TOOLS` | Set to `1` to get the task-tracking tools on the models listed under [Task tool availability](/docs/en/tools-reference#task-tool-availability), where Claude Code otherwise leaves them out. `CLAUDE_CODE_ENABLE_TASKS` still selects the Task tools or `TodoWrite`. Requires Claude Code v2.1.233 or later | +| `CLAUDE_CODE_EXIT_AFTER_STOP_DELAY` | Time in milliseconds to wait after the query loop becomes idle before automatically exiting. Useful for automated workflows and scripts using SDK mode | +| `CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS` | Set to `1` to enable [agent teams](/docs/en/agent-teams). Agent teams are experimental and disabled by default | +| `CLAUDE_CODE_EXTRA_BODY` | JSON object to merge into the top level of every API request body. Useful for passing provider-specific parameters that Claude Code doesn't expose directly. A value exported in your shell also applies to the [background sessions](/docs/en/agent-view) you dispatch with `claude agents` or `--bg`. Before v2.1.206, background sessions ignored a shell-exported value and used whatever copy the background supervisor process inherited | +| `CLAUDE_CODE_FILE_READ_MAX_OUTPUT_TOKENS` | Override the default token limit for file reads. Useful when you need to read larger files in full | +| `CLAUDE_CODE_FORCE_SESSION_PERSISTENCE` | Set to `1` to force transcript persistence, prompt history, and `claude agents` registration even when this `claude` was launched from inside another Claude Code session. Use when an inherited `CLAUDE_CODE_CHILD_SESSION` value, for example from a `screen` session or a background launcher first started by Claude Code's Bash tool, causes a genuine top-level session to be misclassified as nested. As of v2.1.178, Claude Code detects the tmux case automatically and ignores the inherited marker, so tmux no longer needs this variable. Also honored on v2.1.169 and earlier; has no effect on v2.1.170 and v2.1.171, where the nested-session detection it overrides was removed | +| `CLAUDE_CODE_FORCE_STRIKETHROUGH` | Set to `1` to force strikethrough rendering for `~~text~~` in Claude's responses when your terminal supports it but is not auto-detected, such as over SSH without `TERM_PROGRAM` forwarded. Without this, undetected terminals show the literal `~~` markers instead of rendering the text as strikethrough. Requires Claude Code v2.1.186 or later | +| `CLAUDE_CODE_FORCE_SYNC_OUTPUT` | Set to `1` to force-enable DEC private mode 2026 [synchronized output](https://gist.github.com/christianparpart/d8a62cc1ab659194337d73e399004036) when your terminal supports it but is not auto-detected. Useful for emulators such as Emacs `eat` that implement BSU/ESU but do not reply to the capability probe. Has no effect under tmux. Unlike `CLAUDE_CODE_NO_FLICKER`, which switches to [fullscreen rendering](/docs/en/fullscreen), this doesn't change the renderer | +| `CLAUDE_CODE_FORK_SUBAGENT` | Controls [fork mode](/docs/en/sub-agents#turn-fork-mode-on-or-off), which lets Claude spawn [forked subagents](/docs/en/sub-agents#fork-the-current-conversation) itself and is on by default in interactive sessions only. Set to `1` to turn it on in `claude -p` and the Agent SDK as well, or `0` to turn it off in every kind of session. You can run `/subtask` whether or not fork mode is on. The interactive default requires Claude Code v2.1.232 or later; on earlier versions, set the variable to `1` to turn fork mode on | +| `CLAUDE_CODE_FORWARD_SUBAGENT_TEXT` | Set to `1` to emit [subagent](/docs/en/sub-agents) text and thinking blocks in `claude -p --output-format stream-json` output, the same behavior as the [`--forward-subagent-text`](/docs/en/cli-reference#cli-flags) flag. Use the variable when a harness invokes `claude` and can't pass the flag itself. Unlike the flag, which exits with an error outside non-interactive mode with stream-json output, the variable is ignored there so that nested invocations keep working when it's set process-wide. Requires Claude Code v2.1.211 or later | +| `CLAUDE_CODE_GIT_BASH_PATH` | Windows only: path to the Git Bash executable (`bash.exe`). Use when Git Bash is installed but not in your PATH. If the path doesn't exist or the file isn't named `bash.exe`, `sh.exe`, `bash`, or `sh`, Claude Code ignores the variable and auto-detects Git Bash as if it were unset, logging a warning visible with `--debug`. Before v2.1.219, Claude Code exited at startup when the path didn't exist, and used any existing file as the shell without checking that it was bash or sh. See [Windows setup](/docs/en/setup#set-up-on-windows) | +| `CLAUDE_CODE_GLOB_HIDDEN` | Set to `false` to exclude dotfiles from results when Claude invokes the [Glob tool](/docs/en/tools-reference#glob-tool-behavior). Included by default. Does not affect `@` file autocomplete, `ls`, Grep, or Read | +| `CLAUDE_CODE_GLOB_NO_IGNORE` | Set to `false` to make the [Glob tool](/docs/en/tools-reference#glob-tool-behavior) respect `.gitignore` patterns. By default, Glob returns all matching files including gitignored ones. Does not affect `@` file autocomplete, which has its own [`respectGitignore` setting](/docs/en/settings-reference#respectgitignore) | +| `CLAUDE_CODE_GLOB_TIMEOUT_SECONDS` | Timeout in seconds for Glob tool file discovery. Defaults to 20 seconds on most platforms and 60 seconds on WSL | +| `CLAUDE_CODE_GOAL_CHECKIN_MINUTES` | How many minutes background work can keep an active goal waiting before Claude Code [asks Claude to check on it](/docs/en/goal#background-work-defers-evaluation). Default `30`. Set `0` to turn check-ins off. Give whole minutes in plain digits, at most `10080`, which is one week. Claude Code treats any other value as unset and uses the default. Requires Claude Code v2.1.234 or later | +| `CLAUDE_CODE_HIDE_CWD` | Set to `1` to hide the working directory in the startup logo. Useful for screenshares or recordings where the path exposes your OS username | +| `CLAUDE_CODE_IDE_HOST_OVERRIDE` | Override the host address used to connect to the IDE extension. By default Claude Code auto-detects the correct address, including WSL-to-Windows routing | +| `CLAUDE_CODE_IDE_SKIP_AUTO_INSTALL` | Set to `1` to skip auto-installation of IDE extensions. Equivalent to setting [`autoInstallIdeExtension`](/docs/en/settings-reference#autoinstallideextension) to `false` | +| `CLAUDE_CODE_IDE_SKIP_VALID_CHECK` | Set to `1` to skip validation of IDE lockfile entries during connection. Use when auto-connect fails to find your IDE despite it running | +| `CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS` | How many [subagents](/docs/en/sub-agents#concurrent-subagent-limit) can be running in one session before the Agent tool refuses to spawn another (default: 20). Accepts a positive whole number in plain digits; anything else is ignored, so the variable can adjust the cap but can't disable it. Requires Claude Code v2.1.217 or later | +| `CLAUDE_CODE_MAX_CONTEXT_TOKENS` | Override the context window size Claude Code assumes for the active model. As of v2.1.193, how it applies depends on how Claude Code resolves the model ID; see [Correct the window for a gateway or custom model ID](/docs/en/model-config#correct-the-window-for-a-gateway-or-custom-model-id). Use this when routing to a model through `ANTHROPIC_BASE_URL` whose context window does not match the built-in size for its name | +| `CLAUDE_CODE_MAX_OUTPUT_TOKENS` | Set the maximum number of output tokens for most requests. Defaults and caps vary by model; see [max output tokens](https://platform.claude.com/docs/en/about-claude/models/overview#latest-models-comparison). Claude Code defaults to 32000 for model IDs it doesn't recognize, such as gateway-specific names, and lowers values above a model's cap to the cap. Increasing this value reduces the effective context window available before [auto-compaction](/docs/en/costs#reduce-token-usage) triggers | +| `CLAUDE_CODE_MAX_RETRIES` | Override the number of times to retry failed API requests (default: 10). Capped at 15 as of v2.1.186; as of v2.1.199, `CLAUDE_CODE_RETRY_WATCHDOG` raises the default and removes the cap. For unattended sessions that need to wait through longer outages, set `CLAUDE_CODE_RETRY_WATCHDOG` instead | +| `CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION` | Removed in v2.1.224 and now a no-op. Previously capped the total number of [subagents](/docs/en/sub-agents) Claude could spawn with the Agent tool in one session (default: 200); spawning past the cap failed with `Subagent spawn limit reached`. The [concurrent subagent limit](/docs/en/sub-agents#concurrent-subagent-limit) and the [depth limit](/docs/en/sub-agents#let-subagents-spawn-their-own-subagents) still apply | +| `CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH` | Number of [subagent layers](/docs/en/sub-agents#let-subagents-spawn-their-own-subagents) allowed below the main conversation (default: 3). At the default, subagents can spawn their own subagents, and a subagent at the third layer can't spawn further; set `1` to turn nesting off. In v2.1.217 through v2.1.218, the default was 1, so a subagent couldn't spawn its own unless you raised the limit; v2.1.219 raised the default to 3. Accepts a positive whole number in plain digits; anything else is ignored, so the limit can be adjusted but not removed. Requires Claude Code v2.1.217 or later | +| `CLAUDE_CODE_MAX_TOOL_USE_CONCURRENCY` | Maximum number of read-only tools and subagents that can execute in parallel (default: 10). Higher values increase parallelism but consume more resources | +| `CLAUDE_CODE_MAX_TURNS` | Cap the number of agentic turns when no explicit limit is passed. Equivalent to passing [`--max-turns`](/docs/en/cli-reference#cli-flags), which takes precedence when both are set. A value that is not a positive integer is rejected at startup with an error rather than treated as no cap | +| `CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION` | Cap on the total number of [WebSearch](/docs/en/tools-reference#websearch-tool-behavior) calls one session can make (default: 200). When Claude reaches the cap, further WebSearch calls return a notice telling it to continue with the information it already gathered. Accepts a positive whole number with no upper bound. Anything else is ignored and the default applies, so the cap can be raised but not turned off. Requires Claude Code v2.1.212 or later | +| `CLAUDE_CODE_MCP_ALLOWLIST_ENV` | Set to `1` to spawn stdio MCP servers with only a safe baseline environment plus the server's configured `env`, instead of inheriting your shell environment | +| `CLAUDE_CODE_MCP_AUTO_BACKGROUND_MS` | Elapsed time in milliseconds before a still-running MCP tool call [moves to a background task](/docs/en/mcp#automatic-backgrounding-of-long-tool-calls) (default: 120000, or 2 minutes). Set to `0` to turn automatic backgrounding off. Requires Claude Code v2.1.212 or later | +| `CLAUDE_CODE_MCP_TOOL_IDLE_TIMEOUT` | Idle timeout in milliseconds for MCP tool calls. When a stdio, HTTP, SSE, WebSocket, or [claude.ai connector](/docs/en/mcp#use-mcp-servers-from-claude-ai) MCP server sends no response and no progress notification for this long, the tool call aborts with an error instead of waiting for the overall `MCP_TOOL_TIMEOUT`. Overrides the per-transport defaults of 300000 (5 minutes) for network servers and 1800000 (30 minutes) for stdio servers. Set to `0` to disable the idle check. Values below 1000 are raised to one second, and the value is capped at the effective `MCP_TOOL_TIMEOUT`. A per-server `timeout` in `.mcp.json` of at least 1000 raises that server's idle window to at least the `timeout` value. Doesn't apply to IDE servers or SDK in-process servers. Requires Claude Code v2.1.187 or later. Before v2.1.203, stdio servers were exempt from the idle timeout | +| `CLAUDE_CODE_MESSAGING_SOCKET` | Set by Claude Code, not by you: in sessions that bind an [inbox socket](/docs/en/cross-session-messaging#the-sessions-inbox-socket), Claude Code exports that socket's path to hooks and Bash commands when it binds the socket. In a session that starts with messaging on, Claude Code binds the socket before any hook runs. Other sessions on the machine deliver messages to this path. Each session exports its own socket rather than one inherited from a parent, and messages arriving on it go through the session's [inbound controls](/docs/en/cross-session-messaging#control-inbound-messages). Settings `env` blocks can't set it. Requires Claude Code v2.1.224 or later | +| `CLAUDE_CODE_MESSAGING_TOKEN` | Set by Claude Code, not by you: in sessions that bind an [inbox socket](/docs/en/cross-session-messaging#the-sessions-inbox-socket), Claude Code exports this per-session token to hooks and Bash commands alongside `CLAUDE_CODE_MESSAGING_SOCKET`. A script posting to the socket can send `{"type":"auth","token":""}` as its first line to prove it belongs to the session. On native Windows, Claude Code requires this line and closes any connection that doesn't open with a valid one. The [own-child rules](/docs/en/cross-session-messaging#the-sessions-inbox-socket) say when Claude Code consults the token. Each session exports its own token, never one inherited from a parent session. Settings `env` blocks can't set it. Requires Claude Code v2.1.228 or later | +| `CLAUDE_CODE_NATIVE_CURSOR` | Set to `1` to show the terminal's own cursor at the input caret instead of a drawn block. The cursor respects the terminal's blink, shape, and focus settings | +| `CLAUDE_CODE_NEW_INIT` | Set to `1` to make `/init` run an interactive setup flow. The flow asks which files to generate, including CLAUDE.md, skills, and hooks, before exploring the codebase and writing them. Without this variable, `/init` generates a CLAUDE.md automatically without prompting | +| `CLAUDE_CODE_NO_FLICKER` | Set to `1` to enable [fullscreen rendering](/docs/en/fullscreen), a research preview that reduces flicker and keeps memory flat in long conversations. Overrides the [`tui`](/docs/en/settings-reference#tui) setting; you can also switch with `/tui fullscreen` | +| `CLAUDE_CODE_OAUTH_REFRESH_TOKEN` | OAuth refresh token for Claude.ai authentication. When set, `claude auth login` exchanges this token directly instead of opening a browser. Requires `CLAUDE_CODE_OAUTH_SCOPES`. Useful for provisioning authentication in automated environments | +| `CLAUDE_CODE_OAUTH_SCOPES` | Space-separated OAuth scopes the refresh token was issued with, such as `"user:profile user:inference user:sessions:claude_code"`. Required when `CLAUDE_CODE_OAUTH_REFRESH_TOKEN` is set | +| `CLAUDE_CODE_OAUTH_TOKEN` | OAuth access token for claude.ai authentication. Alternative to `/login` for SDK and automated environments. Takes precedence over keychain-stored credentials. Generate one with [`claude setup-token`](/docs/en/authentication#generate-a-long-lived-token). Unless you run [`/login`](/docs/en/authentication#authentication-precedence), Claude Code uses the token you set for the whole session. To replace an expired token, generate a new one and restart | +| `CLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE` | Removed in v2.1.160 and now a no-op. Previously pinned [fast mode](/docs/en/fast-mode) to Claude Opus 4.6 instead of the current default. Opus 4.6 no longer supports fast mode | +| `CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH` | Maximum length of content-bearing OpenTelemetry attributes (model responses, tool content, system prompts, raw API bodies), truncation marker included, in UTF-16 code units (default: 61440, i.e. 60 KB). Raise it only if your telemetry backend accepts attribute values larger than 64 KB, or lower it to cut telemetry volume. Requires Claude Code v2.1.214 or later. See [Monitoring](/docs/en/monitoring-usage) | +| `CLAUDE_CODE_OTEL_DIAG_STDERR` | Set to `1` to write OpenTelemetry exporter diagnostic errors to stderr. By default these errors only appear with `--debug`, so a misconfigured exporter such as a Prometheus port collision otherwise fails silently. Requires Claude Code v2.1.179 or later. See [Monitoring](/docs/en/monitoring-usage) | +| `CLAUDE_CODE_OTEL_FLUSH_TIMEOUT_MS` | Timeout in milliseconds for flushing pending OpenTelemetry spans (default: 5000). See [Monitoring](/docs/en/monitoring-usage) | +| `CLAUDE_CODE_OTEL_HEADERS_HELPER_DEBOUNCE_MS` | Interval for refreshing dynamic OpenTelemetry headers in milliseconds (default: 1740000 / 29 minutes). See [Dynamic headers](/docs/en/monitoring-usage#dynamic-headers) | +| `CLAUDE_CODE_OTEL_SHUTDOWN_TIMEOUT_MS` | Timeout in milliseconds for the OpenTelemetry exporter to finish on shutdown (default: 2000). Increase if metrics are dropped at exit. See [Monitoring](/docs/en/monitoring-usage) | +| `CLAUDE_CODE_PACKAGE_MANAGER_AUTO_UPDATE` | Set to `1` to let Claude Code run your package manager's upgrade command in the background when a new version is available. Applies to Homebrew and WinGet installations. Other package managers continue to show the upgrade command without running it. See [Auto updates](/docs/en/setup#auto-updates) | +| `CLAUDE_CODE_PERFORCE_MODE` | Set to `1` to enable Perforce-aware write protection. When set, Edit, Write, and NotebookEdit fail with a `p4 edit ` hint if the target file lacks the owner-write bit, which Perforce clears on synced files until `p4 edit` opens them. This prevents Claude Code from bypassing Perforce change tracking | +| `CLAUDE_CODE_PLUGIN_CACHE_DIR` | Override the plugins root directory. Despite the name, this sets the parent directory, not the cache itself: marketplaces and the plugin cache live in subdirectories under this path. Defaults to `~/.claude/plugins` | +| `CLAUDE_CODE_PLUGIN_GIT_TIMEOUT_MS` | Timeout in milliseconds for git operations when installing or updating plugins (default: 120000). Increase this value for large repositories or slow network connections. See [Git operations time out](/docs/en/plugin-marketplaces#git-operations-time-out) | +| `CLAUDE_CODE_PLUGIN_KEEP_MARKETPLACE_ON_FAILURE` | Set to `1` to skip the re-clone attempt and keep using the existing marketplace cache when a `git pull` fails. Useful in offline or airgapped environments where re-cloning would fail the same way. See [Marketplace updates fail in offline environments](/docs/en/plugin-marketplaces#marketplace-updates-fail-in-offline-environments) | +| `CLAUDE_CODE_PLUGIN_PREFER_HTTPS` | Set to `1` to clone GitHub `owner/repo` shorthand sources over HTTPS instead of SSH. Applies to plugin install and update, and to `/plugin marketplace add` and `update`. Useful in CI runners, containers, or any environment without a configured SSH key for `github.com` | +| `CLAUDE_CODE_PLUGIN_SEED_DIR` | Path to one or more read-only plugin seed directories, separated by `:` on Unix or `;` on Windows. Use this to bundle a pre-populated plugins directory into a container image. Claude Code registers marketplaces from these directories at startup and uses pre-cached plugins without re-cloning. See [Pre-populate plugins for containers](/docs/en/plugin-marketplaces#pre-populate-plugins-for-containers) | +| `CLAUDE_CODE_POWERSHELL_RESPECT_EXECUTION_POLICY` | Set to `1` to stop Claude Code from passing `-ExecutionPolicy Bypass` when spawning PowerShell for tool calls, hooks, and status line commands, and respect the machine's effective execution policy instead. By default Claude Code bypasses execution policy at process scope so `.ps1` scripts and module imports work on default-Restricted Windows installs. Process-scope bypass never overrides Group Policy `MachinePolicy` or `UserPolicy` regardless of this setting | +| `CLAUDE_CODE_PRINT_BG_WAIT_CEILING_MS` | Ceiling in milliseconds on idle waiting for background subagents and workflows after the final turn in [non-interactive mode](/docs/en/headless#background-tasks-at-exit) with the `-p` flag. Idle waiting starts over each time Claude takes a turn to handle a background result. Default: `600000`, or 10 minutes. When idle waiting reaches the ceiling, Claude Code stops waiting for the remaining background tasks and exits. Set to `0` to wait indefinitely. This cap is separate from the five-second grace period that applies to plain background shells. Requires Claude Code v2.1.182 or later | +| `CLAUDE_CODE_PROCESS_WRAPPER` | Launch the processes Claude Code starts from its own binary, such as the background service that hosts [agent view](/docs/en/agent-view) sessions, through a corporate launcher given as an argv prefix like `/opt/corp/launcher`. Set it in the `env` block of user or [managed settings](/docs/en/managed-settings), not as a shell export, so the detached background service inherits it; project and local settings can't set it. Equivalent to the [`processWrapper` setting](/docs/en/settings-reference#processwrapper), which requires Claude Code v2.1.210 or later; this variable takes precedence when both are set. The VS Code extension configures its own launcher separately through its `claudeProcessWrapper` setting. Ignored on Windows. See [Run Claude Code behind a corporate launcher](/docs/en/corporate-launcher) for the value format, what the launcher covers, and the contract the launcher must satisfy. Requires Claude Code v2.1.208 or later | +| `CLAUDE_CODE_PROJECT_DIR_NAME` | Set together with `CLAUDE_CONFIG_DIR` to choose the `projects/` directory name Claude Code stores that session's transcripts and auto memory under, in place of one derived from the working directory path. For example, starting Claude Code with `CLAUDE_CONFIG_DIR=/srv/tenant-a CLAUDE_CODE_PROJECT_DIR_NAME=work claude` stores them under `/srv/tenant-a/projects/work/`. Claude Code ignores this variable when `CLAUDE_CONFIG_DIR` is unset, and reads it only from the environment you start `claude` from, never from a [settings file `env` block](#in-settings-files). See [Name the project directory yourself](/docs/en/sessions#name-the-project-directory-yourself). Requires Claude Code v2.1.234 or later | +| `CLAUDE_CODE_PROMPT_CACHE_TTL` | Set `5m` or `1h`, the only values Claude Code accepts, to choose the [prompt cache TTL](/docs/en/prompt-caching#cache-lifetime) for the main conversation: your interactive, `-p`, and SDK turns, plus the helpers that run inline with them. Takes precedence over the `promptCacheTtl` setting and over `ENABLE_PROMPT_CACHING_1H`, and `FORCE_PROMPT_CACHING_5M` overrides it. The API bills 1-hour cache writes at a higher rate. Requires Claude Code v2.1.242 or later | +| `CLAUDE_CODE_PROPAGATE_TRACEPARENT` | Set to `1` to propagate W3C trace context when `ANTHROPIC_BASE_URL` points at a custom proxy. Propagation covers the `traceparent` header on model and HTTP MCP requests and the `TRACEPARENT` environment variable for Bash, PowerShell, and hook subprocesses. By default, propagation is enabled only when connected directly to the Anthropic API. Added in v2.1.152. See [Traces (beta)](/docs/en/monitoring-usage#traces-beta) | +| `CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST` | Set by host platforms that embed Claude Code and manage model provider routing on its behalf. When set, Claude Code ignores provider-selection, endpoint, and authentication variables such as `CLAUDE_CODE_USE_BEDROCK`, `ANTHROPIC_BASE_URL`, and `ANTHROPIC_API_KEY` in settings files, so user settings can't override the host's routing. Claude Code also ignores model-selection keys such as `model`, `fallbackModel`, and `modelOverrides` in [managed settings](/docs/en/managed-settings), whichever managed source delivers them, so the host's model configuration takes precedence over an out-of-date managed model pin. Claude Code also ignores model-selection variables such as `ANTHROPIC_MODEL` and the `ANTHROPIC_DEFAULT_*_MODEL` family in a managed `env` block; an [`availableModels`](/docs/en/model-config#restrict-model-selection) allowlist in managed settings still applies unless the host supplies its own. Claude Code also skips the automatic telemetry opt-out it otherwise applies on third-party providers such as Amazon Bedrock, Claude Platform on AWS, Google Cloud's Agent Platform, and Microsoft Foundry, so telemetry follows the standard `DISABLE_TELEMETRY` opt-out. See [Default behaviors by API provider](/docs/en/data-usage#default-behaviors-by-api-provider) | +| `CLAUDE_CODE_PROXY_RESOLVES_HOSTS` | Set to `1` to allow the proxy to perform DNS resolution instead of the caller. Opt-in for environments where the proxy should handle hostname resolution | +| `CLAUDE_CODE_REMOTE` | Set automatically to `true` when Claude Code is running as a [cloud session](/docs/en/claude-code-on-the-web). Read this from a hook or setup script to detect whether you are in a cloud session | +| `CLAUDE_CODE_REMOTE_SESSION_ID` | Set automatically in [cloud sessions](/docs/en/claude-code-on-the-web) to the current session's ID. Read this to construct a link back to the session transcript. See [Link output back to the session](/docs/en/cloud-environments#link-output-back-to-the-session) | +| `CLAUDE_CODE_RESTRICTED` | Set to `1` to start the session in restricted mode, the same as passing [`--restricted`](/docs/en/cli-reference#cli-flags). Claude Code ignores this variable in a settings file's `env` block. Requires Claude Code v2.1.248 or later | +| `CLAUDE_CODE_RESUME_INTERRUPTED_TURN` | Set to `1` to automatically resume if the previous session ended mid-turn. Used in SDK mode so the model continues without requiring the SDK to re-send the prompt. To turn this off, unset the variable or set it to `0`. Before v2.1.221, Claude Code ignored `0` and other falsy values, so setting `0` still triggered the resume in non-interactive mode and unsetting the variable was the only way to turn it off | +| `CLAUDE_CODE_RESUME_INTERRUPTED_TURN_MAX_AGE_MS` | Maximum age in milliseconds of the last transcript message for a session that ended mid-turn to continue automatically on resume. When the last message is older than this bound, Claude Code skips both the `CLAUDE_CODE_RESUME_INTERRUPTED_TURN` automatic resume and the injected `CLAUDE_CODE_RESUME_PROMPT` continuation message, and the session starts idle so you continue explicitly. Unset or `0` means no bound; a negative or non-numeric value applies a one-hour bound. Spawn scripts for long-running agents can set this so a restart against an old transcript doesn't re-run a stale prompt. Claude Code sets a one-hour bound itself when it restarts a crashed [agent view](/docs/en/agent-view) session that inherited its conversation from an interactive session. Requires Claude Code v2.1.211 or later | +| `CLAUDE_CODE_RESUME_PROMPT` | Override the continuation message injected when resuming a session that ended mid-turn. Defaults to `Continue from where you left off.`. Spawn scripts for long-running agents can set this to a more directive boot message. An empty string uses the default | +| `CLAUDE_CODE_RETRY_WATCHDOG` | Set to `1` for unattended sessions such as eval harnesses, CI jobs, or remote workers. Retries `429` and `529` capacity errors indefinitely instead of failing after `CLAUDE_CODE_MAX_RETRIES` attempts. Claude Code fails at once on a `429` that reports a spend limit or exhausted usage credits, even one from a [gateway spend cap](/docs/en/errors#spend-limit-reached) that resets on a schedule. Before v2.1.239, the watchdog retried these indefinitely. The watchdog backs off up to 5 minutes between attempts, or until the limit resets when the response carries a rate-limit reset time, so a session that hits a usage limit waits out the remaining window. On v2.1.199 or later it also raises the default retry count for other transient errors, such as server errors, timeouts, and dropped connections, to 300, roughly three hours of backoff, and removes the cap of 15 on `CLAUDE_CODE_MAX_RETRIES` if you set that variable explicitly. Requires Claude Code v2.1.186 or later | +| `CLAUDE_CODE_SAFE_MODE` | Set to `1` to start in safe mode: CLAUDE.md, skills, plugins, hooks, MCP servers, custom commands and agents, output styles, workflows, custom themes, custom keybindings, status line and file-suggestion commands, LSP servers, and auto memory do not load, for troubleshooting a broken configuration. Managed settings policy still applies, including policy-configured hooks, status line, and file-suggestion commands; managed plugins, managed skills, managed CLAUDE.md, and policy-configured MCP servers do not. Equivalent to passing [`--safe-mode`](/docs/en/cli-reference#cli-flags). Directly spawned child processes inherit the variable | +| `CLAUDE_CODE_SCRIPT_CAPS` | JSON object limiting how many times specific scripts may be invoked per session when `CLAUDE_CODE_SUBPROCESS_ENV_SCRUB` is set. Keys are substrings matched against the command text; values are integer call limits. For example, `{"deploy.sh": 2}` allows `deploy.sh` to be called at most twice. Matching is substring-based so shell-expansion tricks like `./scripts/deploy.sh $(evil)` still count against the cap. Runtime fan-out via `xargs` or `find -exec` is not detected; this is a defense-in-depth control | +| `CLAUDE_CODE_SCROLL_SPEED` | Set the mouse wheel scroll multiplier in [fullscreen rendering](/docs/en/fullscreen#mouse-wheel-scrolling). Accepts any positive value up to 20, including fractional values below 1 such as `0.5` to slow accelerated trackpad and wheel scrolling in terminals that already amplify wheel events. Set to `3` to match `vim` if your terminal sends one wheel event per notch without amplification. Ignored in the JetBrains IDE terminal, where Claude Code uses its own scroll handling | +| `CLAUDE_CODE_SEND_FEEDBACK` | Set to `0` to turn off [Claude-drafted feedback](/docs/en/tools-reference#sendfeedback-tool-behavior) for a session. Set to `1` to turn it on where your account already has access; the variable can't grant access itself, and the other switches that turn feedback off, such as `DISABLE_FEEDBACK_COMMAND` and the [`feedbackDrafts`](/docs/en/settings-reference#feedbackdrafts) setting's `off` value, still apply | +| `CLAUDE_CODE_SESSIONEND_HOOKS_TIMEOUT_MS` | Override the time budget in milliseconds for [SessionEnd](/docs/en/hooks#sessionend) hooks. Applies to session exit, `/clear`, and switching sessions via interactive `/resume`. By default the budget is 1.5 seconds, automatically raised to the highest per-hook `timeout` configured in settings files, up to 60 seconds. Timeouts on plugin-provided hooks do not raise the budget | +| `CLAUDE_CODE_SESSION_ID` | Set automatically to the current session ID in Bash and PowerShell tool subprocesses, [hook command](/docs/en/hooks) subprocesses, and stdio [MCP server](/docs/en/mcp) subprocesses. For Bash, PowerShell, and hooks this matches the `session_id` field in the hook JSON input and is updated on `/clear`. An MCP server subprocess retains the ID it was spawned with. On `--resume ` it receives the resumed ID, matching hooks and Bash. On `--continue` or `--resume` without an explicit ID it may receive the initial startup ID instead. Use to correlate scripts and external tools with the Claude Code session that launched them | +| `CLAUDE_CODE_SHELL` | Set the shell Claude Code uses to run Bash tool commands. Accepts a path to a `bash` or `zsh` binary, for example `/opt/homebrew/bin/bash`. Other shells such as `fish` are not supported. If the value is not a working `bash` or `zsh` path, Claude Code ignores it and falls back to auto-detection. Auto-detection uses your `$SHELL` when it points to `bash` or `zsh`, otherwise it picks the first working `zsh` then `bash` found on your `PATH` and standard install locations | +| `CLAUDE_CODE_SHELL_PREFIX` | Command prefix that wraps shell commands Claude Code spawns: Bash tool calls, [hook](/docs/en/hooks) commands, [status line](/docs/en/statusline) commands, and stdio [MCP server](/docs/en/mcp) startup commands. PowerShell hooks and exec-form hooks run without the prefix. Useful for logging or auditing. Setting a bare executable path such as `/path/to/logger.sh` runs each command as `/path/to/logger.sh ''`. The wrapper receives the command line as a single shell-quoted argument in `$1`, so the wrapper must re-evaluate `$1` with a shell, for example `exec bash -c "$1"`. Treating `$1` as a bare executable path breaks stdio MCP servers that pass arguments such as `npx -y `. For Bash tool calls, `$1` contains the full shell invocation Claude Code assembles, including environment setup, not only the command Claude ran | +| `CLAUDE_CODE_SIMPLE` | Set to `1` to run with a minimal system prompt and only the Bash, file read, and file edit tools. MCP tools from `--mcp-config` are still available. Disables auto-discovery of hooks, skills, custom commands, subagents, plugins, MCP servers, auto memory, and CLAUDE.md. Skills in a directory you pass with `--add-dir` still load. OAuth tokens and keychain credentials are not read, so Anthropic authentication must come from `ANTHROPIC_API_KEY` or an `apiKeyHelper` in `--settings`. Equivalent to passing [`--bare`](/docs/en/headless#start-faster-with-bare-mode) | +| `CLAUDE_CODE_SIMPLE_SYSTEM_PROMPT` | Set to `1` to use a shorter system prompt and abbreviated tool descriptions on any model. Set to `0`, `false`, `no`, or `off` to opt out even on models where the experiment or server configuration would otherwise enable it. The full tool set, hooks, MCP servers, and CLAUDE.md discovery remain enabled | +| `CLAUDE_CODE_SKIP_ANTHROPIC_AWS_AUTH` | Skip client-side authentication for [Claude Platform on AWS](/docs/en/claude-platform-on-aws), for gateways that sign requests themselves | +| `CLAUDE_CODE_SKIP_AWS_CRED_CACHE` | Set to `1` to turn off the in-process cache of credentials resolved from the AWS default credential provider chain, so Claude Code resolves the chain on every API request. With the cache off, an SSO-backed profile requests credentials from IAM Identity Center on every request. See [credential caching and resolution timeout](/docs/en/amazon-bedrock#credential-caching-and-resolution-timeout). Requires Claude Code v2.1.207 or later | +| `CLAUDE_CODE_SKIP_BEDROCK_AUTH` | Skip AWS authentication for Amazon Bedrock (for example, when using an LLM gateway) | +| `CLAUDE_CODE_SKIP_FAST_MODE_NETWORK_ERRORS` | Set to `1` to treat a failed [fast mode](/docs/en/fast-mode#use-fast-mode-behind-proxies-and-llm-gateways) availability check as available, for networks that block the check's direct request to `api.anthropic.com`. Claude Code still honors a "disabled by your organization" response | +| `CLAUDE_CODE_SKIP_FAST_MODE_ORG_CHECK` | Set to `1` to skip the client-side [fast mode](/docs/en/fast-mode#use-fast-mode-behind-proxies-and-llm-gateways) availability check, for proxies that intercept the check's request rather than refuse it. The API still rejects fast mode requests when your organization has fast mode disabled | +| `CLAUDE_CODE_SKIP_FOUNDRY_AUTH` | Skip Azure authentication for Microsoft Foundry, for a proxy or gateway that injects its own `Authorization` header. Claude Code sends requests without an Azure credential and preserves the `Authorization` header you supply, for example through `ANTHROPIC_CUSTOM_HEADERS`. Ignored when `ANTHROPIC_FOUNDRY_API_KEY` or `ANTHROPIC_FOUNDRY_AUTH_TOKEN` is set. Before v2.1.203, this variable left the Microsoft Foundry client unable to send requests unless an API key was also set | +| `CLAUDE_CODE_SKIP_MANTLE_AUTH` | Skip AWS authentication for Amazon Bedrock Mantle (for example, when using an LLM gateway) | +| `CLAUDE_CODE_SKIP_PROMPT_HISTORY` | Set to `1` to skip writing prompt history and session transcripts to disk. Sessions started with this variable set do not appear in `--resume`, `--continue`, or up-arrow history. Useful for ephemeral scripted sessions | +| `CLAUDE_CODE_SKIP_VERTEX_AUTH` | Skip Google authentication for Google Cloud's Agent Platform (for example, when using an LLM gateway) | +| `CLAUDE_CODE_STOP_HOOK_BLOCK_CAP` | Maximum number of consecutive times a [Stop](/docs/en/hooks#stop) or [SubagentStop](/docs/en/hooks#subagentstop) hook may block the turn from ending before Claude Code overrides it and ends the turn anyway (default: 8). Set to `0` to disable the cap. Raise this if your hook legitimately needs more iterations to resolve | +| `CLAUDE_CODE_SUBAGENT_MODEL` | The default model for [subagents](/docs/en/sub-agents#choose-a-model), [agent team](/docs/en/agent-teams#specify-teammates-and-models) teammates, and [workflow](/docs/en/workflows) agents that aren't assigned a model another way. Accepts an alias such as `haiku` or a full model name. Two sources take precedence over it: a model Claude passes when it spawns the agent, and a `model` field in the agent's definition, including `inherit`. To change that, set [`CLAUDE_CODE_SUBAGENT_MODEL_FORCE`](/docs/en/sub-agents#run-every-subagent-on-one-model). See [Choose a model](/docs/en/sub-agents#choose-a-model) for the full order. Setting it to `inherit` is the same as leaving it unset. Before v2.1.251, this variable overrode both the per-invocation model and the definition's `model` field | +| `CLAUDE_CODE_SUBAGENT_MODEL_FORCE` | Set to `1` to force one model onto subagents, teammates, and workflow agents. [Run every subagent on one model](/docs/en/sub-agents#run-every-subagent-on-one-model) says which model that is. Requires Claude Code v2.1.257 or later | +| `CLAUDE_CODE_SUBAGENT_PROMPT_CACHE_TTL` | Set `5m` or `1h`, the only values Claude Code accepts, to choose the [prompt cache TTL](/docs/en/prompt-caching#cache-lifetime) for requests outside the main conversation, such as [subagents](/docs/en/sub-agents), workflows, and background work. Takes precedence over the `subagentPromptCacheTtl` setting and over `ENABLE_PROMPT_CACHING_1H`, and `FORCE_PROMPT_CACHING_5M` overrides it. The API bills 1-hour cache writes at a higher rate. Requires Claude Code v2.1.242 or later | +| `CLAUDE_CODE_SUBPROCESS_ENV_SCRUB` | Set to `1` to strip credentials from subprocess environments (Bash tool, hooks, MCP stdio servers): Anthropic and cloud provider credentials, any other variable that Claude Code recognizes as a credential, and credentials embedded in package registry URLs. The parent Claude process keeps these credentials for API calls, but child processes cannot read them, reducing exposure to prompt injection attacks that attempt to exfiltrate secrets via shell expansion. On Linux, this also runs Bash subprocesses in an isolated PID namespace so they cannot read host process environments via `/proc`; as a side effect, `ps`, `pgrep`, and `kill` cannot see or signal host processes. `claude-code-action` sets this automatically when `allowed_non_write_users` is configured | +| `CLAUDE_CODE_SYNC_PLUGIN_INSTALL` | Set to `1` in non-interactive mode (the `-p` flag) to wait for plugin installation to complete before the first query. Without this, plugins install in the background and may not be available on the first turn. Combine with `CLAUDE_CODE_SYNC_PLUGIN_INSTALL_TIMEOUT_MS` to bound the wait | +| `CLAUDE_CODE_SYNC_PLUGIN_INSTALL_TIMEOUT_MS` | Timeout in milliseconds for synchronous plugin installation. When exceeded, Claude Code proceeds without plugins and logs an error. No default: without this variable, synchronous installation waits until complete | +| `CLAUDE_CODE_SYNC_SKILLS` | Set to `1` to download your enabled claude.ai skills into `~/.claude/skills/synced/` and resync every 10 minutes. Before it runs the first query, Claude Code waits up to `CLAUDE_CODE_SYNC_SKILLS_WAIT_TIMEOUT_MS` for the list of your skills. The downloads themselves finish in the background, and Claude waits for a skill's download when it invokes that skill. The `synced` folder name is [reserved for this download](/docs/en/skills#where-skills-live). Before v2.1.227, the skills downloaded into `~/.claude/skills/` directly. Applies only in non-interactive mode with the `-p` flag. Requires claude.ai authentication. [Claude Code on the web](/docs/en/claude-code-on-the-web) sessions receive your enabled claude.ai skills automatically; you don't need to set this there. Claude Code applies [extra rules to the downloaded skills](/docs/en/skills#how-synced-skills-behave), such as not running their `!` commands on your machine | +| `CLAUDE_CODE_SYNC_SKILLS_INSTALL_TIMEOUT_MS` | Timeout in milliseconds for a mid-session skills resync when `CLAUDE_CODE_SYNC_SKILLS` is set (default: 30000). Bounds the download triggered when the host requests a skill reload during the session. When exceeded, the resync stops and remaining downloads continue in the background | +| `CLAUDE_CODE_SYNC_SKILLS_WAIT_TIMEOUT_MS` | Timeout in milliseconds for the first query to wait for the initial skill list when `CLAUDE_CODE_SYNC_SKILLS` is set (default: 5000). When exceeded, the first query runs with whichever skills have arrived. The downloads finish in the background either way, and Claude waits for a skill's download when it invokes that skill | +| `CLAUDE_CODE_SYNTAX_HIGHLIGHT` | Set to `false` to disable syntax highlighting in diff output. Useful when colors interfere with your terminal setup. To also disable highlighting in code blocks and file previews, use the [`syntaxHighlightingDisabled`](/docs/en/settings-reference#syntaxhighlightingdisabled) setting | +| `CLAUDE_CODE_TASK_LIST_ID` | Share a task list across sessions. Set the same ID in multiple Claude Code instances to coordinate on a shared task list, in [sessions that have the Task tools](/docs/en/tools-reference#task-tool-availability). See [Task list](/docs/en/interactive-mode#task-list) | +| `CLAUDE_CODE_TEAM_TEARDOWN_PARK_TIMEOUT_MS` | Override, in milliseconds, how long a non-interactive session waits at exit for its [agent team](/docs/en/agent-teams) to finish tearing down. Accepts 1000 to 60000; an out-of-range value is ignored and the default of 10000 applies. Requires Claude Code v2.1.206 or later | +| `CLAUDE_CODE_TMPDIR` | Override the temp directory used for internal temp files. Claude Code appends `/claude-{uid}/` on Unix or `/claude/` on Windows to this path. Default: `/tmp` on macOS, `os.tmpdir()` on Linux and Windows. As of v2.1.161, on macOS and Linux, [sandboxed](/docs/en/sandboxing) Bash subprocesses receive a short fallback `$TMPDIR` under the system default when your override is a long path, since some tools fail when temp paths get too long. Unsandboxed Bash commands inherit your shell's `$TMPDIR` unchanged. Claude Code's own temp files always use your override. Set it in your shell, user settings, or managed settings. Ignored in [project and local settings](/docs/en/settings-reference#variables-claude-code-ignores-in-env) | +| `CLAUDE_CODE_TMUX_TRUECOLOR` | Set to any non-empty value, such as `1`, to allow 24-bit truecolor output inside tmux. **Setting it to `0` or `false` still allows truecolor**, unlike most on/off variables; unset the variable to restore the 256-color clamp. By default, Claude Code clamps to 256 colors when `$TMUX` is set because tmux does not pass through truecolor escape sequences unless configured to. Set this after adding `set -ga terminal-overrides ',*:Tc'` to your `~/.tmux.conf`. See [Terminal configuration](/docs/en/terminal-config) for other tmux settings | +| `CLAUDE_CODE_TOOL_MEMORY_CGROUP_EXCLUDE` | On Linux and WSL, set to a comma-separated list of the kinds of processes Claude Code [excludes from the tool memory cap](/docs/en/tools-reference#memory-limit-on-linux-and-wsl), such as `mcp` or `lsp`. Set `none` to cap every kind, or `all-new` to cap only Bash, PowerShell, and Monitor tool commands. Claude Code keeps Bash, PowerShell, and Monitor tool commands under the cap whatever you list. Requires Claude Code v2.1.246 or later | +| `CLAUDE_CODE_TOOL_MEMORY_LIMIT` | On Linux and WSL, set to a size such as `4G` to [cap the memory that Bash and PowerShell tool commands can use](/docs/en/tools-reference#memory-limit-on-linux-and-wsl), and Monitor tool commands on v2.1.246 or later. Write the size in plain digits, alone for a number of bytes or with a `K`, `M`, `G`, or `T` suffix. Set `0` or `off` to turn the cap off. Once the first process Claude Code starts has turned the cap on or off, a changed value takes effect the next time you launch `claude`. Requires Claude Code v2.1.233 or later | +| `CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS` | Deadline in milliseconds for dialogs Claude Code forwards to a remote client, such as a [Remote Control](/docs/en/remote-control) or SDK host, and for the approval dialog for a [held cross-session message](/docs/en/cross-session-messaging#control-inbound-messages), before Claude Code cancels them; permission prompts and `AskUserQuestion` questions use their own flows and aren't governed by it. Also bounds the mid-session [Fable usage-credits consent prompt](/docs/en/model-config#fable-and-usage-credits) in a session that may be running unattended. [Control inbound messages](/docs/en/cross-session-messaging#control-inbound-messages) and [non-interactive sessions](/docs/en/cross-session-messaging#non-interactive-sessions) cover the full held-message expiry rules, including the cases where the deadline doesn't apply. Overrides the [`dialogExpiry`](/docs/en/settings-reference#dialogexpiry) setting; `0` or a negative value disables the deadline | +| `CLAUDE_CODE_USE_ANTHROPIC_AWS` | Use [Claude Platform on AWS](/docs/en/claude-platform-on-aws) | +| `CLAUDE_CODE_USE_BEDROCK` | Use [Amazon Bedrock](/docs/en/amazon-bedrock) | +| `CLAUDE_CODE_USE_FOUNDRY` | Use [Microsoft Foundry](/docs/en/microsoft-foundry) | +| `CLAUDE_CODE_USE_MANTLE` | Use the Amazon Bedrock [Mantle endpoint](/docs/en/amazon-bedrock#use-the-mantle-endpoint) | +| `CLAUDE_CODE_USE_NATIVE_FILE_SEARCH` | Set to `1` to discover custom commands, subagents, and output styles using Node.js file APIs instead of ripgrep. Set this if the bundled ripgrep binary is unavailable or blocked in your environment. Does not affect the Grep or file search tools | +| `CLAUDE_CODE_USE_POWERSHELL_TOOL` | Controls the PowerShell tool. On Windows without Git Bash, the tool is enabled automatically; set to `0` to disable it. On Windows with Git Bash installed, the tool is on by default for claude.ai and Console accounts; set to `1` to enable it in Amazon Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry sessions, or `0` to turn it off. On Linux, macOS, and WSL, set to `1` to enable it, which requires `pwsh` on your `PATH`. When enabled on Windows, Claude can run PowerShell commands natively instead of routing through Git Bash. See [PowerShell tool](/docs/en/tools-reference#powershell-tool) | +| `CLAUDE_CODE_USE_VERTEX` | Use [Google Cloud's Agent Platform](/docs/en/google-vertex-ai) | +| `CLAUDE_CODE_WEBFETCH_CACHE_TTL_MS` | Set to the number of milliseconds [WebFetch](/docs/en/tools-reference#webfetch-tool-behavior) keeps each fetched URL's response cached. The default is `900000`, which is 15 minutes. Takes plain digits only; `0`, a decimal, or any other spelling keeps the default. Claude Code reads the value once per launch, so a change in a settings `env` block applies when you next launch `claude`. Requires Claude Code v2.1.233 or later | +| `CLAUDE_CODE_WORKFLOW_PREFIX_STAGGER_MS` | Upper bound in milliseconds on how long a [workflow](/docs/en/workflows) agent waits for a same-prefix sibling's first response to begin before sending its own first request. When a fan-out starts several agents that share a [prompt-cache prefix](/docs/en/workflows#prompt-caching-in-a-fan-out), Claude Code holds all but the first agent for up to this long so the rest read the cached prefix instead of each processing it uncached. Default `5000`. Set to `0` to disable the wait. When `DISABLE_PROMPT_CACHING` is set, agents never wait. Requires Claude Code v2.1.229 or later | +| `CLAUDE_CONFIG_DIR` | Override the configuration directory (default: `~/.claude`). All settings, session history, and plugins are stored under this path. For credentials, see [where Claude Code stores credentials](/docs/en/authentication#credential-management). Useful for running multiple accounts side by side: for example, `alias claude-work='CLAUDE_CONFIG_DIR=~/.claude-work claude'`. Set it in your shell, user settings, or managed settings. Ignored in [project and local settings](/docs/en/settings-reference#variables-claude-code-ignores-in-env) | +| `CLAUDE_DISABLE_ADOPT` | Set to `1` to stop in-flight background work instead of carrying it over when you background a session by pressing `←` or with [`/background`](/docs/en/agent-view#from-inside-a-session). Claude Code asks you to confirm before backgrounding, then stops the tasks that would otherwise carry over. Requires Claude Code v2.1.195 or later | +| `CLAUDE_EFFORT` | Set automatically in Bash tool subprocesses and hook commands to the [effort level](/docs/en/model-config#adjust-effort-level) in effect when the subprocess starts: `low`, `medium`, `high`, `xhigh`, or `max`. Ultracode is not a distinct level and reports as `xhigh`. Matches the `effort.level` field passed to [hooks](/docs/en/hooks). Only set when the current model supports the effort parameter | +| `CLAUDE_ENABLE_BYTE_WATCHDOG` | Set to `1` to force-enable the byte-level streaming idle watchdog, or set to `0` to force-disable it. `0` also turns off the [first-byte deadline](/docs/en/network-config#streaming-idle-watchdogs) on the connections where that deadline runs. When unset, the watchdog is enabled by default for direct Anthropic API and [Claude Platform on AWS](/docs/en/claude-platform-on-aws) connections, and for streaming responses on [gateway](/docs/en/gateways) connections reached through `ANTHROPIC_BASE_URL` or `ANTHROPIC_AWS_BASE_URL`; before v2.1.222 it didn't run on those gateway connections, so the event-level watchdog could report a stall there even while keep-alive pings were arriving. For timeouts and how the timers interact, see [Streaming idle watchdogs](/docs/en/network-config#streaming-idle-watchdogs) | +| `CLAUDE_ENABLE_BYTE_WATCHDOG_BEDROCK` | Set to `1` to enable the byte-level streaming idle watchdog on Amazon Bedrock `vnd.amazon.eventstream` responses, which also enables the [first-byte deadline](/docs/en/network-config#streaming-idle-watchdogs) on Bedrock streaming requests. Off by default. Configure the timeout with `CLAUDE_STREAM_IDLE_TIMEOUT_MS` | +| `CLAUDE_ENABLE_STREAM_WATCHDOG` | Set to `0` to force-disable the event-level streaming idle watchdog, or set to `1` to force-enable it. When unset, the watchdog is on by default for all providers. Before v2.1.196, the unset default was server-controlled on the direct Anthropic API and off on other providers. Configure the timeout with `CLAUDE_STREAM_IDLE_TIMEOUT_MS`; for the other stall timers that run alongside this one, see [Streaming idle watchdogs](/docs/en/network-config#streaming-idle-watchdogs) | +| `CLAUDE_ENV_FILE` | Path to a shell script whose contents Claude Code runs before each Bash command in the same shell process, so exports in the file are visible to the command. Use to persist virtualenv or conda activation across commands. Also populated dynamically by [SessionStart](/docs/en/hooks#persist-environment-variables), [Setup](/docs/en/hooks#setup), [CwdChanged](/docs/en/hooks#cwdchanged), and [FileChanged](/docs/en/hooks#filechanged) hooks | +| `CLAUDE_PID` | Claude Code sets this to its own process ID in the subprocesses it spawns: Bash and PowerShell tool commands and hook commands. On Linux, the Bash tool's shell integration uses it to refuse a `pkill` pattern that would match the Claude Code process itself; see [the error reference](/docs/en/errors#pkill-pattern-matches-the-claude-code-process). Read it from your own scripts to identify or signal the parent Claude Code process deliberately. Requires Claude Code v2.1.214 or later | +| `CLAUDE_REMOTE_CONTROL_SESSION_NAME_PREFIX` | Prefix for auto-generated [Remote Control](/docs/en/remote-control) session names when no explicit name is provided. Defaults to your machine's hostname, producing names like `myhost-graceful-unicorn`. The `--remote-control-session-name-prefix` CLI flag sets the same value for a single invocation | +| `CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS` | Deadline in milliseconds for the first response byte of a streaming request, on the connections where the [first-byte deadline](/docs/en/network-config#streaming-idle-watchdogs) runs. For how Claude Code clamps it, the extra time it adds for large request bodies, and how it picks the deadline when you leave this unset, see [No response from API](/docs/en/errors#no-response-from-api). Requires Claude Code v2.1.242 or later | +| `CLAUDE_STREAM_IDLE_TIMEOUT_MS` | Timeout in milliseconds before the event- and byte-level streaming idle watchdogs close a stalled connection. When you set this variable explicitly, the minimum is `300000` (5 minutes); lower values are silently clamped to absorb extended thinking pauses and proxy buffering, and the byte-level watchdog caps the value at 30 minutes. `CLAUDE_BYTE_STREAM_IDLE_TIMEOUT_MS` takes precedence over this variable for the byte-level watchdog. For the per-watchdog unset defaults, see [Streaming idle watchdogs](/docs/en/network-config#streaming-idle-watchdogs) | +| `CLAUDE_SUBAGENT_BG_SHELL_MAX_MS` | Maximum lifetime in milliseconds for a [background shell command](/docs/en/interactive-mode#background-bash-commands) that a [subagent](/docs/en/sub-agents) started. Default `3600000` (60 minutes). When you set `0`, Claude Code applies the default instead of removing the cap. When the subagent runs in the foreground, Claude Code also ends the command when that subagent gives its final response, regardless of this cap. See [the background command lifetime rules](/docs/en/tools-reference#background-commands). Claude Code doesn't cap main-session background commands this way. For the memory-pressure limit that covers them, see [How backgrounding works](/docs/en/interactive-mode#how-backgrounding-works) | +| `DEBUG` | Set to `1` to enable debug mode, equivalent to launching with [`--debug`](/docs/en/cli-reference#cli-flags). Debug logs are written to `~/.claude/debug/.txt`, or to the path set by `CLAUDE_CODE_DEBUG_LOGS_DIR`. Only the truthy values `1`, `true`, `yes`, and `on` enable debug mode, so namespace patterns like `DEBUG=express:*` set for other tools do not trigger it | +| `DISABLE_AUTOUPDATER` | Set to `1` to disable automatic background updates. Manual `claude update` still works. Use `DISABLE_UPDATES` to block both | +| `DISABLE_AUTO_COMPACT` | Set to `1` to disable automatic compaction when approaching the context limit. The manual `/compact` command remains available. Use when you want explicit control over when compaction occurs. Overrides the [`autoCompactEnabled`](/docs/en/settings-reference#autocompactenabled) setting | +| `DISABLE_COMPACT` | Set to `1` to disable all compaction: both automatic compaction and the manual `/compact` command | +| `DISABLE_COST_WARNINGS` | Set to `1` to disable cost warning messages | +| `DISABLE_DOCTOR_COMMAND` | Set to `1` to hide the [`/doctor`](/docs/en/commands#all-commands) setup checkup skill and its `/checkup` alias. Useful for managed deployments where users shouldn't run setup diagnostics from a session. Doesn't affect the `claude doctor` terminal command. Before v2.1.205, this variable hid the `/doctor` diagnostics screen command | +| `DISABLE_ERROR_REPORTING` | Set to any non-empty value, such as `1`, to opt out of error reporting. **Setting it to `0` or `false` still opts out**, unlike most on/off variables; unset the variable to turn error reporting back on | +| `DISABLE_EXTRA_USAGE_COMMAND` | Set to `1` to hide the `/usage-credits` command that lets users purchase additional usage beyond rate limits | +| `DISABLE_FEEDBACK_COMMAND` | Set to `1` to disable the `/feedback` command and [Claude-drafted feedback](/docs/en/tools-reference#sendfeedback-tool-behavior). Also disables `/bug` and `/share`, which report through the same path; before v2.1.212 they were aliases of `/feedback`, so the command was disabled under every name. The older name `DISABLE_BUG_COMMAND` is also accepted | +| `DISABLE_GROWTHBOOK` | Set to `1` or `true` to disable GrowthBook feature-flag fetching and use code defaults for every flag. This makes [Remote Control](/docs/en/remote-control#requirements) and the other [features that need feature-flag fetching](#features-that-need-feature-flag-fetching) unavailable. Setting it to `0` or `false` leaves fetching on. Telemetry event logging stays on unless `DISABLE_TELEMETRY` is also set | +| `DISABLE_INSTALLATION_CHECKS` | Set to `1` to disable installation warnings. Use only when manually managing the installation location, as this can mask issues with standard installations | +| `DISABLE_INSTALL_GITHUB_APP_COMMAND` | Set to `1` to hide the `/install-github-app` command. Already hidden when using third-party providers (Amazon Bedrock, Google Cloud's Agent Platform, or Microsoft Foundry) | +| `DISABLE_INTERLEAVED_THINKING` | Set to `1` to prevent sending the interleaved-thinking beta header. Useful when your LLM gateway or provider does not support [interleaved thinking](https://platform.claude.com/docs/en/build-with-claude/extended-thinking#interleaved-thinking) | +| `DISABLE_LOGIN_COMMAND` | Set to `1` to hide the `/login` command. Useful when authentication is handled externally via API keys or `apiKeyHelper` | +| `DISABLE_LOGOUT_COMMAND` | Set to `1` to hide the `/logout` command | +| `DISABLE_PROMPT_CACHING` | Set to `1` to disable [prompt caching](/docs/en/prompt-caching#disable-prompt-caching) for all models (takes precedence over per-model settings) | +| `DISABLE_PROMPT_CACHING_FABLE` | Set to `1` to disable prompt caching for Fable models | +| `DISABLE_PROMPT_CACHING_HAIKU` | Set to `1` to disable prompt caching for Haiku models | +| `DISABLE_PROMPT_CACHING_OPUS` | Set to `1` to disable prompt caching for Opus models | +| `DISABLE_PROMPT_CACHING_SONNET` | Set to `1` to disable prompt caching for Sonnet models | +| `DISABLE_TELEMETRY` | Set to any non-empty value, such as `1`, to opt out of telemetry. **Setting it to `0` or `false` still opts out**, unlike most on/off variables; unset the variable to turn telemetry back on. Telemetry events don't include user data like code, file paths, or bash commands. Also disables feature-flag fetching with the same effect as `DISABLE_GROWTHBOOK`, which makes [Remote Control](/docs/en/remote-control#requirements) and the other [features that need feature-flag fetching](#features-that-need-feature-flag-fetching) unavailable. See [Turn telemetry off for your organization](/docs/en/managed-settings#turn-telemetry-off-for-your-organization) | +| `DISABLE_UPDATES` | Set to `1` to block all updates including manual `claude update` and `claude install`. Stricter than `DISABLE_AUTOUPDATER`. Use when distributing Claude Code through your own channels and users should not self-update | +| `DISABLE_UPGRADE_COMMAND` | Set to `1` to hide the `/upgrade` command | +| `DO_NOT_TRACK` | Set to `1` to opt out of telemetry, with the same effect as `DISABLE_TELEMETRY`, including making [Remote Control](/docs/en/remote-control#requirements) and the other [features that need feature-flag fetching](#features-that-need-feature-flag-fetching) unavailable. Claude Code reads this variable as a standard boolean, so `0` leaves telemetry on, and honors it as the cross-tool convention recognized by many developer CLIs | +| `ENABLE_BETA_TRACING_DETAILED` | Set to `1`, together with `BETA_TRACING_ENDPOINT`, to turn on [detailed beta tracing](/docs/en/monitoring-usage#traces-beta), which adds content-bearing span attributes and the `claude_code.hook` span. Interactive CLI sessions also require your organization to be allowlisted for the beta. Both variables are ignored in [project and local settings](/docs/en/settings-reference#variables-claude-code-ignores-in-env) | +| `ENABLE_CLAUDEAI_MCP_SERVERS` | Set to `false` to stop Claude Code from fetching [claude.ai MCP servers](/docs/en/mcp#use-mcp-servers-from-claude-ai). Enabled by default for logged-in users. To disable per-project or per-org, set [`disableClaudeAiConnectors`](/docs/en/settings-reference#disableclaudeaiconnectors) in settings instead | +| `ENABLE_PROMPT_CACHING_1H` | Set to `1` to request a 1-hour [prompt cache TTL](/docs/en/prompt-caching#cache-lifetime) instead of the default 5 minutes. Intended for API key, [Amazon Bedrock](/docs/en/amazon-bedrock), [Google Cloud's Agent Platform](/docs/en/google-vertex-ai), [Microsoft Foundry](/docs/en/microsoft-foundry), and [Claude Platform on AWS](/docs/en/claude-platform-on-aws) users. Subscription users within included usage receive the 1-hour TTL automatically on the [main conversation](/docs/en/prompt-caching#which-ttl-each-request-gets). Subscription users drawing on [usage credits](https://support.claude.com/en/articles/12429409-extra-usage-for-paid-claude-plans) can set it to keep the 1-hour TTL. 1-hour cache writes are billed at a higher rate. To choose the TTL per request bucket instead, use `CLAUDE_CODE_PROMPT_CACHE_TTL` and `CLAUDE_CODE_SUBAGENT_PROMPT_CACHE_TTL`, which take precedence over this variable | +| `ENABLE_PROMPT_CACHING_1H_BEDROCK` | Deprecated. Use `ENABLE_PROMPT_CACHING_1H` instead | +| `ENABLE_TOOL_SEARCH` | Controls [MCP tool search](/docs/en/mcp#scale-with-mcp-tool-search). Unset, Claude Code defers all MCP tools by default. It still loads them upfront on Google Cloud's Agent Platform models earlier than the Claude 4.5 generation, on a Microsoft Foundry deployment hosted on Azure, and when `ANTHROPIC_BASE_URL` points to a non-first-party host. `true` always defers and sends the beta header, except on those same Agent Platform models and Microsoft Foundry deployments; requests fail on proxies that don't support `tool_reference`. `auto` loads upfront when tool definitions fit within 10% of context. `auto:N` sets a custom threshold, such as `auto:5` for 5%. `false` loads all tools upfront. A value you set yourself is ignored when `CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS` is set. Before v2.1.221, Claude Code disabled tool search for all models on Google Cloud's Agent Platform unless you set this variable to `true` | +| `FALLBACK_FOR_ALL_PRIMARY_MODELS` | Set to any non-empty value, such as `1`, to make every model stop retrying with a repeated-overload error when no fallback model is configured. **Setting it to `0` or `false` still enables this**, unlike most on/off variables; unset the variable to restore the default retry behavior. Without it, models Claude Code recognizes as Opus, Fable, or Mythos models stop retrying this way when you authenticate with an API key or a [third-party provider](/docs/en/third-party-integrations) rather than a Claude subscription. As of v2.1.160, a configured [fallback model chain](/docs/en/model-config#fallback-model-chains) triggers on repeated overload errors for any primary model, so this variable does not affect switching to a fallback model | +| `FORCE_AUTOUPDATE_PLUGINS` | Set to `1` to force plugin auto-updates even when the main auto-updater is disabled via `DISABLE_AUTOUPDATER` | +| `FORCE_HYPERLINK` | Set to `1` to enable clickable OSC 8 hyperlinks when your terminal supports them but isn't auto-detected, or `0` to disable them. When unset, Claude Code enables hyperlinks only when it detects terminal support. Claude Code parses this value as a number, not a Boolean, so a value such as `false`, `no`, or `off` enables hyperlinks rather than disabling them. Claude Code renders the footer [PR or merge request badge](/docs/en/interactive-mode#pr-review-status) as a hyperlink even when it can't detect terminal support, such as over SSH. Set `0` to render the badge as plain text | +| `FORCE_PROMPT_CACHING_5M` | Set to `1` to force the 5-minute prompt cache TTL even when 1-hour TTL would otherwise apply. Overrides `CLAUDE_CODE_PROMPT_CACHE_TTL`, `CLAUDE_CODE_SUBAGENT_PROMPT_CACHE_TTL`, `ENABLE_PROMPT_CACHING_1H`, and the `promptCacheTtl` and `subagentPromptCacheTtl` settings | +| `HTTP_PROXY` | Specify HTTP proxy server for network connections | +| `HTTPS_PROXY` | Specify HTTPS proxy server for network connections | +| `IS_DEMO` | Set to any non-empty value, such as `1`, to enable demo mode: hides your email and organization name from the header and `/status` output, and skips onboarding. **Setting it to `0` or `false` still enables demo mode**, unlike most on/off variables; unset the variable to turn it off. Useful when streaming or recording a session | +| `MAX_MCP_OUTPUT_TOKENS` | Maximum number of tokens allowed in MCP tool responses. Claude Code displays a warning when output exceeds 10,000 tokens. Tools that declare [`anthropic/maxResultSizeChars`](/docs/en/mcp#raise-the-limit-for-a-specific-tool) use that character limit for text content instead, but image content from those tools is still subject to this variable (default: 25000) | +| `MAX_STRUCTURED_OUTPUT_RETRIES` | Number of times Claude Code retries when the model's response fails validation against the [`--json-schema`](/docs/en/cli-reference#cli-flags) in non-interactive mode with the `-p` flag. The same retry count applies when a [workflow](/docs/en/workflows) subagent's structured output fails validation. Defaults to 5 | +| `MAX_THINKING_TOKENS` | Fixed token budget for [extended thinking](https://platform.claude.com/docs/en/build-with-claude/extended-thinking). Claude Code caps it at one token below the request's max output tokens and never below 1,024; see `CLAUDE_CODE_MAX_OUTPUT_TOKENS` for how that limit is set. When unset and thinking is enabled, models with [adaptive reasoning](/docs/en/model-config#adjust-effort-level) choose their own thinking depth, and other models use the cap. Set to `0` to disable thinking on the Anthropic API, except on [Fable models](/docs/en/model-config#extended-thinking), which can't have thinking turned off; on [third-party providers](/docs/en/third-party-integrations), `0` omits the `thinking` parameter instead. With thinking turned off on the Anthropic API, Claude Code sends effort `high` instead of a higher level to models it knows [don't accept that combination](/docs/en/errors#effort-isnt-available-with-thinking-turned-off), such as Opus 5. Nonzero values are ignored on adaptive reasoning models unless `CLAUDE_CODE_DISABLE_ADAPTIVE_THINKING` is set | +| `MCP_CLIENT_SECRET` | OAuth client secret for MCP servers that require [pre-configured credentials](/docs/en/mcp#use-pre-configured-oauth-credentials). Avoids the interactive prompt when adding a server with `--client-secret` | +| `MCP_CONNECTION_NONBLOCKING` | Controls whether startup waits for MCP servers to connect before the first query. MCP startup is non-blocking by default: servers connect in the background and their tools become available as they finish. Set to `0` to make Claude Code wait for servers to connect before the first query. Servers configured with [`alwaysLoad: true`](/docs/en/mcp#exempt-a-server-from-deferral) still make startup wait regardless, except when served from the [discovery cache](/docs/en/mcp#server-status-detail), since their tools must be present when the first prompt is built. In non-interactive mode (`-p`), Claude Code also waits for still-pending servers before the first turn regardless of this variable, with a longer deadline when you pass [`--mcp-config`](/docs/en/cli-reference#cli-flags) explicitly; see that flag's entry for the cached-server exception | +| `MCP_CONNECT_TIMEOUT_MS` | How long blocking MCP startup waits, in milliseconds, for the connection batch before snapshotting the tool list (default: 5000). Applies when `MCP_CONNECTION_NONBLOCKING=0` or for servers marked [`alwaysLoad: true`](/docs/en/mcp#exempt-a-server-from-deferral). Servers still pending at the deadline keep connecting in the background. Distinct from `MCP_TIMEOUT`, which bounds an individual server's connect attempt | +| `MCP_DISCOVERY_CACHE` | Turns the [MCP discovery cache](/docs/en/mcp#server-status-detail) on or off. With the cache on, a remote HTTP or SSE server you've used before can show the [`cached` status](/docs/en/mcp#server-status-detail), and Claude Code connects it on its first tool call instead of at startup. The cache is off by default unless a gradual rollout has enabled it for your account. Set to `1` to turn it on, or `0` to keep it off even when the rollout has enabled it. Before v2.1.238, the cache was on by default. The `cached` status requires Claude Code v2.1.221 or later | +| `MCP_DISCOVERY_CACHE_MAX_STALE_S` | Maximum age, in seconds, of a [discovery-cache](/docs/en/mcp#server-status-detail) entry (default: 14400, or 4 hours). At a start where the entry is older than that, Claude Code discards it and connects the server at startup, as it does with the cache off. Claude Code caps the value at 7 days. Before v2.1.238, the default was 86400, or 24 hours, and Claude Code didn't cap the value | +| `MCP_DISCOVERY_CACHE_STRIKES` | At a start where a [discovery-cache](/docs/en/mcp#server-status-detail) entry is older than `MCP_DISCOVERY_CACHE_TTL_S`, Claude Code refreshes it in the background. This variable sets how many refreshes in a row can fail before Claude Code discards the entry and connects the server at the next start instead (default: 1). Raise it if your network connection drops occasionally, so that one failed refresh doesn't discard the entry. Requires Claude Code v2.1.238 or later | +| `MCP_DISCOVERY_CACHE_TTL_S` | Seconds for which Claude Code uses a [discovery-cache](/docs/en/mcp#server-status-detail) entry without refreshing it (default: 900). At a start where the entry is older than that, Claude Code still uses it but refreshes it in the background. Once the entry is older than `MCP_DISCOVERY_CACHE_MAX_STALE_S`, Claude Code discards it instead. Claude Code caps the value at `MCP_DISCOVERY_CACHE_MAX_STALE_S`, which is 4 hours by default. Before v2.1.238, Claude Code didn't cap the value | +| `MCP_OAUTH_CALLBACK_PORT` | Fixed port for the OAuth redirect callback, as an alternative to `--callback-port` when adding an MCP server with [pre-configured credentials](/docs/en/mcp#use-pre-configured-oauth-credentials) | +| `MCP_PROTOCOL_NEGOTIATION` | On the [v2 MCP client runtime](/docs/en/mcp#mcp-client-runtimes) only, whether Claude Code probes servers for MCP protocol revision 2026-07-28. Set `auto` to probe HTTP, claude.ai connector, and stdio servers; a server that doesn't answer the probe connects on the earlier protocol instead, as SSE and WebSocket servers always do. Set `legacy` to skip the probe for every server. Without the variable, Claude Code probes HTTP and claude.ai connector servers on Claude Code v2.1.232 or later, with the exceptions the [MCP client runtimes](/docs/en/mcp#mcp-client-runtimes) section lists. Any other value is ignored with a warning in the debug log. Requires Claude Code v2.1.221 or later | +| `MCP_REMOTE_SERVER_CONNECTION_BATCH_SIZE` | Maximum number of remote MCP servers (HTTP/SSE) to connect in parallel during startup (default: 20) | +| `MCP_SDK_GENERATION` | Pin which [MCP client runtime](/docs/en/mcp#mcp-client-runtimes) this process connects to MCP servers with: `v1`, built on MCP TypeScript SDK 1.x, or `v2`, built on [MCP TypeScript SDK 2.0](https://ts.sdk.modelcontextprotocol.io/v2/). Without the variable, Claude Code uses v2 on Claude Code v2.1.232 or later, except where that section says it uses v1. On Claude Code v2.1.221 or later, the v2 runtime checks the issuer an MCP OAuth server returns in its authorization response and fails the sign-in with an error that begins `Issuer mismatch in authorization response` when it doesn't match. The v1 runtime doesn't run this check. If you set an unrecognized value, Claude Code ignores it and writes a warning to the debug log. Claude Code reads the value once per process. Requires Claude Code v2.1.218 or later | +| `MCP_SERVER_CONNECTION_BATCH_SIZE` | Maximum number of local MCP servers (stdio) to connect in parallel during startup (default: 3) | +| `MCP_TIMEOUT` | Timeout in milliseconds for MCP server startup (default: 30000, or 30 seconds) | +| `MCP_TOOL_TIMEOUT` | Timeout in milliseconds for MCP tool execution (default: 100000000, about 28 hours). For an HTTP, SSE, or claude.ai connector server, each request also times out after 60 seconds by default; set this variable, or the per-server `timeout`, above 60000 to raise that per-request limit. A lower value still shortens the overall tool-execution timeout but leaves the per-request limit at 60 seconds. Stdio and WebSocket servers have no per-request timer. A per-server `timeout` field in `.mcp.json` overrides this for that server. A per-server `timeout` of at least 1000 also sets the minimum idle window for that server's tool calls, so `CLAUDE_CODE_MCP_TOOL_IDLE_TIMEOUT` never aborts them sooner; this floor requires Claude Code v2.1.203 or later. For the env variable, values below 1000 are floored to one second; for the per-server field, values below 1000 are ignored | +| `NO_PROXY` | List of domains and IPs to which requests will be directly issued, bypassing proxy | +| `OTEL_ATTRIBUTE_VALUE_LENGTH_LIMIT` | Standard OpenTelemetry SDK limit on attribute value length. Claude Code caps content-bearing telemetry attributes at the smaller of this and `CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH`, so the truncation marker stays within the SDK limit. Claude Code reads the `OTEL_LOGRECORD_ATTRIBUTE_VALUE_LENGTH_LIMIT` and `OTEL_SPAN_ATTRIBUTE_VALUE_LENGTH_LIMIT` variants the same way, and the smallest set value applies to all signals. Requires Claude Code v2.1.214 or later. See [Monitoring](/docs/en/monitoring-usage#common-configuration-variables) | +| `OTEL_LOG_ASSISTANT_RESPONSES` | Set to `1` to include the model's response text on `assistant_response` OpenTelemetry log events. When unset, the value of `OTEL_LOG_USER_PROMPTS` is used instead. Set to `0` to keep responses redacted even when `OTEL_LOG_USER_PROMPTS` is set. Requires Claude Code v2.1.193 or later. See [Monitoring](/docs/en/monitoring-usage#assistant-response-event) | +| `OTEL_LOG_RAW_API_BODIES` | Emit Anthropic Messages API request and response JSON as `api_request_body` / `api_response_body` log events. Set to `1` for inline bodies truncated at the content limit, or `file:` to write untruncated bodies to disk and emit a `body_ref` path instead. `CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH` configures the content limit, 60 KB by default. Disabled by default; bodies include the entire conversation history. Set it in your shell, user settings, or managed settings. Ignored in [project and local settings](/docs/en/settings-reference#variables-claude-code-ignores-in-env). See [Monitoring](/docs/en/monitoring-usage#api-request-body-event) | +| `OTEL_LOG_TOOL_CONTENT` | Set to `1` to include tool input and output content in OpenTelemetry span events. Disabled by default to protect sensitive data. See [Monitoring](/docs/en/monitoring-usage) | +| `OTEL_LOG_TOOL_DETAILS` | Set to `1` to include tool input arguments, MCP server names, user-authored workflow names, raw error strings on tool failures, the refusal `category` on `api_refusal` events, and other tool details in OpenTelemetry traces and logs. Disabled by default to protect PII. See [Monitoring](/docs/en/monitoring-usage) | +| `OTEL_LOG_USER_PROMPTS` | Set to `1` to include user prompt text in OpenTelemetry traces and logs. Disabled by default (prompts are redacted). See [Monitoring](/docs/en/monitoring-usage) | +| `OTEL_METRICS_INCLUDE_ACCOUNT_UUID` | Set to `false` to exclude account UUID from metrics attributes (default: included). See [Monitoring](/docs/en/monitoring-usage) | +| `OTEL_METRICS_INCLUDE_ENTRYPOINT` | Set to `true` to include the session entrypoint in metrics attributes (default: excluded). Added in v2.1.152. See [Monitoring](/docs/en/monitoring-usage) | +| `OTEL_METRICS_INCLUDE_RESOURCE_ATTRIBUTES` | As of v2.1.161, Claude Code attaches `OTEL_RESOURCE_ATTRIBUTES` keys to metric datapoint labels. Set to `false` to exclude them (default: included). See [Monitoring](/docs/en/monitoring-usage#multi-team-organization-support) | +| `OTEL_METRICS_INCLUDE_SESSION_ID` | Set to `false` to exclude session ID from metrics attributes (default: included). See [Monitoring](/docs/en/monitoring-usage) | +| `OTEL_METRICS_INCLUDE_VERSION` | Set to `true` to include Claude Code version in metrics attributes (default: excluded). See [Monitoring](/docs/en/monitoring-usage) | +| `SLASH_COMMAND_TOOL_CHAR_BUDGET` | Override the character budget for skill metadata shown to the [Skill tool](/docs/en/skills#control-who-invokes-a-skill). The budget scales dynamically at 1% of the context window, with a fallback of 8,000 characters. Legacy name kept for backwards compatibility | +| `TASK_MAX_OUTPUT_LENGTH` | Maximum number of characters of a [background task's](/docs/en/tools-reference#background-commands) output that the `TaskOutput` tool keeps (default: 32000; maximum: 160000). If you set the [`taskOutputMaxChars`](/docs/en/settings-reference#taskoutputmaxchars) setting, Claude Code ignores this variable | +| `USE_BUILTIN_RIPGREP` | Set to `0` to use system-installed `rg` instead of `rg` included with Claude Code | +| `VERTEX_REGION_CLAUDE_3_5_HAIKU` | Override region for Claude 3.5 Haiku when using Google Cloud's Agent Platform | +| `VERTEX_REGION_CLAUDE_3_5_SONNET` | Override region for Claude 3.5 Sonnet when using Google Cloud's Agent Platform | +| `VERTEX_REGION_CLAUDE_3_7_SONNET` | Override region for Claude 3.7 Sonnet when using Google Cloud's Agent Platform | +| `VERTEX_REGION_CLAUDE_4_0_OPUS` | Override region for Claude 4.0 Opus when using Google Cloud's Agent Platform | +| `VERTEX_REGION_CLAUDE_4_0_SONNET` | Override region for Claude 4.0 Sonnet when using Google Cloud's Agent Platform | +| `VERTEX_REGION_CLAUDE_4_1_OPUS` | Override region for Claude 4.1 Opus when using Google Cloud's Agent Platform | +| `VERTEX_REGION_CLAUDE_4_5_OPUS` | Override region for Claude Opus 4.5 when using Google Cloud's Agent Platform | +| `VERTEX_REGION_CLAUDE_4_5_SONNET` | Override region for Claude Sonnet 4.5 when using Google Cloud's Agent Platform | +| `VERTEX_REGION_CLAUDE_4_6_OPUS` | Override region for Claude Opus 4.6 when using Google Cloud's Agent Platform | +| `VERTEX_REGION_CLAUDE_4_6_SONNET` | Override region for Claude Sonnet 4.6 when using Google Cloud's Agent Platform | +| `VERTEX_REGION_CLAUDE_4_7_OPUS` | Override region for Claude Opus 4.7 when using Google Cloud's Agent Platform | +| `VERTEX_REGION_CLAUDE_4_8_OPUS` | Override region for Claude Opus 4.8 when using Google Cloud's Agent Platform. Added in v2.1.154 | +| `VERTEX_REGION_CLAUDE_5_OPUS` | Override region for Claude Opus 5 when using Google Cloud's Agent Platform. Added in v2.1.219 | +| `VERTEX_REGION_CLAUDE_5_SONNET` | Override region for Claude Sonnet 5 when using Google Cloud's Agent Platform. Added in v2.1.197 | +| `VERTEX_REGION_CLAUDE_FABLE_5` | Override region for Claude Fable 5 when using Google Cloud's Agent Platform. Added in v2.1.170 | +| `VERTEX_REGION_CLAUDE_FABLE_5_1` | Override region for Claude Fable 5.1 when using Google Cloud's Agent Platform. Added in v2.1.255 | +| `VERTEX_REGION_CLAUDE_HAIKU_4_5` | Override region for Claude Haiku 4.5 when using Google Cloud's Agent Platform | Standard OpenTelemetry exporter variables (`OTEL_METRICS_EXPORTER`, `OTEL_LOGS_EXPORTER`, `OTEL_EXPORTER_OTLP_ENDPOINT`, `OTEL_EXPORTER_OTLP_PROTOCOL`, `OTEL_EXPORTER_OTLP_HEADERS`, `OTEL_METRIC_EXPORT_INTERVAL`, `OTEL_RESOURCE_ATTRIBUTES`, and signal-specific variants) are also supported. See [Monitoring](/docs/en/monitoring-usage) for configuration details. @@ -504,6 +504,7 @@ With fetching off, you can't: * Use [Remote Control](/docs/en/remote-control#requirements) * [Message sessions beyond this machine](/docs/en/cross-session-messaging#message-sessions-on-other-machines); messaging between sessions on this machine works with fetching off * Run [`claude import` or the `/import` command](/docs/en/cli-reference#cli-commands) +* Run [`/skill-doctor`](/docs/en/skills#find-unused-skills) or open its report in the `/plugin` **Stats** tab * Use [the advisor tool](/docs/en/advisor#requirements) * Read or reply to [comments on an artifact](/docs/en/artifacts#collect-comments-on-an-artifact) * Get the [v2 MCP client runtime](/docs/en/mcp#mcp-client-runtimes) and its protocol probe without setting `MCP_SDK_GENERATION` and `MCP_PROTOCOL_NEGOTIATION`; Claude Code uses the v1 runtime unless you set `MCP_SDK_GENERATION=v2`, and skips the probe unless you set `MCP_PROTOCOL_NEGOTIATION=auto` diff --git a/content/en/docs/claude-code/errors.md b/content/en/docs/claude-code/errors.md index dc4a84ddf..403facd13 100644 --- a/content/en/docs/claude-code/errors.md +++ b/content/en/docs/claude-code/errors.md @@ -166,6 +166,7 @@ Match the message you see to a section below. | `Cannot switch renderers while work is running in the background` | [Command-line errors](#cannot-switch-renderers-in-this-session) | | `Couldn't read your Zed keymap` / `Couldn't back up your Zed keymap` / `Couldn't update your Zed keymap` | [Command-line errors](#terminal-setup-left-your-zed-keymap-unchanged) | | `Your Zed keymap isn't a readable list of keybindings` | [Command-line errors](#terminal-setup-left-your-zed-keymap-unchanged) | +| `Skill usage reports are not available on this connection.` | [Command-line errors](#skill-usage-reports-are-not-available-on-this-connection) | | `Marketplace "" is registered from an untrusted source` | [Plugin errors](#marketplace-is-registered-from-an-untrusted-source) | | `references ${user_config.*} in a shell-form command` | [Plugin errors](#plugin-command-references-user-config) | | `Monitor "" from plugin references ${user_config.*} in its command` | [Plugin errors](#plugin-command-references-user-config) | @@ -211,7 +212,8 @@ Match the message you see to a section below. | `exited before it became reachable` | [Background session errors](#background-service-exited-before-it-became-reachable) | | `Claude Code process exited with code N` | [Wrapper and IDE errors](#claude-code-process-exited-with-code-n) | | `Could not locate the Claude CLI on PATH` | [Wrapper and IDE errors](#could-not-locate-the-claude-cli-on-path) | -| `Restored the code, but skipped N files` | [Rewind warnings](#restored-the-code-but-skipped-files) | +| `Restored the code, but skipped N files` | [Rewind warnings and errors](#restored-the-code-but-skipped-files) | +| `No files were restored: N files failed (backup missing, or the file could not be updated)` | [Rewind warnings and errors](#no-files-were-restored) | | `Transcript writes are failing (...)` | [Session saving warnings](#transcript-writes-are-failing) | | `Transcript saving is off — CLAUDE_CODE_SKIP_PROMPT_HISTORY is set` | [Session saving warnings](#transcript-saving-is-off-skip-prompt-history) | | `Transcript saving is off — inherited CLAUDE_CODE_CHILD_SESSION marker` | [Session saving warnings](#transcript-saving-is-off-child-session-marker) | @@ -219,11 +221,14 @@ Match the message you see to a section below. | `Claude Code exited after an unrecoverable interface error (...)` | [Configuration warnings](#exited-after-an-unrecoverable-interface-error) | | `Agent descriptions are over the 15.0k-token limit` | [Configuration warnings](#agent-descriptions-are-over-the-15000-token-limit) | | `Ignoring N permissions.allow entries from ... this workspace has not been trusted` | [Configuration warnings](#workspace-has-not-been-trusted) | +| `is a network path, which cannot be added as a working directory` | [Configuration warnings](#working-directory-is-a-network-path) | | `Remote managed settings failed to load ()` | [Configuration warnings](#remote-managed-settings-failed-to-load) | +| `MCP server is blocked by enterprise managed policy` | [Configuration warnings](#mcp-server-is-blocked-by-enterprise-managed-policy) | | `Managed settings document could not be parsed as a JSON object; none of its settings are in effect. Fix or remove it.` | [Configuration warnings](#managed-settings-document-could-not-be-parsed) | | `Managed settings drop-in directory could not be read` | [Configuration warnings](#managed-settings-document-could-not-be-parsed) | | `"crossSessionInbound" must be one of "accept", "hold", "refuse"` | [Configuration warnings](#crosssessioninbound-must-be-one-of-accept-hold-refuse) | | `headersHelper not run — this workspace has no persisted trust` | [Configuration warnings](#headershelper-not-run) | +| `Invalid permission rule "..." was skipped: Malformed Tool(content) rule` | [Configuration warnings](#malformed-tool-content-rule) | | `... is not matched by file permission checks` | [Configuration warnings](#is-not-matched-by-file-permission-checks) | | `... has a wildcard before the rest of the command` | [Configuration warnings](#has-a-wildcard-before-the-rest-of-the-command) | | `CLAUDE_CODE_DISABLE_1M_CONTEXT is set, but the 200K limit isn't enforced` | [Configuration warnings](#the-200k-limit-isnt-enforced) | @@ -284,7 +289,7 @@ You can tune retry behavior with these environment variables: | :---------------------------------------------------- | :------ | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | [`CLAUDE_CODE_MAX_RETRIES`](/docs/en/env-vars) | 10 | Number of retry attempts. Capped at 15 as of v2.1.186; as of v2.1.199 `CLAUDE_CODE_RETRY_WATCHDOG` raises the default and removes the cap. Lower it to surface failures faster in scripts. | | [`CLAUDE_CODE_RETRY_WATCHDOG`](/docs/en/env-vars) | unset | Set to `1` in unattended sessions such as CI jobs to retry `429` and `529` capacity errors indefinitely instead of failing after `CLAUDE_CODE_MAX_RETRIES` attempts. Claude Code fails at once on a `429` that reports a spend limit or exhausted usage credits, even one from a [gateway spend cap](#spend-limit-reached) that resets on a schedule. Before v2.1.239, the watchdog retried these indefinitely. On v2.1.199 or later it also raises the default retry count for other transient errors, such as server errors, timeouts, and dropped connections, to 300, roughly three hours of backoff, and removes the cap of 15 on `CLAUDE_CODE_MAX_RETRIES` if you set that variable explicitly. | -| [`API_TIMEOUT_MS`](/docs/en/env-vars) | 600000 | Per-request timeout in milliseconds. Raise it for slow networks or proxies. It also bounds the [first-byte deadline](#no-response-from-api). | +| [`API_TIMEOUT_MS`](/docs/en/env-vars) | 600000 | Per-request timeout in milliseconds. Raise it for slow networks or proxies. It also caps how long Claude Code waits for response headers, described in [No response from API](#no-response-from-api). | | [`CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS`](/docs/en/env-vars) | unset | Deadline in milliseconds for the first response byte of a streaming request. Requires Claude Code v2.1.242 or later. For how Claude Code picks the deadline when this is unset, see [No response from API](#no-response-from-api). | ## Server errors @@ -346,27 +351,27 @@ This can happen during periods of high load or when the model is generating a ve ### No response from API -Claude Code sent a streaming request and the API returned no response headers within the deadline for the first byte, so Claude Code aborted the request instead of waiting for the full `API_TIMEOUT_MS` request timeout, 10 minutes by default. Claude Code sends the request again at most once per model request, within the retry budget, and ends the turn with this message when that attempt goes unanswered too. When you set [`CLAUDE_CODE_RETRY_WATCHDOG`](/docs/en/env-vars), the one-retry cap doesn't apply and Claude Code retries under the budget described in [Tune retry behavior](#tune-retry-behavior). +Claude Code sent a streaming request and the API returned no response headers within the deadline for the first byte, so Claude Code aborted the request instead of waiting for the full `API_TIMEOUT_MS` request timeout, 10 minutes by default. Claude Code sends the request again at most once, if the [retry budget](#tune-retry-behavior) allows. When the retry goes unanswered too, the turn ends with this message, which shows how long each attempt waited. When you set [`CLAUDE_CODE_RETRY_WATCHDOG`](/docs/en/env-vars), the one-retry cap doesn't apply and Claude Code retries under the budget described in [Tune retry behavior](#tune-retry-behavior). ```text theme={null} -API Error: No response from API +API Error: No response from API (waited 3m, then 10m on the retry). If a proxy or gateway on your network holds responses until they complete, raise API_TIMEOUT_MS or CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS to wait longer. ``` -Claude Code picks the deadline from the first of these that applies: +Claude Code sets the first attempt's wait for response headers and the retry's wait separately: -* [`CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS`](/docs/en/env-vars), when you set it to 1 or more: Claude Code uses that value, clamped to between 10 seconds and 30 minutes, and adds one second for every 32KB of request body. Claude Code ignores 0 and lower. -* [`API_TIMEOUT_MS`](/docs/en/env-vars), when you set it above the byte-level watchdog timeout, 180 seconds on the Anthropic API and 300 seconds elsewhere: Claude Code uses one second less than the value you set. -* Otherwise, Claude Code uses the byte-level watchdog timeout, and adds one second for every 32KB of request body. +* **First attempt**: [`CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS`](/docs/en/env-vars) when you set it to 1 or more, clamped to between 10 seconds and 30 minutes. Otherwise Claude Code uses the byte-level watchdog timeout listed in [Streaming idle watchdogs](/docs/en/network-config#streaming-idle-watchdogs), so the variables that change that timeout change this wait too. Either way, Claude Code adds one second for every 32KB of request body. +* **Retry**: one second less than `API_TIMEOUT_MS`, just under 10 minutes by default, so that the retry can outlast a proxy or gateway that holds the response until generation completes. On Amazon Bedrock, the retry uses the same deadline as the first attempt, and the message shows one duration instead of two. -Whichever case applies, the deadline never exceeds one second less than a positive `API_TIMEOUT_MS`, and a positive `API_TIMEOUT_MS` under 11 seconds turns the deadline off. See [Streaming idle watchdogs](/docs/en/network-config#streaming-idle-watchdogs) for the variables that change the watchdog timeout and the connections the deadline runs on. The byte-level watchdog starts only once the response headers arrive, so a response that stops sending bytes after that follows the [stalled-stream rules](#automatic-retries) instead of this deadline. +Neither wait exceeds one second less than a positive `API_TIMEOUT_MS`, and a positive `API_TIMEOUT_MS` under 11 seconds turns the deadline off. The byte-level watchdog starts only once the response headers arrive, so a response that stops sending bytes after that follows the [stalled-stream rules](#automatic-retries) instead of this deadline. **What to do:** * Send your message again. Your original message is still in the conversation, so for a long prompt you can type `try again` instead of pasting the whole thing. * If it repeats, treat it as a [network or proxy problem](#unable-to-connect-to-api). A proxy that accepts the connection and never forwards the request produces this error on every attempt. -* On a slow network, set `CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS` to the deadline you want, or set `API_TIMEOUT_MS` above the watchdog timeout. +* If a proxy or gateway on your network holds responses until they complete, raise `API_TIMEOUT_MS` so the retry waits longer. On Amazon Bedrock, raise `CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS` as well. +* If the first attempt keeps timing out and the retry then succeeds, raise `CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS` so the first attempt waits long enough too. -Before v2.1.242, Claude Code waited for the full `API_TIMEOUT_MS` request timeout, 10 minutes by default, before failing an unanswered streaming request. +Before v2.1.242, Claude Code waited for the full `API_TIMEOUT_MS` request timeout, 10 minutes by default, before failing an unanswered streaming request. Before v2.1.261, the retry waited the same deadline as the first attempt and the message showed no durations. ### The response above may be incomplete @@ -2384,6 +2389,18 @@ The first line of the message names the cause: Before v2.1.247, `/terminal-setup` couldn't parse a Zed keymap that used `//` comments or trailing commas, and it replaced the entire file with only its own binding while reporting the binding as installed. To restore a keymap an earlier version replaced, use the `.bak` backup file described under [Enter multiline prompts](/docs/en/terminal-config#enter-multiline-prompts). +### Skill usage reports are not available on this connection + +You ran [`/skill-doctor`](/docs/en/skills#find-unused-skills) over [Remote Control](/docs/en/remote-control), from your phone or browser. Claude Code doesn't send the skill usage report over Remote Control and replies with this message instead: + +```text theme={null} +Skill usage reports are not available on this connection. +``` + +**What to do:** + +* Run `/skill-doctor` in the terminal on the machine where the session is running, or run `claude -p "/skill-doctor"` there + ## Plugin errors These errors come from [plugin](/docs/en/plugins) and [marketplace](/docs/en/plugin-marketplaces) configuration. For plugin problems that don't produce one of the messages on this page, such as a marketplace URL that doesn't load or a plugin that installs but doesn't appear, see [Plugin troubleshooting](/docs/en/discover-plugins#troubleshooting). @@ -2460,11 +2477,20 @@ commands path escapes plugin directory: ./../shared.md In `claude plugin` command output, the same error reads `Path escapes plugin directory: ./../shared.md (commands)`. +Claude Code rejects both a path that points outside the plugin as written, such as `../shared-utils`, and a symlink that leads outside the plugin and isn't one the [marketplace symlink rules](/docs/en/plugins-reference#share-files-within-a-marketplace-with-symlinks) allow. For a symlink, the message also says where the path resolves: + +```text theme={null} +commands path escapes plugin directory: ./commands/deploy.md — it resolves to /home/user/shared/deploy.md, outside the plugin directory +``` + Before v2.1.251, Claude Code loaded a `commands` path declared in a marketplace entry even when it pointed outside the plugin directory. Claude Code already rejected paths declared in `plugin.json` and the other component paths in a marketplace entry. +Before v2.1.257, the check looked only at the path's spelling, not at where a symlink leads. + **What to do:** * Move the referenced file inside the plugin directory and point the path at it with a `./` relative path +* If the path is a symlink to a file outside the plugin, replace the symlink with a copy of the file * To share files with other plugins in the same marketplace, link them with a symlink inside the plugin directory, following the [symlink rules](/docs/en/plugins-reference#share-files-within-a-marketplace-with-symlinks) ### Failed to load marketplace configuration @@ -3045,9 +3071,9 @@ Failed to run Claude Code: Error: Could not locate the Claude CLI on PATH. Launc * Set the PATH entry as a user or system environment variable, not in your PowerShell profile. The extension doesn't run your profile, so a PATH edit that lives only there never reaches it. * Restart VS Code after changing PATH. The extension checks the PATH that VS Code captured at startup, so a PATH change takes effect only after a restart. -## Rewind warnings +## Rewind warnings and errors -This warning comes from a [`/rewind`](/docs/en/checkpointing) code restore. It reports paths the restore refused to touch; the restore completed for every other tracked file. +These messages come from a [`/rewind`](/docs/en/checkpointing) code restore. `Restored the code, but skipped N files` is a warning that Claude Code skipped some paths. `No files were restored` is an error that means it restored nothing.

Restored the code, but skipped files @@ -3071,6 +3097,27 @@ Restored the code, but skipped 2 files: the tracked path is (or became) a link o * If a skipped file is a link you created on purpose, such as a config file managed by a dotfile manager or a file hard-linked by tools like pnpm, the rewind left its contents alone. To undo the session's changes to it, ask Claude to reverse the edit or edit the file yourself * If you didn't create the link, inspect the path before trusting its contents: something replaced the file after the checkpoint +

+ No files were restored +

+ +Claude Code shows this message when you restore code with [`/rewind`](/docs/en/checkpointing) and it can't restore any of the files in that checkpoint. For each file, either the backup Claude Code saved before editing it is missing, or Claude Code couldn't write to or delete the file. + +```text theme={null} +Failed to restore the code: +No files were restored: 1 file failed (backup missing, or the file could not be updated) +``` + +Claude Code deletes a session's backups in the [retention sweep](/docs/en/claude-directory#cleaned-up-automatically), by default about 30 days after the session last saved one. If you resume a session after that, `/rewind` still lists its checkpoints, but rewinding to one of them can fail with this error. If the message also says `N paths were skipped for link safety`, see [Restored the code, but skipped files](#restored-the-code-but-skipped-files) for those paths. + +**What to do:** + +* Undo the changes another way: ask Claude to reverse its edits, or restore the files from version control. When the backups are gone, running `/rewind` again fails the same way. +* If Claude Code couldn't write or delete a file, fix what blocks the write, such as file permissions, then run `/rewind` again. +* To keep backups longer in future sessions, raise [`cleanupPeriodDays`](/docs/en/settings-reference#cleanupperioddays). + +Before v2.1.260, Claude Code silently skipped files whose backups were missing, and the rewind appeared to succeed. + ## Session saving warnings Claude Code shows these warnings on a persistent line below the input box when it isn't saving your session transcript. The session keeps working either way; the warnings tell you the session may be missing from [`--resume`](/docs/en/sessions) later. @@ -3202,6 +3249,30 @@ Ignoring 2 permissions.allow entries from .claude/settings.local.json: this work * In [non-interactive mode](/docs/en/headless) with `-p` no dialog is shown. Set the `hasTrustDialogAccepted` entry in `~/.claude.json` using the exact `projects` key the message prints. * If the message names `.claude/settings.local.json` and you started Claude Code outside a git repository or in your home directory, update to v2.1.200 or later. Versions 2.1.196 through 2.1.199 treated your own `.claude/settings.local.json` as repository-supplied in those workspaces. On v2.1.207 and later, updating isn't enough outside a git repository if you haven't trusted the folder: determining that a folder isn't inside a repository runs git, and Claude Code runs that check only after you accept the trust dialog, so use the first step. Your home directory and any other [configuration home](/docs/en/permissions#project-allow-rules-and-workspace-trust) are exempt and don't wait for the dialog. See [Project allow rules and workspace trust](/docs/en/permissions#project-allow-rules-and-workspace-trust). +### Working directory is a network path + +Claude Code doesn't add network paths as working directories. Looking up a network path can contact the host it names, and on Windows that contact can send the host your credentials, so Claude Code refuses the path without looking it up. You see this message when you run `/add-dir` with such a path, or as a warning at startup. When it appears at startup, Claude Code starts without that directory. + +```text theme={null} +\\server\share is a network path, which cannot be added as a working directory. On Windows, map the share to a drive letter and pass it at launch with --add-dir (a drive letter added mid-session does not yet carry remote-read trust). +``` + +Paths that Claude Code refuses this way include: + +* UNC shares such as `\\server\share` +* Automount paths such as `/net/`, unless you launched Claude Code from a directory under that host's automount +* Local paths that reach a network location through a symbolic link or junction + +Mapped drive letters and `\\wsl$` paths don't count as network paths. + +**What to do:** + +* On Windows, map the share to a drive letter, for example with `net use Z: \\server\share`, and pass the drive at launch with `claude --add-dir Z:\`. +* On macOS or Linux, mount the share at a local path and add that path instead. +* If the path is in `permissions.additionalDirectories`, remove it from the settings file that lists it. + +Before v2.1.257, Claude Code accepted a reachable network path as a working directory. +

Remote managed settings failed to load

@@ -3218,6 +3289,30 @@ Your session is eligible for [server-managed settings](/docs/en/server-managed-s Before v2.1.248, Claude Code reported a failed settings fetch only in the debug log. +

+ MCP server is blocked by enterprise managed policy +

+ +You selected **Reconnect** on a server in `/mcp`, or turned a disabled server back on there, and a setting that [restricts MCP servers](/docs/en/managed-mcp) blocks that server. Claude Code refuses to connect it and shows: + +```text theme={null} +MCP server is blocked by enterprise managed policy +``` + +Any of these settings can produce the message: + +* A [`deniedMcpServers`](/docs/en/managed-mcp#policy-based-control-with-allowlists-and-denylists) entry that matches the server, including one in your own `~/.claude/settings.json` or the project's `.claude/settings.json` +* An [`allowedMcpServers`](/docs/en/managed-mcp#policy-based-control-with-allowlists-and-denylists) list that the server doesn't match +* [`strictPluginOnlyCustomization`](/docs/en/settings-reference#strictpluginonlycustomization) with `mcp` locked, which blocks servers configured in `~/.claude.json` and `.mcp.json` +* [`disableClaudeAiConnectors`](/docs/en/mcp#disable-claude-ai-connectors), when the server is a claude.ai connector + +**What to do:** + +* Check your own user and project settings files for one of these settings and change or remove it +* If none of your own settings explains the block, ask your administrator which managed setting blocks the server + +Before v2.1.257, **Reconnect** and re-enable in `/mcp` could connect a server that a mid-session policy update blocked. +

Managed settings document could not be parsed

@@ -3265,6 +3360,23 @@ The `projects` key the message prints is the folder [Project allow rules and wor * Set the `hasTrustDialogAccepted` entry in `~/.claude.json` yourself, using the exact `projects` key the message prints * If you started the session in your home directory, work from a project directory you have trusted. When you accept the trust dialog in your home directory, Claude Code holds that trust for the current session only. +

+ Malformed Tool(content) rule +

+ +A [permission rule](/docs/en/permissions#permission-rule-syntax) in one of your settings files doesn't have the shape `Tool` or `Tool(content)`, for example because text follows the closing parenthesis or one of the parentheses is missing. Claude Code skips the rule and lists it in the invalid-settings dialog when an interactive session starts, and in [`claude doctor`](/docs/en/debug-your-config#check-resolved-settings) output: + +```text theme={null} +Invalid permission rule "Bash(ls) x" was skipped: Malformed Tool(content) rule. Rules take the form Tool or Tool(content) and must end at the closing ")"; parentheses inside the content are literal +``` + +**What to do:** + +* In the settings file listed with the message, rewrite the rule so it ends at its closing parenthesis, for example `Bash(ls *)` in place of `Bash(ls) x` +* Leave parentheses inside the content as they are. They're literal, so a rule such as `Edit(./Finance (2024)/**)` is valid without escaping + +Before v2.1.260, Claude Code reported a rule with unmatched parentheses as `Mismatched parentheses`. + ### Is not matched by file permission checks Claude Code found a `Write`, `NotebookEdit`, `MultiEdit`, or `Glob` [permission rule](/docs/en/permissions#read-and-edit) with a path in one of your [settings files](/docs/en/settings#where-settings-live), in [managed settings](/docs/en/managed-settings), or in a `--allowedTools`, `--disallowedTools`, or `--settings` flag value. It checks file permissions against `Edit` and `Read` rules only, so it never consults a path rule that names one of the other file tools. It keeps the rule and changes nothing else; the warning names the rule, its source in parentheses, and the replacement to write: diff --git a/content/en/docs/claude-code/headless.md b/content/en/docs/claude-code/headless.md index 1e1680244..079ffd4e3 100644 --- a/content/en/docs/claude-code/headless.md +++ b/content/en/docs/claude-code/headless.md @@ -64,9 +64,13 @@ In bare mode Claude has access to the Bash, file read, and file edit tools. Pass ### Background tasks at exit -If Claude starts a [background Bash task](/docs/en/tools-reference#bash-tool-behavior) during a `claude -p` run, for example a dev server or a watch build, that shell is terminated about five seconds after Claude has returned its final result and stdin has closed. The grace period lets a task that finishes right after the result still deliver its output. Before v2.1.163, a never-exiting background process would hold the `claude -p` invocation open indefinitely. +If Claude starts a [background Bash task](/docs/en/tools-reference#bash-tool-behavior) during a `claude -p` run, for example a dev server or a watch build, that shell is terminated about five seconds after Claude has returned its final result and stdin has closed. The grace period lets a task that finishes right after the result still deliver its output. -Background [subagents](/docs/en/sub-agents) and workflows are exempt from the five-second grace because their result is part of the final output, so `claude -p` waits for them to complete. From v2.1.182, that wait is capped at ten minutes of continuous idle waiting by default, so a stuck background agent can't hold the process open indefinitely. Adjust the cap with [`CLAUDE_CODE_PRINT_BG_WAIT_CEILING_MS`](/docs/en/env-vars), or set it to `0` to wait without a limit. +If Claude starts a background [subagent](/docs/en/sub-agents) or workflow, `claude -p` instead stays open until that work completes, because its result is part of the final output. + +By default the wait ends after 10 minutes of continuous idle waiting, so a stuck subagent or workflow can't hold the process open indefinitely. At that point Claude Code stops whatever is still running and drops its partial result. To change the limit, set [`CLAUDE_CODE_PRINT_BG_WAIT_CEILING_MS`](/docs/en/env-vars), or set it to `0` to wait without one. + +If Claude starts a [Monitor](/docs/en/tools-reference#monitor-tool) watch during a `claude -p` run, Claude Code waits for the watch until it times out or the ten-minute cap ends the wait, whichever comes first. While it waits, Claude keeps responding to what the watch reports. By default, a watch times out five minutes after Claude starts it. ### Stop a run with SIGTERM @@ -191,17 +195,18 @@ When you enable either option, Claude Code forwards messages from [subagents at When an API request fails with a retryable error, Claude Code emits a `system/api_retry` event before retrying. On v2.1.246 or later, when a `401` or `403` rejects an [`apiKeyHelper`](/docs/en/settings-reference#apikeyhelper) credential, Claude Code makes the first two retries quietly with no event, then emits the event as usual from the third consecutive retry onward. The quiet retries still count toward `attempt`. You can use the event to show retry progress in your own interface. -| Field | Type | Description | -| ---------------- | --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| `type` | `"system"` | message type | -| `subtype` | `"api_retry"` | identifies this as a retry event | -| `attempt` | integer | current attempt number, starting at 1 | -| `max_retries` | integer | total retries permitted | -| `retry_delay_ms` | integer | milliseconds until the next attempt | -| `error_status` | integer or null | HTTP status code, or `null` for connection errors with no HTTP response | -| `error` | string | error category: `authentication_failed`, `oauth_org_not_allowed`, `billing_error`, `rate_limit`, `overloaded`, `invalid_request`, `model_not_found`, `server_error`, `max_output_tokens`, or `unknown` | -| `uuid` | string | unique event identifier | -| `session_id` | string | session the event belongs to | +| Field | Type | Description | +| ---------------- | ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `type` | `"system"` | message type | +| `subtype` | `"api_retry"` | identifies this as a retry event | +| `attempt` | integer | current attempt number, starting at 1 | +| `max_retries` | integer | total retries permitted | +| `retry_delay_ms` | integer | milliseconds until the next attempt | +| `error_status` | integer or null | HTTP status code, or `null` for connection errors with no HTTP response | +| `no_response` | object, optional | present only when the failed attempt got [no response headers in time](/docs/en/errors#no-response-from-api). `waited_ms` is how long that attempt waited and `retry_wait_ms` is how long the retry will wait. In these events, `max_retries` reflects the one retry this cause normally gets, not the session-wide budget. Requires Claude Code v2.1.261 or later | +| `error` | string | error category: `authentication_failed`, `oauth_org_not_allowed`, `billing_error`, `rate_limit`, `overloaded`, `invalid_request`, `model_not_found`, `server_error`, `max_output_tokens`, or `unknown` | +| `uuid` | string | unique event identifier | +| `session_id` | string | session the event belongs to | #### Read session metadata diff --git a/content/en/docs/claude-code/hooks.md b/content/en/docs/claude-code/hooks.md index f91716eb1..eb971a158 100644 --- a/content/en/docs/claude-code/hooks.md +++ b/content/en/docs/claude-code/hooks.md @@ -2750,7 +2750,7 @@ Claude Code doesn't fire this event when: * You pass a directory with the `--add-dir` startup flag; [SessionStart](#sessionstart) covers those directories * You add a directory on the `/permissions` Workspace tab -* You add a directory that is already a working directory; the add fails with an error +* You add a directory that is already a working directory or inside one Claude Code fires DirectoryAdded after refreshing sandbox and permission state, so sandboxed tools already see the new directory when your hook runs. Hook commands themselves run unsandboxed. diff --git a/content/en/docs/claude-code/interactive-mode.md b/content/en/docs/claude-code/interactive-mode.md index 86bdc4fc1..9d26ee3a5 100644 --- a/content/en/docs/claude-code/interactive-mode.md +++ b/content/en/docs/claude-code/interactive-mode.md @@ -42,40 +42,33 @@ ### Text editing -| Shortcut | Description | Context | -| :------------------------- | :----------------------------------- | :----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `Ctrl+A` | Move cursor to start of current line | In multiline input, moves to the start of the current logical line | -| `Ctrl+E` | Move cursor to end of current line | In multiline input, moves to the end of the current logical line | -| `Ctrl+K` | Delete to end of line | Stores deleted text for pasting | -| `Ctrl+U` | Delete from cursor to line start | Stores deleted text for pasting. Repeat to clear across lines in multiline input. On macOS, terminal emulators including iTerm2 and Terminal.app map `Cmd+Backspace` to this shortcut | -| `Ctrl+W` | Delete previous word | Stores deleted text for pasting. On macOS, `Option+Delete` deletes the previous word, and on Windows, `Ctrl+Backspace` does. To make `Ctrl+W` delete back to the previous whitespace instead, [set `keybindingFlavor` to `"readline"`](#make-ctrl-w-delete-back-to-whitespace) | -| `Ctrl+Y` | Paste deleted text | Paste text deleted with `Ctrl+K`, `Ctrl+U`, `Ctrl+W`, or, under [`keybindingFlavor: "readline"`](#make-ctrl-w-delete-back-to-whitespace), `Alt+D` | -| `Alt+Y` (after `Ctrl+Y`) | Cycle paste history | After pasting, cycle through previously deleted text. Requires [Option as Meta](#keyboard-shortcuts) on macOS | -| `Alt+B` | Move cursor back one word | Word navigation. Requires [Option as Meta](#keyboard-shortcuts) on macOS | -| `Alt+F` | Move cursor forward one word | Moves to the start of the next word, or to the end of the current word when [`keybindingFlavor` is `"readline"`](#make-ctrl-w-delete-back-to-whitespace). Requires [Option as Meta](#keyboard-shortcuts) on macOS | -| `Alt+D` | Delete next word | Deletes through the space after the word, or to the end of the word when [`keybindingFlavor` is `"readline"`](#make-ctrl-w-delete-back-to-whitespace). Requires [Option as Meta](#keyboard-shortcuts) on macOS | -| `Ctrl+_` or `Ctrl+Shift+-` | Undo last input edit | Restores the previous input text and cursor position | +| Shortcut | Description | Context | +| :------------------------- | :----------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `Ctrl+A` | Move cursor to start of current line | In multiline input, moves to the start of the current logical line | +| `Ctrl+E` | Move cursor to end of current line | In multiline input, moves to the end of the current logical line | +| `Ctrl+K` | Delete to end of line | Stores deleted text for pasting | +| `Ctrl+U` | Delete from cursor to line start | Stores deleted text for pasting. Repeat to clear across lines in multiline input. On macOS, terminal emulators including iTerm2 and Terminal.app map `Cmd+Backspace` to this shortcut | +| `Ctrl+W` | Delete back to previous whitespace | Stores deleted text for pasting. One press removes a whole path or `--flag=value`. To delete only the previous word, press `Option+Delete` on macOS or `Ctrl+Backspace` on Windows | +| `Ctrl+Y` | Paste deleted text | Pastes the text you last deleted with one of the word or line deletion shortcuts, such as `Ctrl+K`, `Ctrl+U`, or `Ctrl+W` | +| `Alt+Y` (after `Ctrl+Y`) | Cycle paste history | After pasting, cycle through previously deleted text. Requires [Option as Meta](#keyboard-shortcuts) on macOS | +| `Alt+B` | Move cursor back one word | Word navigation. Requires [Option as Meta](#keyboard-shortcuts) on macOS | +| `Alt+F` | Move cursor forward one word | Moves to the end of the current word, or to the end of the next word when the cursor is between words. Requires [Option as Meta](#keyboard-shortcuts) on macOS | +| `Alt+D` | Delete to end of word | Deletes to the end of the current word, or to the end of the next word when the cursor is between words. Stores deleted text for pasting. Requires [Option as Meta](#keyboard-shortcuts) on macOS | +| `Ctrl+_` or `Ctrl+Shift+-` | Undo last input edit | Restores the previous input text and cursor position |

- Make editing keys follow readline conventions + Word boundaries in editing shortcuts

-Set [`keybindingFlavor`](/docs/en/settings-reference#keybindingflavor) to `"readline"` to make the prompt's editing keys follow GNU readline conventions, as in Bash. The default value is `"classic"`. Requires Claude Code v2.1.238 or later. Under `"readline"`: +The word shortcuts `Alt+B`, `Alt+F`, `Alt+D`, `Option+Delete`, and `Ctrl+Backspace` treat a word as a run of letters and digits, so punctuation such as `_`, `.`, and `/` separates words. With `src/utils/foo.ts` in the prompt, repeated presses of `Alt+B` stop at the start of `ts`, `foo`, `utils`, and `src`. -* `Ctrl+W` deletes back to the previous whitespace. -* A word is a run of letters and digits, so punctuation such as `_`, `.`, and `/` separates words. `Alt+F` and `Alt+D` stop at the end of the current word, and `Ctrl+Y` can paste back text that `Alt+D` deleted. Before v2.1.239, Claude Code applied `"readline"` only to `Ctrl+W`. +`Ctrl+W` is different: it ignores punctuation and deletes back to the previous whitespace, so one press removes all of `src/utils/foo.ts`. -Add the setting to `~/.claude/settings.json`: +In text written without spaces, such as Chinese or Japanese, the word shortcuts still move or delete one word at a time. -```json theme={null} -{ - "keybindingFlavor": "readline" -} -``` - -To confirm, type `fix the bug in src/utils/foo.ts` in the prompt and press `Ctrl+W`. Claude Code removes `src/utils/foo.ts`. Under `"classic"` it removes only `foo.ts`. +These readline conventions apply in Claude Code v2.1.261 and later. The [`keybindingFlavor`](/docs/en/settings-reference#keybindingflavor) setting that turned them on in earlier versions is deprecated and has no effect. -This setting is separate from the [keybindings configuration file](/docs/en/keybindings): the word-editing commands aren't actions there, so you can't remap them in `keybindings.json`. +You can't remap these shortcuts in the [keybindings configuration file](/docs/en/keybindings), which has no actions for them. ### Theme and display @@ -299,7 +292,8 @@ To run commands in the background, you can either: * Output is written to a file and Claude can retrieve it using the Read tool * Background tasks have unique IDs for tracking and output retrieval -* Background tasks are automatically cleaned up when Claude Code exits. If you background the session instead of exiting it, Claude Code hands them to the background session, where they keep running. See [background a running session](/docs/en/agent-view#from-inside-a-session) +* Background tasks are automatically cleaned up when Claude Code exits. On macOS and Linux, when you stop a background task from [`/tasks`](/docs/en/commands) or Claude Code stops it at exit, processes that detached from the task's shell, such as ones started under `setsid` or `timeout`, stop too +* If you background the session instead of exiting it, your background tasks keep running in the background session. See [background a running session](/docs/en/agent-view#from-inside-a-session) * Background tasks are automatically terminated if output exceeds 5GB, with a note in stderr explaining why * On macOS and Linux, Claude Code terminates running background tasks when the operating system signals memory pressure, provided the session has been idle for at least 30 minutes and no turn or subagent is running. Set [`CLAUDE_CODE_DISABLE_BG_SHELL_PRESSURE_REAP`](/docs/en/env-vars) to `1` to turn this off. Requires Claude Code v2.1.193 or later. Background commands owned by a [subagent](/docs/en/sub-agents) are instead terminated after 60 minutes, configurable in milliseconds with [`CLAUDE_SUBAGENT_BG_SHELL_MAX_MS`](/docs/en/env-vars). A command owned by a subagent running in the foreground also ends when that subagent gives its final response; see [Background commands](/docs/en/tools-reference#background-commands) in the tools reference. Before v2.1.218, neither the memory-pressure reap nor the 60-minute limit covered commands moved to the background with `Ctrl+B` @@ -334,6 +328,8 @@ Shell mode: * Exit with `Escape`, `Backspace`, or `Ctrl+U` on an empty prompt * Pasting text that starts with `!` into an empty prompt enters shell mode automatically, matching typed `!` behavior +In a regular interactive session, commands you type in shell mode run outside the [sandbox](/docs/en/sandboxing) even when you've enabled sandboxing, because the sandbox applies to the commands Claude runs. See [strict sandbox mode](/docs/en/sandboxing#the-unsandboxed-retry-escape-hatch) for the sessions where shell-mode commands run sandboxed too, such as background sessions with strict sandbox mode on. + Claude responds to the command output automatically once it lands in the transcript, so you can run `! npm test` and get an explanation of the failures without a second prompt. The response costs the same as sending a normal prompt. To restore the earlier behavior where the output is added to context without a response, set [`respondToBashCommands`](/docs/en/settings-reference#respondtobashcommands) to `false` in `settings.json`. Before v2.1.186, shell mode always added output to context without a response. ## Queue messages while Claude works diff --git a/content/en/docs/claude-code/large-codebases.md b/content/en/docs/claude-code/large-codebases.md index f843ae2e1..6ed69aa9a 100644 --- a/content/en/docs/claude-code/large-codebases.md +++ b/content/en/docs/claude-code/large-codebases.md @@ -176,7 +176,7 @@ The example below blocks build artifacts and a vendored SDK: } ``` -Deny rules cover Claude's built-in file tools and recognized Bash file commands, including `cat`, `head`, `grep`, and `find`, when a denied path is passed as an argument. Claude Code also makes a best-effort attempt to leave denied paths out of the results of the built-in Grep and Glob tools. Claude still sees denied paths in the output of a Bash search such as `grep -r` or `find`. +Deny rules cover Claude's built-in file tools. In Bash, they cover the file commands Claude Code recognizes, such as `cat`, `head`, `grep`, and `find`, when a denied path appears as an argument, and the target of a [redirection](/docs/en/permissions#redirections) such as `< file`. Claude Code also makes a best-effort attempt to leave denied paths out of the results of the built-in Grep and Glob tools. A Bash search such as `grep -r` or `find` over a directory that contains denied files still includes them in its output. Deny rules don't cover subprocesses that open files themselves. For the full pattern syntax, see [Read and Edit permission rules](/docs/en/permissions#read-and-edit). diff --git a/content/en/docs/claude-code/llm-gateway-connect.md b/content/en/docs/claude-code/llm-gateway-connect.md index e90aab656..e04c6f7fe 100644 --- a/content/en/docs/claude-code/llm-gateway-connect.md +++ b/content/en/docs/claude-code/llm-gateway-connect.md @@ -309,7 +309,9 @@ Enable it if your gateway serves model names that aren't in Claude Code's built- To enable it, set `CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY=1` in your shell or in the `env` block of `~/.claude/settings.json`. -Discovered models appear as additional `/model` entries labeled `From gateway`. To confirm discovery ran, start `claude --debug` and look for the `[gatewayDiscovery]` lines in the debug log at `~/.claude/debug/.txt`: Claude Code logs how many models it cached the first time discovery succeeds and again only when the gateway's list changes, and a `404`, timeout, or redirect is recorded there too. For when discovery runs, what it filters, and the response format gateways serve, see the [model discovery reference](/docs/en/llm-gateway-protocol#model-discovery). +Discovered models appear as additional `/model` entries. Each entry shows the description your gateway supplies for the model, or `From gateway` when it doesn't supply one. + +To confirm discovery ran, start `claude --debug` and look for the `[gatewayDiscovery]` lines in the debug log at `~/.claude/debug/.txt`. The first time discovery succeeds, Claude Code logs how many models it cached, and it logs again only when the gateway's list changes. A `404`, timeout, or redirect appears there too. For when discovery runs, what it filters, and the response format gateways serve, see the [model discovery reference](/docs/en/llm-gateway-protocol#model-discovery). ### Rotate credentials with apiKeyHelper @@ -386,7 +388,7 @@ Setting the variable has these effects and limits: * It disables auto-updates, so plan for another update path, such as your package manager or managed distribution. * It suppresses the [fast mode](/docs/en/fast-mode) availability check. Unless a previous check already enabled fast mode on the machine, `/fast` reports that fast mode is unavailable. -* It turns off [gateway model discovery](#add-gateway-models-to-the-model-picker), even though discovery queries the gateway itself. Previously discovered models stay available from the local cache, but the list isn't refreshed. +* It doesn't affect [gateway model discovery](#add-gateway-models-to-the-model-picker), which queries only your gateway. Before v2.1.257, the variable also stopped discovery from refreshing, so the picker kept the previously cached list. * The WebFetch tool's [domain safety check](/docs/en/data-usage#webfetch-domain-safety-check) isn't affected and still calls `api.anthropic.com`. Turn it off separately with `skipWebFetchPreflight: true` in [settings](/docs/en/settings) if your network blocks that host. * For each telemetry stream and the variable that controls it, see [telemetry services](/docs/en/data-usage#telemetry-services). diff --git a/content/en/docs/claude-code/llm-gateway-protocol.md b/content/en/docs/claude-code/llm-gateway-protocol.md index 51c310561..d63ddb378 100644 --- a/content/en/docs/claude-code/llm-gateway-protocol.md +++ b/content/en/docs/claude-code/llm-gateway-protocol.md @@ -167,7 +167,8 @@ Discovery applies only to the Anthropic Messages format. It doesn't run when: * Any `CLAUDE_CODE_USE_*` provider variable is set, even if `ANTHROPIC_BASE_URL` is also set * `ANTHROPIC_BASE_URL` is unset or points at `api.anthropic.com` -* Nonessential traffic is disabled, through [`CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC`](/docs/en/env-vars) or organization policy + +Discovery still runs when [nonessential traffic is turned off](/docs/en/llm-gateway-connect#turn-off-traffic-outside-the-gateway-path), because the request goes only to your gateway. Before v2.1.257, discovery didn't run while nonessential traffic was turned off. ### Request and response @@ -178,16 +179,20 @@ Claude Code sends the discovery request with both credential headers below and o * `Authorization`: `ANTHROPIC_AUTH_TOKEN` as a bearer token, otherwise the [`apiKeyHelper`](/docs/en/llm-gateway-connect#rotate-credentials-with-apikeyhelper) value as a bearer token. In that case Claude Code waits for the helper to return before sending the request. * `x-api-key`: the API key Claude Code resolved, such as `ANTHROPIC_API_KEY`. When a helper value is the only credential, this header carries it too, so the value arrives in both headers. -Claude Code also sends any headers from `ANTHROPIC_CUSTOM_HEADERS`. +Claude Code also sends any headers from `ANTHROPIC_CUSTOM_HEADERS`. When a custom header has a non-empty value, Claude Code sends it in place of a built-in header of the same name, matching names case-insensitively. -When neither credential header's value resolves, Claude Code skips discovery and writes a `[gatewayDiscovery] skipped` line to the debug log of a `claude --debug` session. +When neither credential header's value resolves, Claude Code skips discovery and writes a `[gatewayDiscovery] skipped` line to the debug log of a `claude --debug` session. If you supply a credential only through `ANTHROPIC_CUSTOM_HEADERS`, Claude Code still skips discovery. -Claude Code reads `id` and the optional `display_name` from each entry in the response's `data` array: +Claude Code reads `id`, the optional `display_name`, and the optional `description` from each entry in the response's `data` array: ```json theme={null} { "data": [ - { "id": "claude-sonnet-4-6", "display_name": "Claude Sonnet 4.6" }, + { + "id": "claude-sonnet-4-6", + "display_name": "Claude Sonnet 4.6", + "description": "Default model for everyday coding tasks" + }, { "id": "claude-opus-4-8" } ] } @@ -197,9 +202,14 @@ Claude Code keeps an entry when its `id` contains `claude` or `anthropic` anywhe ### Picker entries and caching -The picker is the interactive model list that opens when a developer runs `/model` in Claude Code. Each discovered entry is labeled "From gateway" and uses `display_name` when provided. The [`availableModels` managed setting](/docs/en/settings-reference#availablemodels) bounds what discovery can add. +The picker is the interactive model list that opens when a developer runs `/model` in Claude Code. Each discovered entry uses `display_name` as its name when the gateway sends one, and the model's `id` otherwise. Discovery adds only models that the [`availableModels` managed setting](/docs/en/settings-reference#availablemodels) allows. + +Each entry also shows the model's `description`, collapsed to one line. An entry without a `description` reads "From gateway" instead. Before v2.1.257, every discovered entry read "From gateway". + +A discovered ID doesn't get its own row when it matches a row already in the picker: -A discovered ID is skipped when it exactly matches a row already in the picker, or when the discovered and existing IDs are spellings of the same [Fable](/docs/en/model-config#work-with-fable) version. A discovered explicit ID is also folded into a built-in entry when both resolve to the same model. Built-in rows are keyed on aliases such as `sonnet`, so a discovered explicit ID of the model the alias currently resolves to, such as `claude-sonnet-5`, collapses into the `sonnet` row, while an ID the alias doesn't resolve to, such as `claude-sonnet-4-6`, still adds its own "From gateway" row alongside the built-in entry. Before v2.1.197, Claude Code didn't fold explicit IDs into built-in entries, so a discovered ID such as `claude-sonnet-5` added its own "From gateway" row alongside the `sonnet` row. +* Same ID: the discovered ID exactly matches an existing row's ID, or the two IDs are spellings of the same [Fable](/docs/en/model-config#work-with-fable) version. +* Same model as a built-in alias: when a discovered explicit ID names the model that a built-in alias currently resolves to, the picker shows only the alias row. For example, while `sonnet` resolves to `claude-sonnet-5`, a discovered `claude-sonnet-5` collapses into the `sonnet` row, and a discovered `claude-sonnet-4-6` still gets its own row. Before v2.1.197, Claude Code didn't fold these IDs into built-in rows, so `claude-sonnet-5` also got its own "From gateway" row. Results are cached to `~/.claude/cache/gateway-models.json`, or `%USERPROFILE%\.claude\cache\gateway-models.json` on Windows, and refreshed on each startup. If you set [`CLAUDE_CONFIG_DIR`](/docs/en/env-vars), the cache lives under that directory instead. If the request fails or the gateway doesn't implement `/v1/models`, the picker falls back to the cached list from the previous startup or to the built-in model list. If your gateway serves Claude models under aliases that don't match the discovery filter, developers can add those aliases manually with the [model configuration](/docs/en/model-config) variables. diff --git a/content/en/docs/claude-code/managed-mcp.md b/content/en/docs/claude-code/managed-mcp.md index 8526decf7..6786f6761 100644 --- a/content/en/docs/claude-code/managed-mcp.md +++ b/content/en/docs/claude-code/managed-mcp.md @@ -170,7 +170,7 @@ To turn off all the claude.ai connectors Claude Code fetches itself, see [`disab ### How a server is evaluated -Before loading a server, including one from `managed-mcp.json`, Claude Code runs the three checks below in order. In-process `type: "sdk"` servers, which the [app that started the session registers](/docs/en/mcp#how-connectors-reach-claude-code), skip all three. +Before loading a server, including one from `managed-mcp.json`, Claude Code runs the three checks below in order. It runs them again when a user reconnects a server or turns a disabled one back on in `/mcp`. In-process `type: "sdk"` servers, which the [app that started the session registers](/docs/en/mcp#how-connectors-reach-claude-code), skip all three. 1. **Merge the lists.** Allowlist and denylist entries from every settings scope combine into one allowlist and one denylist, with the managed scope's lists coming from the [managed source or sources Claude Code applies](/docs/en/managed-settings#how-claude-code-combines-managed-sources). When `allowManagedMcpServersOnly` is `true`, only the managed allowlist is kept; the denylist always merges from every scope. 2. **Check the denylist.** A server that matches any denylist entry, by URL, command, or name, is blocked. Nothing overrides a denylist match. @@ -346,14 +346,15 @@ When `allowManagedMcpServersOnly` is `true`, allowlists from user, project, and For what users see at startup when `managed-mcp.json` is deployed and the session also has `--mcp-config` servers, see [Exclusive control with managed-mcp.json](#exclusive-control-with-managed-mcp-json). Use this table to recognize the other reports and to tell users what to expect before you roll out a change: -| Restriction | What the user sees | -| :------------------------------------------------------------------- | :--------------------------------------------------------------------------------------------------------- | -| `managed-mcp.json` is present and the user runs `claude mcp add` | `Cannot add MCP server: enterprise MCP configuration is active and has exclusive control over MCP servers` | -| The server is on a denylist and the user runs `claude mcp add` | `Cannot add MCP server "": server is explicitly blocked by enterprise policy` | -| The server isn't on the allowlist and the user runs `claude mcp add` | `Cannot add MCP server "": not allowed by enterprise policy` | -| A previously configured server is now blocked by policy | The server silently disappears from `/mcp` and `claude mcp list` with no warning | +| Restriction | What the user sees | +| :-------------------------------------------------------------------------------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------- | +| `managed-mcp.json` is present and the user runs `claude mcp add` | `Cannot add MCP server: enterprise MCP configuration is active and has exclusive control over MCP servers` | +| The server is on a denylist and the user runs `claude mcp add` | `Cannot add MCP server "": server is explicitly blocked by enterprise policy` | +| The server isn't on the allowlist and the user runs `claude mcp add` | `Cannot add MCP server "": not allowed by enterprise policy` | +| A previously configured server is now blocked by policy | The server silently disappears from `/mcp` and `claude mcp list` with no warning | +| A server becomes blocked while a session is running, and the user selects **Reconnect** or turns it back on in `/mcp` | [`MCP server is blocked by enterprise managed policy`](/docs/en/errors#mcp-server-is-blocked-by-enterprise-managed-policy) | -In the last case, the user gets no signal that policy is the reason their server disappeared, so tell affected users which servers are blocked when you roll out a new restriction. +When a server silently disappears, the user gets no signal that policy is the reason, so tell affected users which servers are blocked when you roll out a new restriction. ## Monitor MCP usage diff --git a/content/en/docs/claude-code/managed-settings.md b/content/en/docs/claude-code/managed-settings.md index f396f958e..be0278811 100644 --- a/content/en/docs/claude-code/managed-settings.md +++ b/content/en/docs/claude-code/managed-settings.md @@ -363,6 +363,8 @@ The table covers the permission, plugin, and delivery controls. For any key not On Team and Enterprise plans, an Owner enables or disables [Remote Control](/docs/en/remote-control) and [web sessions](/docs/en/claude-code-on-the-web) organization-wide in [Claude Code admin settings](https://claude.ai/admin-settings/claude-code). Remote Control can additionally be disabled per device with the [`disableRemoteControl`](/docs/en/settings-reference#disableremotecontrol) setting. Web sessions have no per-device managed settings key. + + To check whether these organization settings reached a given machine, run `claude doctor` there and read the `Organization policy` line, which says where Claude Code loaded the policy from or why it didn't load. Requires Claude Code v2.1.261 or later. In a running session, `/status` shows the same line when the policy didn't load. ## Turn telemetry off for your organization diff --git a/content/en/docs/claude-code/mcp.md b/content/en/docs/claude-code/mcp.md index b0e3737b1..faefa3129 100644 --- a/content/en/docs/claude-code/mcp.md +++ b/content/en/docs/claude-code/mcp.md @@ -231,6 +231,8 @@ claude mcp remove notion /mcp ``` +When you remove a remote server, Claude Code also deletes the OAuth tokens and client registration it stored for that server. + #### Server status `claude mcp add` confirms a successful add by printing an `Added ...` line, which means the configuration was written. `claude mcp list` then shows a health status next to each server it lists, such as `✔ Connected`, `! Needs authentication`, or `✘ Failed to connect`. A failure status means Claude Code couldn't connect to that server, not that the list command failed. diff --git a/content/en/docs/claude-code/memory.md b/content/en/docs/claude-code/memory.md index cd1e5794f..021b60aea 100644 --- a/content/en/docs/claude-code/memory.md +++ b/content/en/docs/claude-code/memory.md @@ -394,7 +394,7 @@ The directory contains a `MEMORY.md` index and one topic file per memory: Auto memory is machine-local. All worktrees and subdirectories within the same git repository share one auto memory directory. Files are not shared across machines or cloud environments. -Claude Code deletes old session transcripts after the [`cleanupPeriodDays`](/docs/en/settings-reference#cleanupperioddays) retention period, but excludes the files in the memory directory from that [retention sweep](/docs/en/claude-directory#cleaned-up-automatically). `MEMORY.md` and topic files stay until you or Claude edits or deletes them. +Claude Code deletes old session transcripts after the [`cleanupPeriodDays`](/docs/en/settings-reference#cleanupperioddays) retention period, but excludes the memory files in the memory directory from that [retention sweep](/docs/en/claude-directory#cleaned-up-automatically). `MEMORY.md` and topic files stay until you or Claude edits or deletes them. ### How it works diff --git a/content/en/docs/claude-code/monitoring-usage.md b/content/en/docs/claude-code/monitoring-usage.md index 4075add69..3efcd35f7 100644 --- a/content/en/docs/claude-code/monitoring-usage.md +++ b/content/en/docs/claude-code/monitoring-usage.md @@ -1154,7 +1154,7 @@ When Claude Code can't safely determine the retention period, it pauses the swee * `used_default`: `"true"` when no readable settings source sets `cleanupPeriodDays`, `"false"` otherwise. On complete events, `"true"` means the 30-day default applied * `skip_reason`: Why Claude Code paused the sweep. Present only when `result` is `"skipped"`: * `"user_source_disabled"`: User settings are excluded, for example by the [`--setting-sources`](/docs/en/cli-reference#cli-flags) flag or the SDK's [`settingSources`](/docs/en/agent-sdk/typescript#options) option, and no enabled source provides `cleanupPeriodDays` - * `"settings_unknowable"`: A settings file couldn't be read or parsed, so `cleanupPeriodDays` may be set to a value Claude Code can't see + * `"settings_unknowable"`: A settings file couldn't be read or parsed, so `cleanupPeriodDays` or `desktopSessionCleanupPeriodDays` may be set to a value Claude Code can't see * `"settings_invalid_key_set"`: Settings have validation errors and `cleanupPeriodDays` or `desktopSessionCleanupPeriodDays` is explicitly set, so falling back to the default could delete or keep files against that setting * `transcripts_deleted`: Number of session transcripts, the top-level `~/.claude/projects/*/*.jsonl` files, that the sweep deleted * `transcripts_exempted_desktop`: Number of transcripts past the retention period that the sweep kept under the [Claude Desktop and Cowork rule](/docs/en/claude-directory#cleaned-up-automatically). These don't count toward `files_past_cutoff`. Requires Claude Code v2.1.248 or later diff --git a/content/en/docs/claude-code/network-config.md b/content/en/docs/claude-code/network-config.md index 787b786ee..f6123158c 100644 --- a/content/en/docs/claude-code/network-config.md +++ b/content/en/docs/claude-code/network-config.md @@ -195,7 +195,7 @@ Configure the timers with these variables, each detailed in the [environment var * `CLAUDE_ENABLE_STREAM_WATCHDOG` and `CLAUDE_ENABLE_BYTE_WATCHDOG` force the corresponding watchdog on with `1` or off with `0`, within the connections the table lists; neither variable extends a watchdog to a connection type it doesn't cover. `CLAUDE_ENABLE_BYTE_WATCHDOG` set to `0` also turns off the first-byte deadline. * `CLAUDE_STREAM_IDLE_TIMEOUT_MS` sets both watchdogs' timeout. Claude Code raises values below 5 minutes to 5 minutes, and caps the value at 30 minutes for the byte-level watchdog. * `CLAUDE_BYTE_STREAM_IDLE_TIMEOUT_MS` sets the byte-level watchdog's timeout without changing the event-level watchdog's, clamped to between 10 seconds and 30 minutes, and takes precedence over `CLAUDE_STREAM_IDLE_TIMEOUT_MS` for that watchdog. -* `CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS` sets the first-byte deadline directly. Leave it unset and Claude Code derives the deadline from the byte-level watchdog's timeout or from an `API_TIMEOUT_MS` you set above that timeout, so `CLAUDE_STREAM_IDLE_TIMEOUT_MS` and `CLAUDE_BYTE_STREAM_IDLE_TIMEOUT_MS` change the deadline too. For the clamps, the upload allowance, and the `API_TIMEOUT_MS` cap, see [No response from API](/docs/en/errors#no-response-from-api). +* `CLAUDE_STREAM_FIRST_BYTE_TIMEOUT_MS` sets the first-byte deadline directly. Leave it unset and Claude Code uses the byte-level watchdog's timeout, so `CLAUDE_STREAM_IDLE_TIMEOUT_MS` and `CLAUDE_BYTE_STREAM_IDLE_TIMEOUT_MS` change the deadline too. For the clamps, the upload allowance, the `API_TIMEOUT_MS` cap, and how long the retry waits after a no-response abort, see [No response from API](/docs/en/errors#no-response-from-api). * `API_FORCE_IDLE_TIMEOUT` set to `0` turns the body idle timeout off, and set to `1` turns it on for every provider. The watchdogs run independently of it, so to let a stream pause longer than their thresholds, also raise or disable them. When a watchdog aborts a stalled stream, Claude Code treats the abort as a mid-stream failure, and what you see depends on how far the response had got. Claude Code retries the request or ends the turn with an error, keeps the completed output and shows an [incomplete-response notice](/docs/en/errors#the-response-above-may-be-incomplete), or ends the turn normally. [Automatic retries](/docs/en/errors#automatic-retries) says where each outcome applies. diff --git a/content/en/docs/claude-code/permissions.md b/content/en/docs/claude-code/permissions.md index 7e70c3794..24c7519f0 100644 --- a/content/en/docs/claude-code/permissions.md +++ b/content/en/docs/claude-code/permissions.md @@ -90,7 +90,7 @@ To prevent `bypassPermissions` or `auto` mode from being used, set `permissions. ## Permission rule syntax -Permission rules follow the format `Tool` or `Tool(specifier)`. +Permission rules follow the format `Tool` or `Tool(specifier)`. Parentheses inside the specifier are literal, so a command or path that contains them needs no escaping. ### Match all uses of a tool @@ -218,6 +218,8 @@ Bash rules match the whole command text, with `*` standing in for any text. [Wil Claude Code is aware of shell operators, so a rule like `Bash(safe-cmd *)` won't give it permission to run the command `safe-cmd && other-cmd`. The recognized command separators are `&&`, `||`, `;`, `|`, `|&`, `&`, and newlines. A rule must match each subcommand independently. +Deny and ask rules apply when any subcommand matches them, including a command nested inside a subshell, a command substitution, or a control-flow body such as a `for` loop. An ask rule like `Bash(git clean *)` still prompts you for `cd /tmp && git clean -f` or `echo "$(git clean -f)"`, even in [auto mode](/docs/en/permission-modes#eliminate-prompts-with-auto-mode). + When `&&` or `||` has nothing after it, such as in `npm test &&`, Claude Code treats the command as unparseable and doesn't split it into subcommands for allow-rule matching, so a rule such as `Bash(npm *)` doesn't approve it. When you approve a compound command with "Yes, and don't ask again", Claude Code saves a separate rule for each subcommand that requires approval, rather than a single rule for the full compound string. For example, approving `git status && npm test` saves a rule for `npm test`, so future `npm test` invocations are recognized regardless of what precedes the `&&`. Subcommands like `cd` into a subdirectory generate their own Read rule for that path. Up to 5 rules may be saved for a single compound command. @@ -252,10 +254,10 @@ In Manual mode, commands from this set still prompt in these cases: * **Network paths on Windows**: a command whose arguments include a network (UNC) path, such as `\\server\share\file`, prompts because accessing a network path can send your Windows credentials to the host it names. The same check applies to [PowerShell tool](/docs/en/tools-reference#powershell-tool) commands. * **Commands the analysis can't parse**: when Claude Code can't fully parse a command, it asks for approval instead of treating the command as read-only. Commands longer than 10,000 characters always prompt because they exceed what the analysis parses. -A `cd` into a path inside your working directory or an [additional directory](#working-directories) is also read-only, and a compound command like `cd packages/api && ls` runs without a prompt when each part qualifies on its own. Two combinations prompt even when each part is read-only: +A `cd` into a path inside your working directory or an [additional directory](#working-directories) is also read-only, and a compound command like `cd packages/api && ls` runs without a prompt when each part qualifies on its own. These combinations prompt even when each part is read-only: * **`cd` with `git`**: prompts when the `cd` changes into a different directory, since running `git` in a new directory can execute that directory's hooks. A `cd` whose target resolves to the current working directory is a no-op and doesn't trigger the prompt. -* **`cd` with an output redirect**: prompts when Claude Code can't determine which directory the redirect target resolves against after the `cd` runs. A command whose only redirect target is `/dev/null`, such as `cd app; grep -r pattern . 2>/dev/null`, doesn't prompt, because `/dev/null` doesn't depend on the working directory. +* **`cd` with a redirect**: prompts when Claude Code can't determine which directory the redirect target resolves against after the `cd` runs. A command whose only redirect target is `/dev/null`, such as `cd app; grep -r pattern . 2>/dev/null`, doesn't prompt, because `/dev/null` doesn't depend on the working directory. Bash permission patterns that try to constrain command arguments are fragile. For example, `Bash(curl http://github.com/ *)` intends to restrict curl to GitHub URLs, but won't match variations like: @@ -277,7 +279,12 @@ A `cd` into a path inside your working directory or an [additional directory](#w #### Redirections -Claude Code checks the target of an output redirection, such as `>`, `>>`, or `2>`, as a file write. The check covers your `Edit` allow and deny rules, [protected paths](/docs/en/permission-modes#protected-paths), and the [working directories](#working-directories). A rule such as `Bash(git commit *)` allows the command, not the target. A `/dev/null` target isn't checked. A target that starts with `~` or contains a glob character needs approval. +When a command redirects output or input, Claude Code checks the redirect target against your file rules as if Claude wrote or read that file directly: + +* **Output redirects**: for `> file`, `>> file`, or `2> file`, the check covers your `Edit` allow and deny rules, [protected paths](/docs/en/permission-modes#protected-paths), and the [working directories](#working-directories). A rule such as `Bash(git commit *)` allows the command, not the target. A target that starts with `~` or contains a glob character needs your approval. +* **Input redirects**: for `< file`, the check covers your `Read` allow and deny rules and the working directories. A target outside the working directories needs your approval unless an allow rule covers it. A target that contains a glob pattern, or a relative path that follows a `cd` in the same command, needs your approval even when an allow rule covers it. Claude Code checks input targets in v2.1.257 and later. + +Targets with no file behind them aren't checked: `/dev/null`, file-descriptor forms such as `2>&1` and `<&3`, and here-docs and here-strings. ### PowerShell @@ -312,7 +319,7 @@ A `Read` deny rule also blocks the [Edit and Write tools](/docs/en/errors#file-i Claude Code checks file permissions against `Edit(path)` and `Read(path)` rules only. If you write a path rule for `Write`, `NotebookEdit`, `Glob`, or the legacy `MultiEdit` tool instead, Claude Code accepts the rule but never consults it, and [warns at startup](/docs/en/errors#is-not-matched-by-file-permission-checks), except for a `Glob` rule passed in `--allowedTools`. Use `Edit(docs/**)` in place of `Write(docs/**)`, `NotebookEdit(docs/**)`, or `MultiEdit(docs/**)`, and `Read(docs/**)` in place of `Glob(docs/**)`. Claude Code doesn't warn about a tool-name rule with no path, such as a deny rule for `Write`; it matches that rule at the tool level everywhere. Requires Claude Code v2.1.210 or later. - Read and Edit deny rules apply to Claude's built-in file tools and to file commands Claude Code recognizes in Bash, such as `cat`, `head`, `tail`, and `sed`. They don't apply to arbitrary subprocesses that read or write files indirectly, like a Python or Node script that opens files itself. For OS-level enforcement that blocks all processes from accessing a path, [enable the sandbox](/docs/en/sandboxing). + Read and Edit deny rules apply to Claude's built-in file tools, to file commands Claude Code recognizes in Bash, such as `cat`, `head`, `tail`, and `sed`, and to the targets of Bash [redirections](#redirections) such as `> file` and `< file`. They don't apply to arbitrary subprocesses that read or write files indirectly, like a Python or Node script that opens files itself. For OS-level enforcement that blocks all processes from accessing a path, [enable the sandbox](/docs/en/sandboxing). Read and Edit rules both use [gitignore](https://git-scm.com/docs/gitignore) pattern syntax with four distinct pattern types; for single-segment directory patterns, the matching depth also depends on the rule type, described later in this section: @@ -392,6 +399,10 @@ The following example shows each pattern shape against a project with a top-leve When you approve a file path with "Yes, and don't ask again", Claude Code escapes gitignore pattern characters in that path, such as `[`, `]`, and `*`, so the generated rule matches only the literal path you approved. Rules you write yourself aren't escaped. Before v2.1.202, Claude Code saved the path unescaped, so a generated rule for a directory named `[2024-06] Reports` could fail to match its own path or match unintended sibling directories. +You don't need to escape parentheses in a path, so `Edit(./Finance (2024)/**)` matches the `Finance (2024)` folder as spelled. + +A deny or ask rule whose path isn't usable as a gitignore pattern still guards that exact path. An allow rule with an unusable pattern doesn't approve anything. + When Claude accesses a symlink, permission rules check two paths: the symlink itself and the file it resolves to. Allow and deny rules treat that pair differently: allow rules fall back to prompting you, while deny rules block outright. * **Allow rules**: apply only when both the symlink path and its target match. A symlink inside an allowed directory that points outside it still prompts you. @@ -504,6 +515,8 @@ By default, Claude has access to files in the directory where you launched it. T Files in additional directories follow the same permission rules as the original working directory: they become readable without prompts, and file editing permissions follow the current permission mode. +You can't add most [network paths](/docs/en/errors#working-directory-is-a-network-path), such as the UNC share `\\server\share`, as working directories, because looking one up can contact the host it names. On Windows, map the share to a drive letter instead and pass the drive with `--add-dir` at launch. + Set [`permissions.blockReadsOutsideWorkingDirectories`](/docs/en/settings-reference#permissions-blockreadsoutsideworkingdirectories) to make the file tools refuse the paths it fences in every permission mode. In auto mode, Claude Code offers to turn it on the first time Claude [reads outside the working directories](/docs/en/permission-modes#first-read-outside-the-working-directories). In background sessions on macOS, the session host requests access to protected folders such as `~/Desktop`, `~/Documents`, and `~/Downloads` separately from your terminal when Claude needs to read or write files there; if reads there fail with `Operation not permitted`, see [how to grant folder access to background sessions](/docs/en/agent-view#background-sessions-can’t-read-desktop-documents-or-downloads-on-macos). @@ -543,6 +556,8 @@ The following configuration types are loaded from `--add-dir` directories: | [Settings](/docs/en/settings) in `.claude/settings.json` and `.claude/settings.local.json` | `enabledPlugins` and [`extraKnownMarketplaces`](/docs/en/settings-reference#extraknownmarketplaces) keys only | | [CLAUDE.md](/docs/en/memory) files, `.claude/rules/`, and `CLAUDE.local.md` | Only when `CLAUDE_CODE_ADDITIONAL_DIRECTORIES_CLAUDE_MD=1` is set. `CLAUDE.local.md` additionally requires the `local` setting source, which is enabled by default | +To load the skills, commands, and subagents from a subdirectory of your [primary working directory](#working-directories) mid-session, run `/add-dir` with that subdirectory's path. Claude Code loads them for the rest of the session without prompting you or adding a working directory, because the subdirectory is already readable. This requires Claude Code v2.1.257 or later. + Claude Code discovers output styles from the current working directory and its parents, your user directory at `~/.claude/`, and managed settings. Hooks and other `.claude/settings.json` keys load from the current working directory's `.claude/` folder with no parent-directory fallback, alongside your user `~/.claude/settings.json` and managed settings. `.claude/settings.local.json` loads from the git repository root instead, even when you start Claude Code in a subdirectory, except in the cases where Claude Code [doesn't use the repository root](/docs/en/settings#where-claude-code-looks-for-each-file), such as on Windows; before v2.1.211, it too loaded only from the current working directory. [Agent SDK](/docs/en/agent-sdk/claude-code-features#control-filesystem-settings-with-settingsources) sessions load it from the working directory in all versions. To share that configuration across projects, use one of these approaches: diff --git a/content/en/docs/claude-code/plugins-reference.md b/content/en/docs/claude-code/plugins-reference.md index 7ba8eddcc..5d1c64295 100644 --- a/content/en/docs/claude-code/plugins-reference.md +++ b/content/en/docs/claude-code/plugins-reference.md @@ -826,7 +826,9 @@ For dependencies the automatic install can't provide, such as packages that need ### Path traversal limitations -Claude Code doesn't let a plugin reference files outside its own directory. It rejects a component path that resolves outside the plugin root, such as `../shared-utils`, whether the path is declared in `plugin.json` or in a [marketplace entry](/docs/en/plugin-marketplaces#plugin-entries). Claude Code reports a [`path escapes plugin directory`](/docs/en/errors#path-escapes-plugin-directory) error and loads the plugin without that component. +Claude Code doesn't let a plugin reference files outside its own directory. It rejects a component path that resolves outside the plugin root, whether the path is declared in `plugin.json` or in a [marketplace entry](/docs/en/plugin-marketplaces#plugin-entries). That covers a path that points outside the plugin as written, such as `../shared-utils`, and a symlink that leads outside the plugin, other than [links within one marketplace](#share-files-within-a-marketplace-with-symlinks). + +When Claude Code rejects a path, it reports a [`path escapes plugin directory`](/docs/en/errors#path-escapes-plugin-directory) error and loads the plugin without that component. Claude Code also doesn't copy files outside the plugin directory into the cache when it installs the plugin, so when a script inside a copied plugin reads a path above the plugin root, it doesn't find those files either. diff --git a/content/en/docs/claude-code/prompt-caching.md b/content/en/docs/claude-code/prompt-caching.md index 237d31f9d..c49f5eca2 100644 --- a/content/en/docs/claude-code/prompt-caching.md +++ b/content/en/docs/claude-code/prompt-caching.md @@ -296,6 +296,8 @@ A high read-to-creation ratio means caching is working well. If creation stays h For a per-session summary, run `/usage`. After the main conversation's first response, Claude Code adds a [`Prompt cache (main)` line](/docs/en/costs#prompt-cache-statistics) to the Session block, showing the session's hit ratio, miss count, and whether the cache is warm right now. A status line script can read the same numbers from the [`prompt_cache` object](/docs/en/statusline#prompt-cache-fields). Both require Claude Code v2.1.251 or later. +The `Prompt cache (main)` line also names the likely cause of the last miss when Claude Code can identify one, for example `likely cause: tool definitions changed`. The likely-cause text requires Claude Code v2.1.260 or later. + For visibility across an organization, the OpenTelemetry exporter reports cache read and creation tokens per user and session. See [Monitor usage](/docs/en/monitoring-usage) for the metric and event attribute reference. ## Subagents and the cache diff --git a/content/en/docs/claude-code/remote-control.md b/content/en/docs/claude-code/remote-control.md index 32b992109..db6aa4191 100644 --- a/content/en/docs/claude-code/remote-control.md +++ b/content/en/docs/claude-code/remote-control.md @@ -376,10 +376,12 @@ The message names what routed the session away from the Anthropic API, such as ` ### "Remote Control is disabled by your organization's policy" -A policy blocks Remote Control. The message's own text tells you which: +A policy blocks Remote Control, or Claude Code couldn't load your organization's policy on this machine and keeps Remote Control off in the meantime. Check these causes in order: * **The error mentions `disableRemoteControl`**: your IT administrator has disabled Remote Control on this device through [managed settings](/docs/en/managed-settings), independent of the organization-wide toggle and of how you're signed in. -* **Otherwise, an Owner hasn't enabled it for your organization**: this form appears when you're signed in with an eligible claude.ai account but Remote Control is off, the default on Team and Enterprise plans. An Owner can enable it at [claude.ai/admin-settings/claude-code](https://claude.ai/admin-settings/claude-code) by turning on the **Remote Control** toggle. This toggle is a server-side organization setting. +* **Your claude.ai plan is Pro or Max**: Claude Code is still signed in under a Team or Enterprise organization from an earlier login, so it checks that organization's Remote Control policy. Run `/status` to see which plan and organization your sign-in uses. Run `claude auth logout` then `claude auth login` to sign in again under your current plan. +* **The organization policy didn't load on this machine**: run `claude doctor` and read the `Organization policy` line. If the line shows the policy isn't loaded, that is what's keeping Remote Control off. Before v2.1.261, `claude doctor` didn't print this line. +* **Otherwise, an Owner hasn't enabled it for your organization**: Remote Control is off by default on Team and Enterprise plans. An Owner can enable it at [claude.ai/admin-settings/claude-code](https://claude.ai/admin-settings/claude-code) by turning on the **Remote Control** toggle. This toggle is a server-side organization setting. ### "Remote Control isn't available for your organization due to its compliance policy" diff --git a/content/en/docs/claude-code/sandboxing.md b/content/en/docs/claude-code/sandboxing.md index 43ad9a38d..b43474e58 100644 --- a/content/en/docs/claude-code/sandboxing.md +++ b/content/en/docs/claude-code/sandboxing.md @@ -146,7 +146,14 @@ Some commands can't run inside the sandbox at all, such as tools that are incomp The retried command runs outside the sandbox, so it goes through the regular permission flow. In Manual mode you get a confirmation prompt. In [auto mode](/docs/en/permission-modes#eliminate-prompts-with-auto-mode), the classifier evaluates the underlying command. While [`permissions.blockReadsOutsideWorkingDirectories`](/docs/en/settings-reference#permissions-blockreadsoutsideworkingdirectories) is on, a retry that needs approval to run outside the sandbox prompts you instead. To be prompted on every unsandboxed retry even in auto mode, add an [ask rule](/docs/en/permissions#match-by-input-parameter) for `Bash(dangerouslyDisableSandbox:true)`. -You can disable this escape hatch by setting `"allowUnsandboxedCommands": false` in your [sandbox settings](/docs/en/settings-reference#sandbox-settings). When disabled, which the `/sandbox` Overrides tab shows as **Strict sandbox mode**, the `dangerouslyDisableSandbox` parameter is completely ignored and all commands must run sandboxed or be explicitly listed in `excludedCommands`. +You can disable this escape hatch by setting `"allowUnsandboxedCommands": false` in your [sandbox settings](/docs/en/settings-reference#sandbox-settings). With the escape hatch disabled, Claude Code ignores the `dangerouslyDisableSandbox` parameter, and every command Claude runs must run sandboxed unless you've listed it in `excludedCommands`. The `/sandbox` **Overrides** tab shows this setting as **Strict sandbox mode**. + +Strict sandbox mode applies to the commands Claude runs. Commands you type yourself at the [`!` shell-mode prompt](/docs/en/interactive-mode#shell-mode-with-prefix) run outside the sandbox unless the session is one of these: + +* **A [background session](/docs/en/agent-view)**: strict sandbox mode covers shell-mode commands too +* **A Linux session with [`CLAUDE_CODE_SUBPROCESS_ENV_SCRUB`](/docs/en/env-vars#variables) set**: every command runs sandboxed, shell-mode commands included + +Before v2.1.260, strict sandbox mode sandboxed shell-mode commands in every session. #### Temporary directories @@ -606,10 +613,12 @@ The following managed settings configuration enables the sandbox, refuses to sta The two keys beyond `enabled` control what happens when the sandbox cannot run a command: * **`failIfUnavailable`**: a missing dependency such as bubblewrap on Linux blocks Claude Code from starting rather than showing a warning and falling back to unsandboxed execution -* **`allowUnsandboxedCommands: false`**: the `dangerouslyDisableSandbox` escape hatch is ignored, so commands that fail under the sandbox cannot be retried outside it +* **`allowUnsandboxedCommands: false`**: Claude Code ignores the `dangerouslyDisableSandbox` escape hatch, so when a command fails under the sandbox, Claude can't retry it unsandboxed Two additions are worth considering alongside them. Add `excludedCommands` for any organization-approved tools that must run without isolation. Add [`sandbox.credentials`](#protect-credentials) entries for credential directories such as `~/.aws` and `~/.ssh` and for secret environment variables, since the default read policy still allows them. +This configuration sandboxes the commands Claude runs. A developer can still type a command at the [`!` shell-mode prompt](/docs/en/interactive-mode#shell-mode-with-prefix) and run it outside the sandbox, with the same access they already have in any terminal outside Claude Code. See [The unsandboxed retry escape hatch](#the-unsandboxed-retry-escape-hatch) for the sessions where typed commands run sandboxed. + The sandbox does not run on native Windows, so if your fleet includes Windows hosts, scope this configuration to macOS and Linux or have those users run Claude Code inside WSL2 or a container. ### Keep developers from widening the policy @@ -653,7 +662,10 @@ Some commands fail inside the sandbox even though they work outside it. The fixe * **Go-based CLIs fail TLS verification on macOS**: tools such as `gh`, `gcloud`, and `terraform` may fail TLS verification under Seatbelt. List these tools in `excludedCommands` to run them outside the sandbox. If you are using `httpProxyPort` with a MITM proxy and custom CA, set [`enableWeakerNetworkIsolation`](/docs/en/settings-reference#sandbox-enableweakernetworkisolation) to `true` instead. * **`open`, `osascript`, or browser-based auth flows fail with error `-600` on macOS**: the sandbox blocks Apple Events by default. Set [`allowAppleEvents`](/docs/en/settings-reference#sandbox-allowappleevents) to `true` in your user, managed, or CLI settings to allow them. Project settings are ignored for this key. Enabling it removes code-execution isolation, since sandboxed commands can then launch other applications unsandboxed with no user prompt and send AppleScript commands to running applications, subject to the macOS automation-consent prompt (TCC). Alternatively, add the command to `excludedCommands` to run it outside the sandbox. * **`docker` commands fail**: `docker` is incompatible with the sandbox. Add `docker *` to `excludedCommands` to run it outside the sandbox. -* **A git command fails with `unable to unlink old`**: `git merge`, `git checkout`, and similar commands fail this way when they need to replace a file the sandbox denies writes to, whether that file is under a [protected path](#protected-paths) such as `.claude/skills`, under one of your `denyWrite` entries, or outside the directories the sandbox lets commands write to at all. On Linux and WSL2 the error ends with `Read-only file system`. After the failure, Claude may [offer to rerun the command outside the sandbox](#sandbox-modes); approve that retry, or run the git command yourself in another terminal. If you've set `allowUnsandboxedCommands` to `false`, Claude can't offer the retry, so run the command yourself or, if the same git command fails often, add that command to [`excludedCommands`](/docs/en/settings-reference#sandbox-excludedcommands). +* **`pbcopy`, `xclip`, or `wl-copy` doesn't update the clipboard**: these clipboard utilities can fail to reach the system clipboard from inside the sandbox, in which case the text piped to them doesn't arrive. To put Claude's output on your clipboard, ask Claude to print it in its response, then run [`/copy`](/docs/en/commands), which writes to the clipboard from the Claude Code process rather than from a sandboxed command. Alternatively, add `pbcopy *`, `wl-copy *`, or `xclip *` to `excludedCommands` to run the command outside the sandbox. +* **A git command fails with `unable to unlink old`**: `git merge`, `git checkout`, and similar commands fail this way when they need to replace a file the sandbox denies writes to, whether that file is under a [protected path](#protected-paths) such as `.claude/skills`, under one of your `denyWrite` entries, or outside the directories the sandbox lets commands write to at all. On Linux and WSL2 the error ends with `Read-only file system`. + + After the failure, Claude may [offer to rerun the command outside the sandbox](#the-unsandboxed-retry-escape-hatch); approve that retry, or run the git command yourself in another terminal. If you've set `allowUnsandboxedCommands` to `false`, Claude can't offer the retry, so run the command yourself. If the same git command fails often, add it to [`excludedCommands`](/docs/en/settings-reference#sandbox-excludedcommands). * **Bubblewrap fails to start inside a container**: in an unprivileged container, bubblewrap can't mount a fresh `/proc` filesystem, so sandboxed commands fail with a `bwrap` error such as `Can't mount proc on /newroot/proc: Operation not permitted`. Set [`enableWeakerNestedSandbox`](/docs/en/settings-reference#sandbox-enableweakernestedsandbox) to `true` so the inner sandbox bind-mounts the container's existing `/proc` instead. Only use this setting when the outer container already provides the isolation boundary you need, since it exposes process information to sandboxed commands that a fresh `/proc` mount would hide. * **`--dangerously-skip-permissions` fails as root**: this flag is blocked when running as root or via sudo on Linux and macOS, because root access combined with no permission prompts can modify any file or service on the system. The check is skipped automatically inside a recognized sandbox. To run autonomously in a container, use the [dev container](/docs/en/devcontainer) configuration, which runs Claude Code as a non-root user. diff --git a/content/en/docs/claude-code/settings-example.md b/content/en/docs/claude-code/settings-example.md index fa6917cd8..8bfb57224 100644 --- a/content/en/docs/claude-code/settings-example.md +++ b/content/en/docs/claude-code/settings-example.md @@ -364,9 +364,9 @@ Administrators deploy a file like this as `managed-settings.json`, or the same J "repo": "acme-corp/approved-plugins" } ], - // Sandbox every command, refuse to start if the sandbox can't be set up, and - // never let a blocked command retry outside the sandbox; network limited to - // npm and GitHub, and users can't add domains + // Sandbox every command Claude runs, refuse to start if the sandbox can't be + // set up, and never let a blocked command retry outside the sandbox; network + // limited to npm and GitHub, and users can't add domains "sandbox": { "enabled": true, "failIfUnavailable": true, diff --git a/content/en/docs/claude-code/settings-reference.md b/content/en/docs/claude-code/settings-reference.md index 1f21e0c50..96e423c3a 100644 --- a/content/en/docs/claude-code/settings-reference.md +++ b/content/en/docs/claude-code/settings-reference.md @@ -620,6 +620,7 @@ scope: "Which settings files can set the key: user (~/.claude/settings.json), pr | [`awsAuthRefresh`](#awsauthrefresh) | Refresh expired [Bedrock credentials](/docs/en/amazon-bedrock#advanced-credential-configuration) in `.aws` with your own command | Authentication and providers | Any file | | [`awsCredentialExport`](#awscredentialexport) | Supply [Bedrock credentials](/docs/en/amazon-bedrock#advanced-credential-configuration) as JSON from your own command | Authentication and providers | Any file | | [`axScreenReader`](#axscreenreader) | Render [screen-reader friendly output](/docs/en/accessibility) | Interface and terminal | Any file | +| [`bashOutputMaxChars`](#bashoutputmaxchars) | Set how much of a successful command's [output](/docs/en/tools-reference#output-limits) Claude receives inline | Memory and context | Any file | | [`blockedMarketplaces`](#blockedmarketplaces) | Block [plugin marketplace](/docs/en/plugin-marketplaces) sources for your organization | Plugins and skills | Managed | | [`browserExternalPageTools`](#browserexternalpagetools) | Keep Claude's tools off external pages in the [desktop](/docs/en/desktop) Browser pane | Tools | Managed | | [`channelsEnabled`](#channelsenabled) | Allow [channels](/docs/en/channels#enable-channels-for-your-organization) for your organization | Plugins and skills | Managed | @@ -680,7 +681,7 @@ scope: "Which settings files can set the key: user (~/.claude/settings.json), pr | [`includeGitInstructions`](#includegitinstructions) | Remove the built-in commit and PR instructions from the [system prompt](/docs/en/sub-agents#what-loads-at-startup) | Git and attribution | Any file | | [`inputNeededNotifEnabled`](#inputneedednotifenabled) | Get a [push notification](/docs/en/remote-control#mobile-push-notifications) when Claude is waiting on you | Remote, desktop, and notifications | Any file | | [`isolatePeerMachines`](#isolatepeermachines) | Ask you before Claude [messages one of your sessions on another machine](/docs/en/cross-session-messaging#require-approval-for-cross-machine-messages) | Agents, sessions, and worktrees | Any file | -| [`keybindingFlavor`](#keybindingflavor) | Make `Ctrl+W` [delete back to the previous whitespace](/docs/en/interactive-mode#make-ctrl-w-delete-back-to-whitespace), as Bash does | Interface and terminal | Any file | +| [`keybindingFlavor`](#keybindingflavor) | Deprecated and has no effect; the word-editing shortcuts always [follow readline conventions](/docs/en/interactive-mode#make-ctrl-w-delete-back-to-whitespace) | Interface and terminal | Any file | | [`language`](#language) | Have Claude respond in a language other than English | Model and responses | Any file | | [`managedSourcesBehavior`](#managedsourcesbehavior) | Compose every [managed source](/docs/en/managed-settings#how-claude-code-combines-managed-sources) you deploy instead of using the highest-priority one alone | Enterprise and managed settings | Managed | | [`minimumVersion`](#minimumversion) | Keep [auto-updates](/docs/en/setup#pin-a-minimum-version) from installing anything below a version | Updates and versioning | Any file | @@ -786,6 +787,7 @@ scope: "Which settings files can set the key: user (~/.claude/settings.json), pr | [`switchModelsOnFlag`](#switchmodelsonflag) | Switch models automatically or pause when a [safety classifier](/docs/en/model-config#ask-before-switching) flags a request | Model and responses | Any file | | [`syncClaudeAiSkills`](#syncclaudeaiskills) | Stop downloading the [skills enabled on your claude.ai account](/docs/en/skills#how-synced-skills-behave) and hide the ones already synced | Plugins and skills | User, local, or managed | | [`syntaxHighlightingDisabled`](#syntaxhighlightingdisabled) | Turn off syntax highlighting in diffs and code blocks | Interface and terminal | Any file | +| [`taskOutputMaxChars`](#taskoutputmaxchars) | Set how much of a [background task's](/docs/en/tools-reference#background-commands) output Claude receives inline | Memory and context | Any file | | [`teammateDefaultModel`](#teammatedefaultmodel) | Removed in v2.1.234; see [Specify teammates and models](/docs/en/agent-teams#specify-teammates-and-models) for how Claude Code picks a teammate's model | Global config settings | Global config | | [`teammateMode`](#teammatemode) | Choose how [agent team teammates display](/docs/en/agent-teams#choose-a-display-mode) | Agents, sessions, and worktrees | Any file | | [`terminalProgressBarEnabled`](#terminalprogressbarenabled) | Hide the terminal progress bar in terminals that support it | Interface and terminal | Any file | @@ -1440,7 +1442,7 @@ List the tool uses that prompt you for confirmation even in a permission mode th ### `permissions.deny` -List the tool uses Claude Code blocks. Use it for files that hold API keys, secrets, or environment values: Claude Code excludes matching files from file discovery and search results, denies reads of them, and blocks the [Edit and Write tools](/docs/en/permissions#read-and-edit) on the matching paths. Read and Edit deny rules apply to Claude's built-in file tools and to file commands Claude Code recognizes in Bash, such as `cat`, `head`, `tail`, and `sed`; they don't apply to arbitrary subprocesses, so for OS-level enforcement [enable the sandbox](/docs/en/sandboxing). +List the tool uses Claude Code blocks. Use it for files that hold API keys, secrets, or environment values: Claude Code excludes matching files from file discovery and search results, denies reads of them, and blocks the [Edit and Write tools](/docs/en/permissions#read-and-edit) on the matching paths. Read and Edit deny rules apply to Claude's built-in file tools, to file commands Claude Code recognizes in Bash, such as `cat`, `head`, `tail`, and `sed`, and to the targets of Bash [redirections](/docs/en/permissions#redirections) such as `> file` and `< file`; they don't apply to arbitrary subprocesses, so for OS-level enforcement [enable the sandbox](/docs/en/sandboxing). * **Scope**: [`Any file`](#scopes) * **Type**: array of permission rule strings @@ -1692,7 +1694,7 @@ Name commands that Claude Code always runs outside the sandbox, such as tools th * **Scope**: [`Any file`](#scopes) * **Type**: array of command patterns -* **Default**: unset, so every command Claude Code can sandbox runs sandboxed +* **Default**: unset, so no command is excluded ```json settings.json theme={null} { @@ -1706,12 +1708,12 @@ Excluded commands still go through the regular permission flow. Exclusion is a c ### `sandbox.allowUnsandboxedCommands` -Let Claude retry a command outside the sandbox with the `dangerouslyDisableSandbox` parameter after the sandbox blocks it. Set it to `false` so Claude Code ignores that parameter completely and every command must run sandboxed or appear in [`excludedCommands`](#sandbox-excludedcommands), which the `/sandbox` **Overrides** tab shows as **Strict sandbox mode**. Use `false` in managed settings for policies that require strict sandboxing. +Let Claude retry a command outside the sandbox with the `dangerouslyDisableSandbox` parameter after the sandbox blocks it. Set it to `false` so Claude Code ignores that parameter completely and every command Claude runs must be sandboxed or appear in [`excludedCommands`](#sandbox-excludedcommands). The `/sandbox` **Overrides** tab shows that state as **Strict sandbox mode**. Use `false` in managed settings for policies that require strict sandboxing. * **Scope**: [`Any file`](#scopes) * **Type**: Boolean * `true`: Claude can retry a command outside the sandbox with the `dangerouslyDisableSandbox` parameter after the sandbox blocks it - * `false`: Claude Code ignores that parameter, so every command runs sandboxed or appears in `excludedCommands` + * `false`: Claude Code ignores that parameter, so every command Claude runs is sandboxed or appears in `excludedCommands` * **Default**: `true` This enforces strict sandbox mode for everyone the managed settings cover: @@ -1727,6 +1729,8 @@ This enforces strict sandbox mode for everyone the managed settings cover: An unsandboxed retry goes through the regular permission flow, with a prompt in Manual mode. See [The unsandboxed retry escape hatch](/docs/en/sandboxing#the-unsandboxed-retry-escape-hatch). +To see when commands you type yourself at the [`!` shell-mode prompt](/docs/en/interactive-mode#shell-mode-with-prefix) run sandboxed, see [strict sandbox mode](/docs/en/sandboxing#the-unsandboxed-retry-escape-hatch). + ### `sandbox.filesystem` Control which paths sandboxed commands can read and write. By default they can write to the working directory, the session temp directory, and directories you add with `--add-dir`, `/add-dir`, or `permissions.additionalDirectories`, and can read the rest of the filesystem, including credential files. Widen or narrow that with the four path lists, or switch the filesystem layer off with `disabled`. See [Filesystem isolation](/docs/en/sandboxing#filesystem-isolation) for the default boundaries. @@ -2637,6 +2641,22 @@ Turn [auto memory](/docs/en/memory#enable-or-disable-auto-memory) on or off. Whe } ``` +### `bashOutputMaxChars` + +Set how many characters of a successful Bash or PowerShell command's [output Claude receives inline](/docs/en/tools-reference#output-limits). When output passes the limit, Claude Code saves it to a file and Claude receives a short preview plus the file's path. Raise the limit when command output, such as a verbose build or a full test-suite log, routinely overflows the default and you want Claude to read it without opening the file. Requires Claude Code v2.1.261 or later. + +* **Scope**: [`Any file`](#scopes) +* **Type**: number of characters, a positive integer. Claude Code clamps the value into the range `4000` to `128000` +* **Default**: unset, so Claude receives up to 30,000 characters inline + +```json settings.json theme={null} +{ + "bashOutputMaxChars": 100000 +} +``` + +When you set this key, Claude Code ignores the [`BASH_MAX_OUTPUT_LENGTH`](/docs/en/env-vars) environment variable. + ### `claudeMd` Inject CLAUDE.md-style instructions as organization-managed memory without deploying a separate file. Claude Code loads the text as a managed memory entry ahead of user and project CLAUDE.md files. @@ -2785,6 +2805,22 @@ Each turn, Claude sees a [listing of your skills](/docs/en/skills#skill-descript Raise it to keep long descriptions intact at the cost of more context per turn; lower it to fit more skills under [`skillListingBudgetFraction`](#skilllistingbudgetfraction). +### `taskOutputMaxChars` + +Set how many characters of a [background task's](/docs/en/tools-reference#background-commands) output Claude receives inline when Claude reads the task with the `TaskOutput` tool. When a finished task's output is longer, Claude receives the most recent characters. Raise the limit when your background tasks routinely produce more output than the default. Requires Claude Code v2.1.261 or later. + +* **Scope**: [`Any file`](#scopes) +* **Type**: number of characters, a positive integer. Claude Code clamps the value into the range `4000` to `128000` +* **Default**: unset, so Claude receives up to 32,000 characters inline + +```json settings.json theme={null} +{ + "taskOutputMaxChars": 100000 +} +``` + +When you set this key, Claude Code ignores the [`TASK_MAX_OUTPUT_LENGTH`](/docs/en/env-vars) environment variable. + ## Interface and terminal Change how Claude Code looks and behaves in your terminal: theme, editor mode, status line, spinner, notifications inside the session, and accessibility. See [Terminal configuration](/docs/en/terminal-config). @@ -3041,21 +3077,15 @@ Footer badges render alongside a [custom status line](/docs/en/statusline) when ### `keybindingFlavor` -Choose which convention `Ctrl+W` follows in the prompt input. Set it to `"readline"` to make `Ctrl+W` delete back to the previous whitespace, as Bash does, so a path or a `--flag=value` goes in one press. Requires Claude Code v2.1.238 or later. - -* **Scope**: [`Any file`](#scopes) -* **Type**: string, one of: - * `"classic"`: `Ctrl+W` deletes the previous word - * `"readline"`: `Ctrl+W` deletes back to the previous whitespace -* **Default**: `"classic"` + + Deprecated since v2.1.261 and has no effect. The prompt's word-editing keys always [follow readline conventions](/docs/en/interactive-mode#make-ctrl-w-delete-back-to-whitespace), as in Bash. Claude Code still accepts `keybindingFlavor`, so a settings file that sets it stays valid. + -```json settings.json theme={null} -{ - "keybindingFlavor": "readline" -} -``` +In v2.1.238 through v2.1.260, setting it to `"readline"` made `Ctrl+W` delete back to the previous whitespace instead of only the previous word. -See [Make editing keys follow readline conventions](/docs/en/interactive-mode#make-ctrl-w-delete-back-to-whitespace) for the per-key behavior. +* **Scope**: [`Any file`](#scopes) +* **Type**: string, `"classic"` or `"readline"` +* **Default**: unset ### `prefersReducedMotion` diff --git a/content/en/docs/claude-code/skills.md b/content/en/docs/claude-code/skills.md index 85cad0dbe..fd08754db 100644 --- a/content/en/docs/claude-code/skills.md +++ b/content/en/docs/claude-code/skills.md @@ -164,7 +164,9 @@ Claude Code watches skill directories for file changes. When you add, edit, or r Project skills load from `.claude/skills/` in the directory where you start Claude Code and in every parent directory up to the repository root. Starting Claude in a subdirectory still picks up skills defined at the root. To load skills from a directory outside that path at startup, pass it with [`--add-dir`](/docs/en/cli-reference). Claude Code reads `.claude/skills/` inside each added directory alongside the project skills. When you [move the session with `/cd`](/docs/en/permissions#move-the-session-to-another-directory) on v2.1.246 or later, Claude Code adds the new directory's project skills. -Skills in nested `.claude/skills/` directories below your starting directory aren't loaded at startup. They load the first time Claude reads or edits a file inside that subdirectory, and stay available for the rest of the session. For example, after Claude edits a file under `packages/frontend/`, skills in `packages/frontend/.claude/skills/` become available. Until then, those skills don't appear in autocomplete and can't be invoked by name. +Skills in nested `.claude/skills/` directories below your starting directory don't load at startup. They load the first time Claude reads or edits a file in the subdirectory that contains them, and stay available for the rest of the session. For example, after Claude edits a file under `packages/frontend/`, skills in `packages/frontend/.claude/skills/` become available. Until then, those skills don't appear in autocomplete, and you can't invoke them by name. + +To load a subdirectory's skills before Claude reads or edits a file there, run `/add-dir` with that subdirectory's path. This requires Claude Code v2.1.257 or later. Files in `.claude/commands/` support the same [frontmatter](#frontmatter-reference), except `name` and `paths`, which Claude Code ignores in a command file. You invoke a command file by its file name. Skills are recommended since they support additional features like [supporting files](#add-supporting-files). @@ -654,7 +656,7 @@ Either tool runs the commands the same way it runs Claude's own shell commands. * **Working directory**: Claude Code runs each command in the session shell's current working directory. That directory moves when Claude runs `cd`. Use [`${CLAUDE_SKILL_DIR}` or `${CLAUDE_PROJECT_DIR}`](#available-string-substitutions) in paths that must resolve the same way every time. * **stderr**: with the default `bash` shell, Claude Code merges stderr into stdout. Anything the command writes to stderr appears in the injected text. * **Timeout**: each command runs under the Bash tool's default 2-minute [timeout](/docs/en/tools-reference#timeout-and-output-limits). When the Bash tool [moves a timed-out command to the background](/docs/en/tools-reference#background-commands), the skill still renders. The injected text reports the move and names the background task and the file collecting the command's output. When the command is one the Bash tool never auto-backgrounds, Claude Code kills it at the timeout. That failure [aborts the invocation](#when-an-injected-command-fails). -* **Output size**: output past the Bash tool's inline ceiling arrives as a file path plus a short preview, not truncated text. [Output limits](/docs/en/tools-reference#output-limits) covers the ceiling and which variable adjusts which boundary. +* **Output size**: output past the Bash tool's inline ceiling arrives as a file path plus a short preview, not truncated text. [Output limits](/docs/en/tools-reference#output-limits) covers the ceiling and how to adjust each boundary. The PowerShell tool applies the same timeout, backgrounding, and output-ceiling behavior to the commands it runs. See the [PowerShell tool](/docs/en/tools-reference#powershell-tool) section for its specifics. @@ -795,6 +797,14 @@ A skill that is absent from `skillOverrides` is treated as `"on"`. The example b Plugin skills are not affected by `skillOverrides`. Manage those through `/plugin` instead. +### Find unused skills + +Every skill in the [skill listing](#skill-descriptions-are-cut-short) adds to your context on every turn, whether or not Claude ever uses it. Run `/skill-doctor` to see what each of your skills costs and how often it gets used, so you can decide which ones to turn off. In an interactive session, the report opens in the `/plugin` manager's **Stats** tab. In [non-interactive mode](/docs/en/headless) with `-p`, Claude Code prints it as text. + +The report covers the skills in your session other than bundled skills and enterprise skills. It flags skills in the listing that have never been invoked and says where to turn them off. It also lists plugins you haven't used recently. + +`/skill-doctor` requires Claude Code v2.1.252 or later and isn't available in sessions that skip [feature-flag fetching](/docs/en/env-vars#features-that-need-feature-flag-fetching). If you run `/skill-doctor` over [Remote Control](/docs/en/remote-control) from your phone or browser, Claude Code replies [`Skill usage reports are not available on this connection.`](/docs/en/errors#skill-usage-reports-are-not-available-on-this-connection) instead. Run `/skill-doctor` in the terminal on the machine where the session is running. + ## Evaluate and iterate on a skill Seeing a skill trigger tells you Claude found it, not that it did what you intended. To know a skill is working, measure two things separately: whether Claude invokes it on the prompts it should, and whether the output matches what you expect when it does. @@ -1051,7 +1061,7 @@ If Claude uses your skill when you don't want it: Claude Code loads a listing of skill names and descriptions into context so Claude knows what's available. The listing always contains every skill name, but if you have many skills, Claude Code shortens descriptions to fit the listing's character budget, which can strip the keywords Claude needs to match your request. The budget scales at 1% of the model's context window. When the listing overflows, Claude Code drops descriptions starting with the skills you invoke least, so the skills you use most keep their full text. -Run `/doctor` for an estimate of the listing's context cost and its biggest contributors. When the listing exceeds its budget, Claude Code also writes a warning to the debug log, visible with [`--debug`](/docs/en/cli-reference#cli-flags). +Run `/doctor` for an estimate of the listing's context cost and its biggest contributors. To find skills worth turning off, run [`/skill-doctor`](#find-unused-skills). When the listing exceeds its budget, Claude Code also writes a warning to the debug log, visible with [`--debug`](/docs/en/cli-reference#cli-flags). The Skills row in `/context` reports the size of the listing after the budget is applied, so it matches what the model receives. Before v2.1.196, the row counted the full text of every description and could show a value several times larger than the configured budget. diff --git a/content/en/docs/claude-code/slash-commands.md b/content/en/docs/claude-code/slash-commands.md index 85cad0dbe..fd08754db 100644 --- a/content/en/docs/claude-code/slash-commands.md +++ b/content/en/docs/claude-code/slash-commands.md @@ -164,7 +164,9 @@ Claude Code watches skill directories for file changes. When you add, edit, or r Project skills load from `.claude/skills/` in the directory where you start Claude Code and in every parent directory up to the repository root. Starting Claude in a subdirectory still picks up skills defined at the root. To load skills from a directory outside that path at startup, pass it with [`--add-dir`](/docs/en/cli-reference). Claude Code reads `.claude/skills/` inside each added directory alongside the project skills. When you [move the session with `/cd`](/docs/en/permissions#move-the-session-to-another-directory) on v2.1.246 or later, Claude Code adds the new directory's project skills. -Skills in nested `.claude/skills/` directories below your starting directory aren't loaded at startup. They load the first time Claude reads or edits a file inside that subdirectory, and stay available for the rest of the session. For example, after Claude edits a file under `packages/frontend/`, skills in `packages/frontend/.claude/skills/` become available. Until then, those skills don't appear in autocomplete and can't be invoked by name. +Skills in nested `.claude/skills/` directories below your starting directory don't load at startup. They load the first time Claude reads or edits a file in the subdirectory that contains them, and stay available for the rest of the session. For example, after Claude edits a file under `packages/frontend/`, skills in `packages/frontend/.claude/skills/` become available. Until then, those skills don't appear in autocomplete, and you can't invoke them by name. + +To load a subdirectory's skills before Claude reads or edits a file there, run `/add-dir` with that subdirectory's path. This requires Claude Code v2.1.257 or later. Files in `.claude/commands/` support the same [frontmatter](#frontmatter-reference), except `name` and `paths`, which Claude Code ignores in a command file. You invoke a command file by its file name. Skills are recommended since they support additional features like [supporting files](#add-supporting-files). @@ -654,7 +656,7 @@ Either tool runs the commands the same way it runs Claude's own shell commands. * **Working directory**: Claude Code runs each command in the session shell's current working directory. That directory moves when Claude runs `cd`. Use [`${CLAUDE_SKILL_DIR}` or `${CLAUDE_PROJECT_DIR}`](#available-string-substitutions) in paths that must resolve the same way every time. * **stderr**: with the default `bash` shell, Claude Code merges stderr into stdout. Anything the command writes to stderr appears in the injected text. * **Timeout**: each command runs under the Bash tool's default 2-minute [timeout](/docs/en/tools-reference#timeout-and-output-limits). When the Bash tool [moves a timed-out command to the background](/docs/en/tools-reference#background-commands), the skill still renders. The injected text reports the move and names the background task and the file collecting the command's output. When the command is one the Bash tool never auto-backgrounds, Claude Code kills it at the timeout. That failure [aborts the invocation](#when-an-injected-command-fails). -* **Output size**: output past the Bash tool's inline ceiling arrives as a file path plus a short preview, not truncated text. [Output limits](/docs/en/tools-reference#output-limits) covers the ceiling and which variable adjusts which boundary. +* **Output size**: output past the Bash tool's inline ceiling arrives as a file path plus a short preview, not truncated text. [Output limits](/docs/en/tools-reference#output-limits) covers the ceiling and how to adjust each boundary. The PowerShell tool applies the same timeout, backgrounding, and output-ceiling behavior to the commands it runs. See the [PowerShell tool](/docs/en/tools-reference#powershell-tool) section for its specifics. @@ -795,6 +797,14 @@ A skill that is absent from `skillOverrides` is treated as `"on"`. The example b Plugin skills are not affected by `skillOverrides`. Manage those through `/plugin` instead. +### Find unused skills + +Every skill in the [skill listing](#skill-descriptions-are-cut-short) adds to your context on every turn, whether or not Claude ever uses it. Run `/skill-doctor` to see what each of your skills costs and how often it gets used, so you can decide which ones to turn off. In an interactive session, the report opens in the `/plugin` manager's **Stats** tab. In [non-interactive mode](/docs/en/headless) with `-p`, Claude Code prints it as text. + +The report covers the skills in your session other than bundled skills and enterprise skills. It flags skills in the listing that have never been invoked and says where to turn them off. It also lists plugins you haven't used recently. + +`/skill-doctor` requires Claude Code v2.1.252 or later and isn't available in sessions that skip [feature-flag fetching](/docs/en/env-vars#features-that-need-feature-flag-fetching). If you run `/skill-doctor` over [Remote Control](/docs/en/remote-control) from your phone or browser, Claude Code replies [`Skill usage reports are not available on this connection.`](/docs/en/errors#skill-usage-reports-are-not-available-on-this-connection) instead. Run `/skill-doctor` in the terminal on the machine where the session is running. + ## Evaluate and iterate on a skill Seeing a skill trigger tells you Claude found it, not that it did what you intended. To know a skill is working, measure two things separately: whether Claude invokes it on the prompts it should, and whether the output matches what you expect when it does. @@ -1051,7 +1061,7 @@ If Claude uses your skill when you don't want it: Claude Code loads a listing of skill names and descriptions into context so Claude knows what's available. The listing always contains every skill name, but if you have many skills, Claude Code shortens descriptions to fit the listing's character budget, which can strip the keywords Claude needs to match your request. The budget scales at 1% of the model's context window. When the listing overflows, Claude Code drops descriptions starting with the skills you invoke least, so the skills you use most keep their full text. -Run `/doctor` for an estimate of the listing's context cost and its biggest contributors. When the listing exceeds its budget, Claude Code also writes a warning to the debug log, visible with [`--debug`](/docs/en/cli-reference#cli-flags). +Run `/doctor` for an estimate of the listing's context cost and its biggest contributors. To find skills worth turning off, run [`/skill-doctor`](#find-unused-skills). When the listing exceeds its budget, Claude Code also writes a warning to the debug log, visible with [`--debug`](/docs/en/cli-reference#cli-flags). The Skills row in `/context` reports the size of the listing after the budget is applied, so it matches what the model receives. Before v2.1.196, the row counted the full text of every description and could show a value several times larger than the configured budget. diff --git a/content/en/docs/claude-code/statusline.md b/content/en/docs/claude-code/statusline.md index a677ac70a..e6664a19f 100644 --- a/content/en/docs/claude-code/statusline.md +++ b/content/en/docs/claude-code/statusline.md @@ -273,6 +273,14 @@ Claude Code sends the following JSON fields to your script via stdin: "cache_write_tokens": 352000, "miss_recache_tokens": 310200, "last_miss_at": 1738425230, + "last_miss_cause": { + "causes": ["tools_changed"], + "tools_added": 2, + "tools_removed": 0 + }, + "miss_causes": { + "tools_changed": 2 + }, "recache_tokens_if_cold": 45000 }, "fast_mode": false, @@ -382,10 +390,23 @@ The table lists each field with its meaning. Timestamps are Unix epoch seconds, | `cache_write_tokens` | All tokens written to the cache this session, the first request's initial write included | | `miss_recache_tokens` | Tokens written to the cache by the requests counted as misses | | `last_miss_at` | When the last miss happened, in epoch seconds. `null` while the session has no misses | +| `last_miss_cause` | What Claude Code identified as the likely cause of the last miss, described under [Last miss cause](#last-miss-cause). Requires Claude Code v2.1.260 or later | +| `miss_causes` | How many of this session's diagnosed misses had each cause, keyed by the same cause names as `last_miss_cause`. Requires Claude Code v2.1.260 or later | | `recache_tokens_if_cold` | Tokens the next request re-caches if the cache has gone cold by then. `null` right after a compaction or a clearing of old tool results, until the next request records the rewritten conversation's size | Claude Code shows the same statistics in the terminal, on the [`/usage` command's `Prompt cache (main)` line](/docs/en/costs#prompt-cache-statistics). +

+ Last miss cause +

+ +The `last_miss_cause` object reports what Claude Code identified as the likely cause of the most recent miss. Its `causes` array holds one or more cause names, such as `tools_changed`, `system_prompt_changed`, `ttl_expired_5m`, or `likely_server_side`. The object is `null` until the session's first miss, and again whenever Claude Code couldn't identify a cause for the most recent miss. Requires Claude Code v2.1.260 or later. + +Two causes add counts to the object: + +* `tools_added` and `tools_removed`: with `tools_changed`, how many tools were added to or removed from the request +* `system_char_delta`: with `system_prompt_changed`, the change in the system prompt's length, in characters + ## Examples These examples show common status line patterns. To use any example: diff --git a/content/en/docs/claude-code/sub-agents.md b/content/en/docs/claude-code/sub-agents.md index 114dc0b6b..ec699fdbf 100644 --- a/content/en/docs/claude-code/sub-agents.md +++ b/content/en/docs/claude-code/sub-agents.md @@ -275,7 +275,7 @@ This working-directory check covers the whole repository containing the director For Bash commands, Claude Code also checks the command itself in two ways: * It blocks a command that redirects git into the main checkout. -* It refuses a command whose shape it can't verify stays inside the worktree. This refusal applies even to a command that runs no git. +* It refuses a command when it can't verify from the command text that any git the command runs stays inside the worktree, for example when the command name is computed at runtime. The redirect vectors and the shape rules are listed under [How Claude Code enforces isolation](/docs/en/worktrees#how-claude-code-enforces-isolation). PowerShell commands get only the working-directory check. diff --git a/content/en/docs/claude-code/terminal-config.md b/content/en/docs/claude-code/terminal-config.md index 83043c3e7..2d078aefd 100644 --- a/content/en/docs/claude-code/terminal-config.md +++ b/content/en/docs/claude-code/terminal-config.md @@ -310,7 +310,7 @@ Run `/tui fullscreen` to switch and save the preference. Your conversation relau When you paste more than 800 characters or more than three lines into the prompt, Claude Code collapses the input to a placeholder such as `[Pasted text #1 +120 lines]` so the input box stays usable. In a terminal window shorter than 12 rows the line limit drops, so Claude Code collapses a three-line paste at 11 rows and any multi-line paste at 10 rows or fewer. Claude Code still sends the full content when you submit. -When you delete with a word or line shortcut such as `Ctrl+W` or `Ctrl+K`, or with a vim delete through an `f`/`t` motion such as `df]`, and the deleted range reaches inside a placeholder, Claude Code removes the placeholder whole. You can paste the deletion back to restore it, with [`Ctrl+Y`](/docs/en/interactive-mode#text-editing) after `Ctrl+W`, `Ctrl+U`, or `Ctrl+K`, or with [`p` in NORMAL mode](/docs/en/interactive-mode#editing-normal-mode) after a vim delete. +When you delete with a word or line shortcut such as `Ctrl+W` or `Ctrl+K`, or with a vim delete through an `f`/`t` motion such as `df]`, and the deleted range reaches inside a placeholder, Claude Code removes the placeholder whole. You can paste the deletion back to restore it, with [`Ctrl+Y`](/docs/en/interactive-mode#text-editing) after a word or line shortcut, or with [`p` in NORMAL mode](/docs/en/interactive-mode#editing-normal-mode) after a vim delete. Claude Code keeps the collapsed content under `~/.claude/paste-cache/`, so when you recall a prompt from [command history](/docs/en/interactive-mode#command-history) and resubmit it, Claude Code sends the full pasted content again, including in a later session, until the retention sweep removes the cache file. diff --git a/content/en/docs/claude-code/tools-reference.md b/content/en/docs/claude-code/tools-reference.md index ed541fb36..6c2cb7173 100644 --- a/content/en/docs/claude-code/tools-reference.md +++ b/content/en/docs/claude-code/tools-reference.md @@ -161,18 +161,22 @@ Each command runs under a timeout, and Claude manages it: when it wants longer t Claude Code streams a command's output to a working file as the command runs; a command whose output passes 5 GB is killed. When the command finishes, Claude Code reads the output back from that file, up to the read-back window described below. How much of the output reaches Claude inline depends on whether Claude Code treats the result as a failure: -| Result | What Claude gets | -| :------ | :----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Valid | Inline up to roughly 30,000 characters; past that, the path of a file saved to the session directory, truncated past 64 MiB, plus a short preview from the start, and Claude reads or searches the file when it needs the rest | -| Failure | Inline up to roughly 10,000 characters; past that, a head-and-tail excerpt of that size cut from the read-back window, with no file path | +| Result | What Claude gets | +| :------ | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| Valid | Inline up to roughly 30,000 characters by default; past that, the path of a file saved to the session directory and truncated past 64 MiB, plus a short preview from the start, and Claude reads or searches the file when it needs the rest | +| Failure | Inline up to roughly 10,000 characters; past that, a head-and-tail excerpt of that size cut from the read-back window, with no file path | A command that exits 1 counts as a valid result for the Bash tool only when Claude Code recognizes exit code 1 as a benign outcome for that command: `grep`, `rg`, `egrep`, `fgrep`, `find`, `diff`, `test`, and `[`, plus `git diff` and `git grep`. Every other command that exits 1 counts as a failure, even when exit 1 is a benign informational outcome: no matches for `pgrep` and `jq -e`, files that differ for `cmp`. -[`BASH_MAX_OUTPUT_LENGTH`](/docs/en/env-vars) sets how many characters of output Claude Code reads back from the working file into a command's result: 30,000 by default, up to a hard ceiling of 150,000. Raise it when your commands routinely overflow that window, such as a verbose build or a full test-suite log. Raising it enlarges the read-back window, and the window a failing command's excerpt is cut from. It does not raise the inline ceilings above: a valid result over roughly 30,000 characters arrives as a file path plus preview regardless of this variable. +[`BASH_MAX_OUTPUT_LENGTH`](/docs/en/env-vars) sets how many characters of output Claude Code reads back from the working file into a command's result: 30,000 by default, up to a hard ceiling of 150,000. Raise it when your commands routinely overflow that window, such as a verbose build or a full test-suite log. Raising it enlarges the read-back window, which is also the window a failing command's excerpt is cut from. It doesn't raise the inline ceilings: a valid result over the inline ceiling arrives as a file path plus preview regardless of this variable. + +To change how much of a valid result Claude receives inline, set the [`bashOutputMaxChars`](/docs/en/settings-reference#bashoutputmaxchars) setting instead, up to 128,000 characters. It sizes the inline ceiling and the read-back window together, and Claude Code then ignores `BASH_MAX_OUTPUT_LENGTH`. Requires Claude Code v2.1.261 or later. ### Background commands -For long-running processes such as dev servers or watch builds, Claude can set `run_in_background: true` to start the command as a background task and continue working while it runs. List and stop background tasks with `/tasks`. When a [subagent running in the foreground](/docs/en/sub-agents#run-subagents-in-foreground-or-background) started the command, Claude Code ends it when that subagent gives its final response. Commands started by the main conversation or by a background subagent keep running. In non-interactive mode with the `-p` flag, [background tasks end shortly after the run's final result](/docs/en/headless#background-tasks-at-exit). +For long-running processes such as dev servers or watch builds, Claude can set `run_in_background: true` to start the command as a background task and continue working while it runs. List and stop background tasks with `/tasks`. After you stop one there, or from a connected client such as the desktop app, Claude moves on instead of waiting for it. If a subagent started the command, it's that subagent that moves on. + +A command that a [foreground subagent](/docs/en/sub-agents#run-subagents-in-foreground-or-background) started stops when that subagent gives its final response. A command that the main conversation or a background subagent started keeps running after a final response. In non-interactive mode with the `-p` flag, [background commands end shortly after the run's final result](/docs/en/headless#background-tasks-at-exit). When a command reaches its timeout without finishing, Claude Code moves it to the background instead of stopping it. Claude keeps working while the command continues. Claude Code applies the same lifetime rules to a moved command as to any other background command, so it still ends a foreground subagent's command at that subagent's final response. Setting [`CLAUDE_CODE_DISABLE_BACKGROUND_TASKS=1`](/docs/en/env-vars#variables) disables auto-backgrounding along with the rest of the background task functionality. @@ -227,7 +231,7 @@ A file that changed on disk after Claude last read it can still be edited when ` Viewing a file with Bash also satisfies the read-before-edit requirement when the command is `cat`, `nl`, `bat`, `batcat`, `head`, `tail`, `sed -n 'X,Yp'`, `grep`, `egrep`, `fgrep`, or `rg` on a single file with no pipes or redirects. Piped output and other Bash commands don't count toward the read-before-edit check. -This affects edit eligibility only, not permissions. [Read and Edit deny rules](/docs/en/permissions#tool-specific-permission-rules) also apply to file commands Claude Code recognizes in Bash, such as `cat`, `head`, `tail`, `sed`, and `grep`, but not to arbitrary subprocesses that read or write files indirectly, like a Python or Node script that opens files itself. The set of commands recognized for deny rules is not the same as the read-before-edit list above: for example, `egrep` and `fgrep` count for read-before-edit but are not checked against Read deny rules. For OS-level enforcement that covers every process, [enable the sandbox](/docs/en/sandboxing). +Viewing a file with Bash affects edit eligibility only, not permissions. See [Read and Edit permission rules](/docs/en/permissions#read-and-edit) for which Bash commands your `Read` and `Edit` deny rules cover. ## EndConversation tool behavior @@ -319,7 +323,9 @@ The Monitor tool lets Claude watch something in the background and react when it For most watches, Claude writes a small script, runs it in the background, and receives each output line as it arrives. For a server that already pushes events, Claude can open a [WebSocket](#websocket-source) instead of running a script. -You keep working in the same session and Claude interjects when an event arrives. Stop a monitor by asking Claude to cancel it or by ending the session. +You keep working in the same session and Claude interjects when an event arrives. + +Stop a monitor by asking Claude to cancel it or by ending the session. When you stop a [subagent](/docs/en/sub-agents) that started monitors, for example from `/tasks`, those monitors stop with it. When Monitor runs a command, it uses the same [permission rules as Bash](/docs/en/permissions#tool-specific-permission-rules), so `allow` and `deny` patterns you have set for Bash apply here too. While [auto mode](/docs/en/permission-modes#eliminate-prompts-with-auto-mode) is active, Claude Code sets aside allow rules that name `Monitor` itself, along with the other [broad allow rules it drops](/docs/en/permission-modes#how-the-classifier-evaluates-actions), so the classifier reviews Monitor commands the same way it reviews Bash commands. diff --git a/content/en/docs/claude-code/troubleshooting.md b/content/en/docs/claude-code/troubleshooting.md index fb54d5ad4..a6d9cf8d4 100644 --- a/content/en/docs/claude-code/troubleshooting.md +++ b/content/en/docs/claude-code/troubleshooting.md @@ -80,6 +80,20 @@ Restarting doesn't lose your conversation. Run `claude --resume` in the same dir If characters render as boxes, smears, or the wrong glyphs when running Claude Code in the VS Code, Cursor, or Devin Desktop integrated terminal, the terminal's GPU renderer is likely the cause. Run `/terminal-setup` inside Claude Code to set `terminal.integrated.gpuAcceleration` to `"off"`, or set it manually in your editor settings and reload the window. See [Terminal configuration](/docs/en/terminal-config) for the other settings `/terminal-setup` writes. +### Mouse wheel scrolls one line at a time in fullscreen rendering + +In [fullscreen rendering](/docs/en/fullscreen), Claude Code scrolls the conversation itself rather than leaving it to your terminal. If each wheel notch moves fewer lines than you want, run `/scroll-speed` to raise the number of lines per notch and save it, or set the `CLAUDE_CODE_SCROLL_SPEED` environment variable, except in the JetBrains IDE terminal, where Claude Code applies its own scroll handling and neither takes effect. See [Mouse wheel scrolling](/docs/en/fullscreen#mouse-wheel-scrolling) for the values each accepts. + +To move faster without changing the speed, press `PgUp` and `PgDn` to scroll half a screen at a time. To hand scrolling back to your terminal's native scrollback instead, run `/tui default` to switch to the classic renderer. + +### Clipboard commands such as `pbcopy` fail inside the sandbox + +When [sandboxing](/docs/en/sandboxing) is on, clipboard utilities such as `pbcopy`, `xclip`, and `wl-copy` can fail to reach the system clipboard from inside a sandboxed Bash command, leaving your clipboard unchanged after Claude pipes text to them. + +To put Claude's output on your clipboard, ask Claude to print the content in its response, then run [`/copy`](/docs/en/commands). `/copy` writes to the clipboard from the Claude Code process itself rather than from a sandboxed command, so sandboxing doesn't block it. It can copy a single code block instead of the whole response, and it also writes what it copied to a file and prints the path, which gives you a fallback when the clipboard write doesn't reach your terminal, for example over SSH. + +To let a piped command reach the clipboard directly instead, add `pbcopy *`, `wl-copy *`, or `xclip *` to [`excludedCommands`](/docs/en/settings-reference#sandbox-excludedcommands) so the command runs outside the sandbox. + ### Search and discovery issues If the Search tool, `@file` mentions, custom agents, or custom skills aren't finding files, the bundled `ripgrep` binary may not run on your system. Install your platform's `ripgrep` package and tell Claude Code to use it instead: diff --git a/content/en/docs/claude-code/worktrees.md b/content/en/docs/claude-code/worktrees.md index fe44c2fbc..374e9fdf7 100644 --- a/content/en/docs/claude-code/worktrees.md +++ b/content/en/docs/claude-code/worktrees.md @@ -89,7 +89,7 @@ Claude Code applies four checks: * **File edits**: Claude Code blocks an `Edit`, `Write`, or `NotebookEdit` that targets a path in the main checkout. * **Command working directory**: Claude Code blocks a Bash, PowerShell, or Monitor command whose working directory resolves to the main checkout, or whose working directory it can't verify stays outside it. * **Git redirects**: Claude Code blocks a Bash or Monitor command that redirects git into the main checkout. The redirect can come through `git -C`, `--git-dir`, a `GIT_DIR` or `GIT_WORK_TREE` variable, or a `cd` into the main checkout before running git. -* **Command shape**: Claude Code blocks a Bash or Monitor command it can't verify stays inside the worktree, even when the command runs no git at all. Claude Code refuses shell constructs it can't trace without running them, such as brace expansion and heredocs with unquoted delimiters. Claude Code tells Claude how to rewrite the refused command, such as splitting it into plain, separate commands. You can't turn this check off. +* **Command shape**: Claude Code blocks a Bash or Monitor command when it can't verify from the command text that any git the command runs stays inside the worktree, for example when the command name is computed at runtime or the syntax can't be parsed. Claude Code tells Claude how to rewrite the refused command, such as splitting it into plain, separate commands. You can't turn this check off. The checks apply to the repository you launched Claude Code from. They also cover the main checkout a linked worktree is linked from. For PowerShell commands, Claude Code applies only the working-directory check. diff --git a/content/en/manage-claude/wif-providers/aws.md b/content/en/manage-claude/wif-providers/aws.md index ffb74c06e..2cf0e47c3 100644 --- a/content/en/manage-claude/wif-providers/aws.md +++ b/content/en/manage-claude/wif-providers/aws.md @@ -291,6 +291,12 @@ Call `GetWebIdentityToken` with `https://api.anthropic.com` as the audience, the ``` ```csharp C# + using Amazon.SecurityToken; + using Amazon.SecurityToken.Model; + // ... + using Anthropic.Credentials; + // ... + var credentials = new WorkloadIdentityCredentials(new WorkloadIdentityOptions { FederationRuleId = Environment.GetEnvironmentVariable("ANTHROPIC_FEDERATION_RULE_ID")!, @@ -299,7 +305,7 @@ Call `GetWebIdentityToken` with `https://api.anthropic.com` as the audience, the WorkspaceId = Environment.GetEnvironmentVariable("ANTHROPIC_WORKSPACE_ID"), IdentityTokenProvider = new StsTokenProvider(), }); - using var client = new AnthropicOidcClient(credentials); + using var client = new AnthropicClient(new ClientOptions { Credentials = credentials }); var message = await client.Messages.Create(new() { @@ -702,9 +708,10 @@ Inside the pod, the projected token is at `/var/run/secrets/anthropic.com/token` ``` ```csharp C# - var result = AnthropicCredentials.Resolve() - ?? throw new InvalidOperationException("No federation credentials found in environment"); - using var client = new AnthropicOidcClient(result); + // Reads ANTHROPIC_FEDERATION_RULE_ID, ANTHROPIC_ORGANIZATION_ID, + // ANTHROPIC_SERVICE_ACCOUNT_ID, ANTHROPIC_WORKSPACE_ID, and ANTHROPIC_IDENTITY_TOKEN_FILE + // from the pod's environment. + using var client = new AnthropicClient(); var message = await client.Messages.Create(new() { diff --git a/content/en/manage-claude/wif-providers/azure.md b/content/en/manage-claude/wif-providers/azure.md index 7bc86a4bf..65a30ddff 100644 --- a/content/en/manage-claude/wif-providers/azure.md +++ b/content/en/manage-claude/wif-providers/azure.md @@ -417,6 +417,9 @@ The samples fetch the managed identity token from the platform's token endpoint: ``` ```csharp C# + using Anthropic.Credentials; + // ... + var credentials = new WorkloadIdentityCredentials(new WorkloadIdentityOptions { FederationRuleId = Environment.GetEnvironmentVariable("ANTHROPIC_FEDERATION_RULE_ID")!, @@ -425,7 +428,7 @@ The samples fetch the managed identity token from the platform's token endpoint: WorkspaceId = Environment.GetEnvironmentVariable("ANTHROPIC_WORKSPACE_ID"), IdentityTokenProvider = new EntraTokenProvider(), }); - using var client = new AnthropicOidcClient(credentials); + using var client = new AnthropicClient(new ClientOptions { Credentials = credentials }); var message = await client.Messages.Create(new() { @@ -1017,6 +1020,9 @@ Two different client IDs appear in the samples. `` is the audience app r ``` ```csharp C# + using Anthropic.Credentials; + // ... + var credentials = new WorkloadIdentityCredentials(new WorkloadIdentityOptions { FederationRuleId = Environment.GetEnvironmentVariable("ANTHROPIC_FEDERATION_RULE_ID")!, @@ -1025,7 +1031,7 @@ Two different client IDs appear in the samples. `` is the audience app r WorkspaceId = Environment.GetEnvironmentVariable("ANTHROPIC_WORKSPACE_ID"), IdentityTokenProvider = new EntraFederationTokenProvider(), }); - using var client = new AnthropicOidcClient(credentials); + using var client = new AnthropicClient(new ClientOptions { Credentials = credentials }); var message = await client.Messages.Create(new() { diff --git a/content/en/manage-claude/wif-providers/gcp.md b/content/en/manage-claude/wif-providers/gcp.md index 9fa3a2df1..b628a2dbd 100644 --- a/content/en/manage-claude/wif-providers/gcp.md +++ b/content/en/manage-claude/wif-providers/gcp.md @@ -308,6 +308,9 @@ Inside your Google Cloud workload, fetch the identity token from the metadata se ``` ```csharp C# + using Anthropic.Credentials; + // ... + var credentials = new WorkloadIdentityCredentials(new WorkloadIdentityOptions { FederationRuleId = Environment.GetEnvironmentVariable("ANTHROPIC_FEDERATION_RULE_ID")!, @@ -316,7 +319,7 @@ Inside your Google Cloud workload, fetch the identity token from the metadata se WorkspaceId = Environment.GetEnvironmentVariable("ANTHROPIC_WORKSPACE_ID"), IdentityTokenProvider = new MetadataTokenProvider(), }); - using var client = new AnthropicOidcClient(credentials); + using var client = new AnthropicClient(new ClientOptions { Credentials = credentials }); var message = await client.Messages.Create(new() { diff --git a/content/en/manage-claude/wif-providers/github-actions.md b/content/en/manage-claude/wif-providers/github-actions.md index eaf95121c..1f780f2a7 100644 --- a/content/en/manage-claude/wif-providers/github-actions.md +++ b/content/en/manage-claude/wif-providers/github-actions.md @@ -245,9 +245,10 @@ Set the federation environment variables on the job and call the SDK normally. ` ``` ```csharp C# - var result = AnthropicCredentials.Resolve() - ?? throw new InvalidOperationException("No federation credentials found in environment"); - using var client = new AnthropicOidcClient(result); + // Reads ANTHROPIC_FEDERATION_RULE_ID, ANTHROPIC_ORGANIZATION_ID, + // ANTHROPIC_SERVICE_ACCOUNT_ID, ANTHROPIC_WORKSPACE_ID, and ANTHROPIC_IDENTITY_TOKEN_FILE + // from the job environment. + using var client = new AnthropicClient(); var message = await client.Messages.Create(new() { diff --git a/content/en/manage-claude/wif-providers/kubernetes.md b/content/en/manage-claude/wif-providers/kubernetes.md index 4270389d1..8295dda1a 100644 --- a/content/en/manage-claude/wif-providers/kubernetes.md +++ b/content/en/manage-claude/wif-providers/kubernetes.md @@ -228,9 +228,10 @@ The pod spec in [Configure Kubernetes](https://platform.claude.com/docs/en/manag ``` ```csharp C# - var result = AnthropicCredentials.Resolve() - ?? throw new InvalidOperationException("No federation credentials found in environment"); - using var client = new AnthropicOidcClient(result); + // Reads ANTHROPIC_IDENTITY_TOKEN_FILE, ANTHROPIC_FEDERATION_RULE_ID, + // ANTHROPIC_ORGANIZATION_ID, ANTHROPIC_SERVICE_ACCOUNT_ID, and ANTHROPIC_WORKSPACE_ID + // from the pod's environment. + using var client = new AnthropicClient(); var message = await client.Messages.Create(new() { diff --git a/content/en/manage-claude/wif-providers/okta.md b/content/en/manage-claude/wif-providers/okta.md index c90c597a3..68c99f528 100644 --- a/content/en/manage-claude/wif-providers/okta.md +++ b/content/en/manage-claude/wif-providers/okta.md @@ -307,6 +307,9 @@ Unlike platform-native providers (AWS, Google Cloud, Kubernetes), which make a t ``` ```csharp C# + using Anthropic.Credentials; + // ... + var credentials = new WorkloadIdentityCredentials(new WorkloadIdentityOptions { FederationRuleId = Environment.GetEnvironmentVariable("ANTHROPIC_FEDERATION_RULE_ID")!, @@ -315,7 +318,7 @@ Unlike platform-native providers (AWS, Google Cloud, Kubernetes), which make a t WorkspaceId = Environment.GetEnvironmentVariable("ANTHROPIC_WORKSPACE_ID"), IdentityTokenProvider = new OktaTokenProvider(), }); - using var client = new AnthropicOidcClient(credentials); + using var client = new AnthropicClient(new ClientOptions { Credentials = credentials }); var message = await client.Messages.Create(new() { diff --git a/content/en/manage-claude/workload-identity-federation.md b/content/en/manage-claude/workload-identity-federation.md index 89a6e71df..8d552b99a 100644 --- a/content/en/manage-claude/workload-identity-federation.md +++ b/content/en/manage-claude/workload-identity-federation.md @@ -249,8 +249,8 @@ You can construct the client with explicit credentials or with no arguments. Wit ``` ```csharp C# - using Anthropic.Models.Messages; - using Anthropic.Oidc; + using Anthropic.Credentials; + // ... var credentials = new WorkloadIdentityCredentials(new WorkloadIdentityOptions { @@ -260,7 +260,7 @@ You can construct the client with explicit credentials or with no arguments. Wit WorkspaceId = "wrkspc_...", IdentityTokenProvider = new FileIdentityTokenProvider("/var/run/secrets/anthropic.com/token"), }); - using var client = new AnthropicOidcClient(credentials); + using var client = new AnthropicClient(new ClientOptions { Credentials = credentials }); var message = await client.Messages.Create(new() { diff --git a/content/github/anthropic-sdk-python/CHANGELOG.md b/content/github/anthropic-sdk-python/CHANGELOG.md index 9a1abb15a..e4a4d009f 100644 --- a/content/github/anthropic-sdk-python/CHANGELOG.md +++ b/content/github/anthropic-sdk-python/CHANGELOG.md @@ -1,5 +1,38 @@ # Changelog +## 1.4.0 (2026-09-04) + +Full Changelog: [v1.3.0...v1.4.0](https://github.com/anthropics/anthropic-sdk-python/compare/v1.3.0...v1.4.0) + +### Features + +* **api:** add Claude Tag category and user breakdowns to usage reports ([9fce1e4](https://github.com/anthropics/anthropic-sdk-python/commit/9fce1e4994e113c35f4a7116d0c5eb90367b9c66)) +* **api:** add named types for organization compliance settings state ([1de1957](https://github.com/anthropics/anthropic-sdk-python/commit/1de1957334e7491979ddb21a1d673fa4e56d5459)) +* **api:** add support for sending a workspace ID on more endpoints ([d1d2c01](https://github.com/anthropics/anthropic-sdk-python/commit/d1d2c01d8aa128080dea3d711e12cb3df95a2149)) + + +### Bug Fixes + +* **client:** raise a clear error when an httpx object is passed instead of an httpx2 one ([9447099](https://github.com/anthropics/anthropic-sdk-python/commit/94470992f0f00ed331f2faa585cfda2cb8412a08)) +* repair custom-code merge in messages resources ([#580](https://github.com/anthropics/anthropic-sdk-python/issues/580)) ([85454ca](https://github.com/anthropics/anthropic-sdk-python/commit/85454cab9a323801b76500707b84c1992c1c0ee4)) + + +### Chores + +* **examples:** refresh platform model IDs ([#499](https://github.com/anthropics/anthropic-sdk-python/issues/499)) ([182abb5](https://github.com/anthropics/anthropic-sdk-python/commit/182abb51cdb5dda815b0b2498dc4adaab6dde469)) +* **internal:** bundle the mock server spec and update dev tooling ([f9b0cf2](https://github.com/anthropics/anthropic-sdk-python/commit/f9b0cf281932512e6b40cd1a887a44542c883468)) +* **internal:** clean up code comments ([#578](https://github.com/anthropics/anthropic-sdk-python/issues/578)) ([d202327](https://github.com/anthropics/anthropic-sdk-python/commit/d2023274f69dd0609ddabbf8f6af08041f868d8b)) +* **internal:** fix mypy unreachable error in detect-breaking-changes script ([07834f6](https://github.com/anthropics/anthropic-sdk-python/commit/07834f601fb4a81958f15e2129ca091cb9d1c646)) +* **internal:** narrower codeowners scope ([daca8f1](https://github.com/anthropics/anthropic-sdk-python/commit/daca8f13032311676ed30a6e0527ee304e1419c9)) +* **internal:** revert codeowners change ([41aa767](https://github.com/anthropics/anthropic-sdk-python/commit/41aa767464881bb51937f42fe9c426ae3081fd9f)) +* **tests:** remove stale warning filters ([ba9bf35](https://github.com/anthropics/anthropic-sdk-python/commit/ba9bf356ed60fa2eb206e266c86c0202dd005616)) +* **tests:** reword the skip reason on the path-level query param tests ([6b5046a](https://github.com/anthropics/anthropic-sdk-python/commit/6b5046ad29999ec887226aecff67db9feb2d1972)) + + +### Documentation + +* **api:** update a few doc strings ([26c509d](https://github.com/anthropics/anthropic-sdk-python/commit/26c509d66192f2b40150b481fa89da97e532612c)) + ## 1.3.0 (2026-09-01) Full Changelog: [v1.2.0...v1.3.0](https://github.com/anthropics/anthropic-sdk-python/compare/v1.2.0...v1.3.0) diff --git a/content/github/anthropic-sdk-python/api.md b/content/github/anthropic-sdk-python/api.md index 39521e96e..03915b9e5 100644 --- a/content/github/anthropic-sdk-python/api.md +++ b/content/github/anthropic-sdk-python/api.md @@ -1770,10 +1770,12 @@ Types: ```python from anthropic.types.beta.organization import ( BetaComplianceSettings, + BetaComplianceSettingsState, BetaComplianceSettingsStateDisabled, BetaComplianceSettingsStateDisabledParam, BetaComplianceSettingsStateEnabled, BetaComplianceSettingsStateEnabledParam, + BetaComplianceSettingsStateParam, ) ``` diff --git a/content/github/anthropic-sdk-typescript/CHANGELOG.md b/content/github/anthropic-sdk-typescript/CHANGELOG.md index 1a716b613..a8b73730a 100644 --- a/content/github/anthropic-sdk-typescript/CHANGELOG.md +++ b/content/github/anthropic-sdk-typescript/CHANGELOG.md @@ -1,5 +1,33 @@ # Changelog +## 0.124.0 (2026-09-04) + +Full Changelog: [sdk-v0.123.0...sdk-v0.124.0](https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.123.0...sdk-v0.124.0) + +### Features + +* **api:** add Claude Tag category and user breakdowns to usage reports ([669ff22](https://github.com/anthropics/anthropic-sdk-typescript/commit/669ff2243179acb2df775e62bfd75e3da1d60d81)) +* **api:** add named types for organization compliance settings state ([54be8da](https://github.com/anthropics/anthropic-sdk-typescript/commit/54be8da7176d7aaa2c3e62ad2e0d5289182a55ed)) +* **api:** add support for sending a workspace ID on more endpoints ([a11e6f1](https://github.com/anthropics/anthropic-sdk-typescript/commit/a11e6f1d3bb0e12e6369d3611a232a6234e715eb)) + + +### Bug Fixes + +* repair custom-code merge in messages resources ([#455](https://github.com/anthropics/anthropic-sdk-typescript/issues/455)) ([7ac43b9](https://github.com/anthropics/anthropic-sdk-typescript/commit/7ac43b92e793f06626bfa7d22ad152e2f44c4d3c)) +* **tools:** create agent-toolset files and directories owner-only ([#485](https://github.com/anthropics/anthropic-sdk-typescript/issues/485)) ([a9c2298](https://github.com/anthropics/anthropic-sdk-typescript/commit/a9c2298873db41b5084efaac01683b025ca2a4f6)) + + +### Chores + +* **internal:** bundle the mock server spec and update breaking-change detection ([8752d02](https://github.com/anthropics/anthropic-sdk-typescript/commit/8752d0242274ddec2228fdb6d99a0c5a8885e6d7)) +* **internal:** codegen related update ([a63afbc](https://github.com/anthropics/anthropic-sdk-typescript/commit/a63afbc47d527d449ab7ae2a68ae49c05cb8e6df)) +* **tests:** reword the skip reason on the path-level query param tests ([999bee5](https://github.com/anthropics/anthropic-sdk-typescript/commit/999bee5bb813bf3857cfada85a6ec89cfb2daa26)) + + +### Documentation + +* **api:** update a few doc strings ([2ef3d59](https://github.com/anthropics/anthropic-sdk-typescript/commit/2ef3d59b81d59d9b12468650a4151b61d8535387)) + ## 0.123.0 (2026-09-01) Full Changelog: [sdk-v0.122.0...sdk-v0.123.0](https://github.com/anthropics/anthropic-sdk-typescript/compare/sdk-v0.122.0...sdk-v0.123.0) diff --git a/content/github/anthropic-sdk-typescript/api.md b/content/github/anthropic-sdk-typescript/api.md index dc4207c2f..d72534de3 100644 --- a/content/github/anthropic-sdk-typescript/api.md +++ b/content/github/anthropic-sdk-typescript/api.md @@ -282,11 +282,11 @@ Types: Methods: - client.messages.batches.create({ ...params }) -> MessageBatch -- client.messages.batches.retrieve(messageBatchID) -> MessageBatch +- client.messages.batches.retrieve(messageBatchID, { ...params }) -> MessageBatch - client.messages.batches.list({ ...params }) -> MessageBatchesPage -- client.messages.batches.delete(messageBatchID) -> DeletedMessageBatch -- client.messages.batches.cancel(messageBatchID) -> MessageBatch -- client.messages.batches.results(messageBatchID) -> MessageBatchIndividualResponse +- client.messages.batches.delete(messageBatchID, { ...params }) -> DeletedMessageBatch +- client.messages.batches.cancel(messageBatchID, { ...params }) -> MessageBatch +- client.messages.batches.results(messageBatchID, { ...params }) -> MessageBatchIndividualResponse # Models @@ -315,9 +315,9 @@ Types: Methods: - client.files.list({ ...params }) -> FileMetadataPageCursor -- client.files.delete(fileID) -> DeletedFile -- client.files.download(fileID) -> Response -- client.files.retrieveMetadata(fileID) -> FileMetadata +- client.files.delete(fileID, { ...params }) -> DeletedFile +- client.files.download(fileID, { ...params }) -> Response +- client.files.retrieveMetadata(fileID, { ...params }) -> FileMetadata - client.files.upload({ ...params }) -> FileMetadata # Skills @@ -331,9 +331,9 @@ Types: Methods: - client.skills.create({ ...params }) -> Skill -- client.skills.retrieve(skillID) -> Skill +- client.skills.retrieve(skillID, { ...params }) -> Skill - client.skills.list({ ...params }) -> SkillsPageCursor -- client.skills.delete(skillID) -> DeletedSkill +- client.skills.delete(skillID, { ...params }) -> DeletedSkill ## Versions @@ -1642,10 +1642,12 @@ Methods: Types: - BetaComplianceSettings +- BetaComplianceSettingsState - BetaComplianceSettingsStateDisabled - BetaComplianceSettingsStateDisabledParam - BetaComplianceSettingsStateEnabled - BetaComplianceSettingsStateEnabledParam +- BetaComplianceSettingsStateParam Methods: diff --git a/content/github/anthropic-sdk-typescript/helpers.md b/content/github/anthropic-sdk-typescript/helpers.md index e02f5501c..2e75b8c43 100644 --- a/content/github/anthropic-sdk-typescript/helpers.md +++ b/content/github/anthropic-sdk-typescript/helpers.md @@ -666,6 +666,6 @@ for await (const work of client.beta.environments.work.poller({ } ``` -The toolset executes shell and file operations directly on the host. Run it inside a container or other isolation boundary you control. +The toolset executes shell and file operations directly on the host. Run it inside a container or other isolation boundary you control. Files and directories that `write`/`edit` create are owner-only (`0o600`/`0o700`) whatever the process umask, so other local users can't read what an agent wrote; a file that already exists keeps its mode when it is rewritten. See [`examples/managed-agents-self-hosted-sandbox-worker.ts`](examples/managed-agents-self-hosted-sandbox-worker.ts) for a complete example. diff --git a/content/github/anthropic-sdk-typescript/packages/aws-sdk/CHANGELOG.md b/content/github/anthropic-sdk-typescript/packages/aws-sdk/CHANGELOG.md index 391bdba3b..ea0c4a52f 100644 --- a/content/github/anthropic-sdk-typescript/packages/aws-sdk/CHANGELOG.md +++ b/content/github/anthropic-sdk-typescript/packages/aws-sdk/CHANGELOG.md @@ -1,5 +1,13 @@ # Changelog +## 0.7.0 (2026-09-04) + +Full Changelog: [aws-sdk-v0.6.6...aws-sdk-v0.7.0](https://github.com/anthropics/anthropic-sdk-typescript/compare/aws-sdk-v0.6.6...aws-sdk-v0.7.0) + +### Features + +* **api:** add support for sending a workspace ID on more endpoints ([a11e6f1](https://github.com/anthropics/anthropic-sdk-typescript/commit/a11e6f1d3bb0e12e6369d3611a232a6234e715eb)) + ## 0.6.6 (2026-08-27) Full Changelog: [aws-sdk-v0.6.5...aws-sdk-v0.6.6](https://github.com/anthropics/anthropic-sdk-typescript/compare/aws-sdk-v0.6.5...aws-sdk-v0.6.6) diff --git a/content/github/anthropic-sdk-typescript/packages/bedrock-sdk/CHANGELOG.md b/content/github/anthropic-sdk-typescript/packages/bedrock-sdk/CHANGELOG.md index c056ab6e8..356a40f6e 100644 --- a/content/github/anthropic-sdk-typescript/packages/bedrock-sdk/CHANGELOG.md +++ b/content/github/anthropic-sdk-typescript/packages/bedrock-sdk/CHANGELOG.md @@ -1,5 +1,13 @@ # Changelog +## 0.33.4 (2026-09-04) + +Full Changelog: [bedrock-sdk-v0.33.3...bedrock-sdk-v0.33.4](https://github.com/anthropics/anthropic-sdk-typescript/compare/bedrock-sdk-v0.33.3...bedrock-sdk-v0.33.4) + +### Chores + +* **examples:** refresh platform model IDs ([#376](https://github.com/anthropics/anthropic-sdk-typescript/issues/376)) ([2637d11](https://github.com/anthropics/anthropic-sdk-typescript/commit/2637d1198b41514f563c799bec50759cce604638)) + ## 0.33.3 (2026-08-27) Full Changelog: [bedrock-sdk-v0.33.2...bedrock-sdk-v0.33.3](https://github.com/anthropics/anthropic-sdk-typescript/compare/bedrock-sdk-v0.33.2...bedrock-sdk-v0.33.3) diff --git a/content/github/anthropic-sdk-typescript/packages/bedrock-sdk/README.md b/content/github/anthropic-sdk-typescript/packages/bedrock-sdk/README.md index 99e675262..dc39054f1 100644 --- a/content/github/anthropic-sdk-typescript/packages/bedrock-sdk/README.md +++ b/content/github/anthropic-sdk-typescript/packages/bedrock-sdk/README.md @@ -27,7 +27,7 @@ const client = new AnthropicBedrock(); async function main() { const message = await client.messages.create({ - model: 'anthropic.claude-3-5-sonnet-20241022-v2:0', + model: 'global.anthropic.claude-sonnet-5', messages: [ { role: 'user', diff --git a/content/github/anthropic-sdk-typescript/packages/foundry-sdk/CHANGELOG.md b/content/github/anthropic-sdk-typescript/packages/foundry-sdk/CHANGELOG.md index 2d02044c6..93f3bc197 100644 --- a/content/github/anthropic-sdk-typescript/packages/foundry-sdk/CHANGELOG.md +++ b/content/github/anthropic-sdk-typescript/packages/foundry-sdk/CHANGELOG.md @@ -1,5 +1,13 @@ # Changelog +## 0.4.5 (2026-09-04) + +Full Changelog: [foundry-sdk-v0.4.4...foundry-sdk-v0.4.5](https://github.com/anthropics/anthropic-sdk-typescript/compare/foundry-sdk-v0.4.4...foundry-sdk-v0.4.5) + +### Chores + +* **examples:** refresh platform model IDs ([#376](https://github.com/anthropics/anthropic-sdk-typescript/issues/376)) ([2637d11](https://github.com/anthropics/anthropic-sdk-typescript/commit/2637d1198b41514f563c799bec50759cce604638)) + ## 0.4.4 (2026-08-19) Full Changelog: [foundry-sdk-v0.4.3...foundry-sdk-v0.4.4](https://github.com/anthropics/anthropic-sdk-typescript/compare/foundry-sdk-v0.4.3...foundry-sdk-v0.4.4) diff --git a/content/github/anthropic-sdk-typescript/packages/foundry-sdk/README.md b/content/github/anthropic-sdk-typescript/packages/foundry-sdk/README.md index d46a3b493..69ba6b455 100644 --- a/content/github/anthropic-sdk-typescript/packages/foundry-sdk/README.md +++ b/content/github/anthropic-sdk-typescript/packages/foundry-sdk/README.md @@ -25,7 +25,7 @@ const client = new AnthropicFoundry({ }); const message = await client.messages.create({ - model: 'claude-3-5-sonnet-20241022', + model: 'claude-sonnet-5', max_tokens: 1024, messages: [{ role: 'user', content: 'Hello, Claude!' }], }); @@ -51,7 +51,7 @@ const client = new AnthropicFoundry({ }); const message = await client.messages.create({ - model: 'claude-3-5-sonnet-20241022', + model: 'claude-sonnet-5', max_tokens: 1024, messages: [{ role: 'user', content: 'Hello, Claude!' }], }); @@ -71,7 +71,7 @@ const client = new AnthropicFoundry({ // The SDK will automatically use /deployments/my-claude-deployment/messages const message = await client.messages.create({ - model: 'claude-3-5-sonnet-20241022', + model: 'claude-sonnet-5', max_tokens: 1024, messages: [{ role: 'user', content: 'Hello!' }], }); diff --git a/content/github/anthropic-sdk-typescript/packages/vertex-sdk/CHANGELOG.md b/content/github/anthropic-sdk-typescript/packages/vertex-sdk/CHANGELOG.md index 7fae51795..a0dac9f00 100644 --- a/content/github/anthropic-sdk-typescript/packages/vertex-sdk/CHANGELOG.md +++ b/content/github/anthropic-sdk-typescript/packages/vertex-sdk/CHANGELOG.md @@ -1,5 +1,13 @@ # Changelog +## 0.19.7 (2026-09-04) + +Full Changelog: [vertex-sdk-v0.19.6...vertex-sdk-v0.19.7](https://github.com/anthropics/anthropic-sdk-typescript/compare/vertex-sdk-v0.19.6...vertex-sdk-v0.19.7) + +### Chores + +* **examples:** refresh platform model IDs ([#376](https://github.com/anthropics/anthropic-sdk-typescript/issues/376)) ([2637d11](https://github.com/anthropics/anthropic-sdk-typescript/commit/2637d1198b41514f563c799bec50759cce604638)) + ## 0.19.6 (2026-08-26) Full Changelog: [vertex-sdk-v0.19.5...vertex-sdk-v0.19.6](https://github.com/anthropics/anthropic-sdk-typescript/compare/vertex-sdk-v0.19.5...vertex-sdk-v0.19.6) diff --git a/content/github/anthropic-sdk-typescript/packages/vertex-sdk/README.md b/content/github/anthropic-sdk-typescript/packages/vertex-sdk/README.md index 5d33e6785..dae5d1ce9 100644 --- a/content/github/anthropic-sdk-typescript/packages/vertex-sdk/README.md +++ b/content/github/anthropic-sdk-typescript/packages/vertex-sdk/README.md @@ -30,7 +30,7 @@ async function main() { content: 'Hey Claude!', }, ], - model: 'claude-3-5-sonnet-v2@20241022', + model: 'claude-sonnet-5', max_tokens: 300, }); console.log(JSON.stringify(result, null, 2)); diff --git a/content/github/claude-plugins-official/.claude-plugin/marketplace.json b/content/github/claude-plugins-official/.claude-plugin/marketplace.json index db65c1d1a..0040ba19b 100644 --- a/content/github/claude-plugins-official/.claude-plugin/marketplace.json +++ b/content/github/claude-plugins-official/.claude-plugin/marketplace.json @@ -223,7 +223,7 @@ "url": "https://github.com/amd/skills.git", "path": "skills", "ref": "main", - "sha": "0a8a3e52b3f92f89803164474e08eb359d10547e" + "sha": "e867fa4ae4516f644221cb04dcdf24008a43cb99" }, "strict": false, "skills": [ @@ -324,7 +324,7 @@ "source": { "source": "url", "url": "https://github.com/atlassian/atlassian-mcp-server.git", - "sha": "06403d54c6c06038fa62bbdaf7890301bc7ca71c" + "sha": "d390144793913360bc0987797c1e0e2ff65ecbf5" }, "homepage": "https://github.com/atlassian/atlassian-mcp-server" }, @@ -338,7 +338,7 @@ "source": { "source": "url", "url": "https://github.com/atlassian-labs/twg-plugins.git", - "sha": "aec06850b6d20c3cec1faefd76904a26b107e936" + "sha": "c50dc777c48fff8c96accffa5fa7597fab022db6" }, "homepage": "https://developer.atlassian.com/cloud/twg-cli/" }, @@ -370,7 +370,7 @@ "url": "https://github.com/auth0/agent-skills.git", "path": "plugins/auth0", "ref": "main", - "sha": "c63de496d51a01cb4bf44566f8b19489bc92122e" + "sha": "d33e1b8ca86a1b74a3f457d327a065c49d7e375a" }, "homepage": "https://auth0.com" }, @@ -386,7 +386,7 @@ "url": "https://github.com/aws/agent-toolkit-for-aws.git", "path": "plugins/aws-agents", "ref": "main", - "sha": "08c9f7d4664130f327ca1ba54ff33dd28f0eeb75" + "sha": "10b28af8aa3417eeeac6f1ebb5dd4f470a0c3594" }, "homepage": "https://github.com/aws/agent-toolkit-for-aws" }, @@ -402,7 +402,7 @@ "url": "https://github.com/aws/agent-toolkit-for-aws.git", "path": "plugins/aws-agents-for-devsecops", "ref": "main", - "sha": "b33847dd218c6ceef176cd5efdcfff50560faf7d" + "sha": "08ad220e4e9bbc498821ce9360b3dcdf4813121d" }, "homepage": "https://github.com/aws/agent-toolkit-for-aws" }, @@ -431,7 +431,7 @@ "url": "https://github.com/aws/agent-toolkit-for-aws.git", "path": "plugins/aws-core", "ref": "main", - "sha": "5ef88c21be6326992c5795036ae9455e0ca29996" + "sha": "10b28af8aa3417eeeac6f1ebb5dd4f470a0c3594" }, "homepage": "https://github.com/aws/agent-toolkit-for-aws" }, @@ -447,7 +447,7 @@ "url": "https://github.com/aws/agent-toolkit-for-aws.git", "path": "plugins/aws-data-analytics", "ref": "main", - "sha": "08c9f7d4664130f327ca1ba54ff33dd28f0eeb75" + "sha": "08ad220e4e9bbc498821ce9360b3dcdf4813121d" }, "homepage": "https://github.com/aws/agent-toolkit-for-aws" }, @@ -476,7 +476,7 @@ "url": "https://github.com/awslabs/startups.git", "path": "advisor/plugins/aws-startup-advisor", "ref": "main", - "sha": "3408f10f51785634cf28944e44fc313127884c33" + "sha": "7ad465c4d1761d88eb3ec68e78dfcbdfaa003a85" }, "homepage": "https://github.com/awslabs/startups" }, @@ -503,7 +503,7 @@ "source": { "source": "url", "url": "https://github.com/microsoft/azure-skills.git", - "sha": "ab81bf68abfb0cffd3d7ecf468493c97cd94f6bf" + "sha": "2fe0f02665574305657c6e79a619c6b9554e53dc" }, "homepage": "https://github.com/microsoft/azure-skills" }, @@ -539,7 +539,7 @@ "source": { "source": "url", "url": "https://github.com/base44/skills.git", - "sha": "c13fdbff4310ee7feb6517373de340e951f3f6c8" + "sha": "8641b9467c852b39f6d1ae0108eec6ffe70b204c" }, "homepage": "https://docs.base44.com" }, @@ -569,7 +569,7 @@ "source": { "source": "url", "url": "https://github.com/gemini-cli-extensions/bigquery-data-analytics.git", - "sha": "91c1c6262636e54bcd681798974e76ef1f0ea95c" + "sha": "632c3c3e6a876908b5cd432e8b018f4774f971ce" }, "homepage": "https://github.com/gemini-cli-extensions/bigquery-data-analytics" }, @@ -751,7 +751,7 @@ "source": { "source": "url", "url": "https://github.com/cap-js/mcp-server.git", - "sha": "e7b9bcd77fcfe15db8705da19a1e0a2582f202a1" + "sha": "644bf4a132313cf506b2ae11ac51db9123198af3" }, "homepage": "https://cap.cloud.sap/" }, @@ -946,7 +946,7 @@ "source": { "source": "url", "url": "https://github.com/cloudflare/skills.git", - "sha": "f96bff754e428838818017f75817f0f9428acd48" + "sha": "9177f9a0bafc1ab61a0dae8dca57a8eb4d9f636d" }, "description": "Skills for the Cloudflare developer platform: Workers, Durable Objects, Agents SDK, MCP servers, Wrangler CLI, and web performance.", "category": "deployment", @@ -1030,7 +1030,7 @@ "source": { "source": "url", "url": "https://github.com/CodSpeedHQ/codspeed.git", - "sha": "e5587f43a292de8e07d72907f292dedf81cfd798" + "sha": "6ecb3c0d0599b1acda9ec60d20f3af78e203f748" }, "homepage": "https://codspeed.io" }, @@ -1055,7 +1055,7 @@ "source": { "source": "url", "url": "https://github.com/spotify/confidence-ai-plugins.git", - "sha": "f59de5266f96311bcbe462b4483263c42bb0859e" + "sha": "c8eb4aefefc4e095759ef0e5d1dd7e4e5ae6dae7" }, "homepage": "https://confidence.spotify.com" }, @@ -1189,7 +1189,7 @@ "source": { "source": "url", "url": "https://github.com/dash0hq/dash0-agent-plugin.git", - "sha": "c35bccc63b90f48578af6cd8adc6b48de640abe8" + "sha": "2e2af93006a2cd39693735539cc076026b9a5776" }, "homepage": "https://dash0.com/" }, @@ -1214,7 +1214,7 @@ "source": { "source": "url", "url": "https://github.com/gemini-cli-extensions/data-agent-kit-starter-pack.git", - "sha": "b687ed19582cb6f89ef3075ef1e5df3e2dadbc93" + "sha": "d8d9081c865256f3a28212387c1a3c77a857a32d" }, "homepage": "https://github.com/gemini-cli-extensions/data-agent-kit-starter-pack" }, @@ -1237,7 +1237,7 @@ "url": "https://github.com/awslabs/agent-plugins.git", "path": "plugins/databases-on-aws", "ref": "main", - "sha": "8b13a503746a4ebb0402b936645163224058bde3" + "sha": "026f03dc9a2f217ab96aa61f87f10fe8c09e067d" }, "homepage": "https://github.com/awslabs/agent-plugins" }, @@ -1253,7 +1253,7 @@ "url": "https://github.com/databricks/databricks-agent-skills.git", "path": "plugins/databricks/claude", "ref": "main", - "sha": "f3b3fed8034e2aabda54381ace5d237f956db624" + "sha": "ce0599506bad5dd63dead9ab88c440ebd2d8336c" }, "homepage": "https://developers.databricks.com/" }, @@ -1281,7 +1281,7 @@ "source": { "source": "url", "url": "https://github.com/datahub-project/datahub-skills.git", - "sha": "be5bfaff2b16d623a6c85a8e8f0a98d80f05899d" + "sha": "c6d0ded76eca4c649276e39ab376ad6c66142eb7" }, "homepage": "https://datahub.com" }, @@ -1322,7 +1322,7 @@ "url": "https://github.com/microsoft/Dataverse-skills.git", "path": ".github/plugins/dataverse", "ref": "main", - "sha": "a2bddb8c4c7f9395a771cf6c85ac701dc437a594" + "sha": "001b31e0c78e63a0675078ad599e44c16078cd7f" }, "homepage": "https://github.com/microsoft/Dataverse-skills" }, @@ -1337,7 +1337,7 @@ "source": { "source": "url", "url": "https://github.com/confident-ai/deepeval.git", - "sha": "97cd53790d4c46d5b47b25e1b3fadd6bf8630a72" + "sha": "c144abbce848a6dfbd35bbdaaab49a62bb3fb7b6" }, "homepage": "https://github.com/confident-ai/deepeval" }, @@ -1468,7 +1468,7 @@ "url": "https://github.com/expo/skills.git", "path": "plugins/expo", "ref": "main", - "sha": "50f59f837ddb7595d8c6683c693207e265d58c43" + "sha": "80090ccda0ce5973c1354743d1d02602664b15be" }, "homepage": "https://github.com/expo/skills/blob/main/plugins/expo/README.md" }, @@ -1484,7 +1484,7 @@ "source": { "source": "url", "url": "https://github.com/fastly/fastly-agent-toolkit.git", - "sha": "3b54f75784b3a6455ed48e915e5782bcfba369be" + "sha": "42a6070055b2cc08e1f085107685d7eb216b72ed" }, "homepage": "https://github.com/fastly/fastly-agent-toolkit/blob/main/README.md" }, @@ -1534,7 +1534,7 @@ "source": { "source": "url", "url": "https://github.com/firecrawl/firecrawl-claude-plugin.git", - "sha": "e85eddf9df90ae6fe9c729bc816e09151b62619a" + "sha": "b5978f60d8308650821918bf4476fc3b701e88b9" }, "homepage": "https://github.com/firecrawl/firecrawl-claude-plugin.git" }, @@ -1629,7 +1629,7 @@ "source": { "source": "url", "url": "https://github.com/gemini-cli-extensions/google-cloud-storage.git", - "sha": "fec332f39aea5433d00ef6bdefff1a15d75aeebd" + "sha": "db08d0fdb8c133ca0cb82e742d9d54228c4a318b" }, "homepage": "https://cloud.google.com/storage" }, @@ -1734,7 +1734,7 @@ "url": "https://github.com/honeycombio/agent-skill.git", "path": "honeycomb", "ref": "main", - "sha": "0b205aaf668d6200f7a3c332f971d1c2b933c10d" + "sha": "41214b7dfb97f262adabf295fa6f0fcad85bc0f6" }, "homepage": "https://www.honeycomb.io" }, @@ -1771,7 +1771,7 @@ "source": { "source": "url", "url": "https://github.com/huggingface/skills.git", - "sha": "cead19e10754e773bad24fecef83cb64be24094e" + "sha": "97862b0fcc89c850fdd00c82ede1e62d3c930a6d" }, "homepage": "https://github.com/huggingface/skills.git" }, @@ -1785,7 +1785,7 @@ "source": { "source": "url", "url": "https://github.com/hunter-io/claude-plugin.git", - "sha": "1e02bb1f6c354c1403ef702ee0368c176c703203" + "sha": "2a6de2a00f7f459a05c146c6f0712417b8d30db9" }, "homepage": "https://hunter.io" }, @@ -1799,7 +1799,7 @@ "source": { "source": "url", "url": "https://github.com/heygen-com/hyperframes.git", - "sha": "36c7dffe5ca4c7dbf84e876d34ac176ed8770c6d" + "sha": "19ab83f9294485bfe8bce1eab067c7727a335b95" }, "homepage": "https://hyperframes.heygen.com" }, @@ -1869,7 +1869,7 @@ "source": { "source": "url", "url": "https://github.com/jfrog/claude-plugin.git", - "sha": "87169dd683077a810526f12f3f07b6535a78b798" + "sha": "41a8da888c3edaa3123336c077118923cb83ad0b" }, "homepage": "https://jfrog.com" }, @@ -1922,7 +1922,7 @@ "source": { "source": "url", "url": "https://github.com/langfuse/claude-observability-plugin.git", - "sha": "d06829810cce8a8a4f486e0afebd155e95ab9517" + "sha": "169ddfac42a6836f0017f1f8ff1396ff6c67e12f" }, "homepage": "https://langfuse.com/integrations/other/claude-code" }, @@ -2159,7 +2159,7 @@ "source": { "source": "url", "url": "https://github.com/mattpocock/skills.git", - "sha": "5b15a47f2d7150f545fbcacbfe381787fc0230dc" + "sha": "6654f6b60cd9d5be8b54c6fafe44346dabeb3b76" }, "homepage": "https://github.com/mattpocock/skills" }, @@ -2213,7 +2213,7 @@ "url": "https://github.com/mercadopago/mercadopago-claude-marketplace.git", "path": "plugins/mercadopago", "ref": "main", - "sha": "8458eb50658d397bea0d0d511cf96cda3fce383d" + "sha": "c0d06959afc90b2f3d637c35eeb51c36f512c005" }, "homepage": "https://github.com/mercadopago/mercadopago-claude-marketplace/tree/main/plugins/mercadopago" }, @@ -2238,7 +2238,7 @@ "source": { "source": "url", "url": "https://github.com/MicrosoftDocs/mcp.git", - "sha": "f1fbeb32fc51805cc6727707e9f0fea766e3a0b1" + "sha": "bb124f19c9304a33e507d0017f0613f8bda3a16c" }, "homepage": "https://github.com/microsoftdocs/mcp" }, @@ -2254,7 +2254,7 @@ "url": "https://github.com/awslabs/startups.git", "path": "migrate/plugins/migration-to-aws", "ref": "main", - "sha": "0b59caf457ae16afa9f89c1907bcb126d4a0cc1b" + "sha": "f1cc0fb275d45ce053997c7e921b4017f8f40eda" }, "homepage": "https://github.com/awslabs/startups" }, @@ -2295,7 +2295,7 @@ "source": { "source": "url", "url": "https://github.com/GoogleChrome/modern-web-guidance.git", - "sha": "457c381def89ce6213a171238f92eea63e9eaeb2" + "sha": "56c61c9ee79a8df1a98822309c04847a57f56000" }, "homepage": "https://goo.gle/modern-web-guidance" }, @@ -2338,7 +2338,7 @@ "url": "https://github.com/mongodb/agent-skills.git", "path": "plugins/mongodb", "ref": "main", - "sha": "03740fc6092ba0865b88ed37ad58f931f15af0cc" + "sha": "8ada610346e678b8dc9f866e8166092840c6eb2f" }, "homepage": "https://www.mongodb.com/docs/mcp-server/overview/" }, @@ -2354,7 +2354,7 @@ "url": "https://github.com/mongodb/agent-skills.git", "path": "plugins/mongodb-atlas", "ref": "main", - "sha": "03740fc6092ba0865b88ed37ad58f931f15af0cc" + "sha": "8ada610346e678b8dc9f866e8166092840c6eb2f" }, "homepage": "https://www.mongodb.com/docs/mcp-server/get-started/" }, @@ -2367,7 +2367,7 @@ "url": "https://github.com/neondatabase/agent-skills.git", "path": "plugins/neon-postgres", "ref": "main", - "sha": "b7f87949583782238aef20414a29b1f5ca2773ea" + "sha": "4d02514f89ec203ec0f603882f90d468ff8c44f8" }, "homepage": "https://github.com/neondatabase/agent-skills/tree/main/plugins/neon-postgres" }, @@ -2378,7 +2378,7 @@ "source": { "source": "url", "url": "https://github.com/netlify/context-and-tools.git", - "sha": "32a261b6b2437464aca7e51bf9b48bcac1e2835c" + "sha": "ee5dd6e5fa0edf8204b8b5e4937fedac61ffe3bf" }, "homepage": "https://github.com/netlify/context-and-tools" }, @@ -2461,7 +2461,7 @@ "source": { "source": "url", "url": "https://github.com/Nimbleway/agent-skills.git", - "sha": "63bdf759759f10fb16fb37c778538ca9b8684e99" + "sha": "2890fdf94f0adfae79bf05b4de3c91667701bafb" }, "homepage": "https://docs.nimbleway.com/integrations/agent-skills/plugin-installation" }, @@ -2582,7 +2582,7 @@ "url": "https://github.com/growthxai/output.git", "path": "coding_assistants/claude/plugins/outputai", "ref": "main", - "sha": "b3beef161910df053f62710dc190d5a00c4ab3d2" + "sha": "69255d7fd577139a7828bd219637d067b86a42b1" }, "homepage": "https://output.ai" }, @@ -2644,7 +2644,7 @@ "source": { "source": "url", "url": "https://github.com/gopigment/ai-plugins.git", - "sha": "ab8bdde7a1a21358ac9246e4853a0eb07fa3fb5d" + "sha": "ccd2831f48bb9cebb214fff107278129f013bed1" }, "homepage": "https://www.pigment.com" }, @@ -2655,7 +2655,7 @@ "source": { "source": "url", "url": "https://github.com/pinecone-io/pinecone-claude-code-plugin.git", - "sha": "c48ac3f67a9b672654f24a976de60c87ebeb6468" + "sha": "db29e063ce51322e962fe477a7cebaf6729a7eed" }, "homepage": "https://github.com/pinecone-io/pinecone-claude-code-plugin" }, @@ -2669,7 +2669,7 @@ "source": { "source": "url", "url": "https://github.com/pixeltable/pixeltable-skill.git", - "sha": "44292f2dce8c23d2e1432db47d435f809e64c378" + "sha": "31af7bdfdbe3edfa81a6797630bfb5b8bb32ac52" }, "homepage": "https://docs.pixeltable.com" }, @@ -2680,7 +2680,7 @@ "source": { "source": "url", "url": "https://github.com/planetscale/claude-plugin.git", - "sha": "835e6e4c76477384d1321650e20bd0d65ec445a7" + "sha": "95c80f9f391be9b1b6172bf82d4191e1ec11b637" }, "homepage": "https://planetscale.com/" }, @@ -2720,7 +2720,7 @@ "source": { "source": "url", "url": "https://github.com/PostHog/ai-plugin.git", - "sha": "70e8e0a8b4052047f26956e8598d3a2ff0f4db14" + "sha": "19e4737aa8ab3db315e43f35f796976a1ac37787" }, "homepage": "https://posthog.com/docs/model-context-protocol" }, @@ -2730,7 +2730,7 @@ "source": { "source": "url", "url": "https://github.com/gitroomhq/postiz-agent.git", - "sha": "77d09c668cb2f7793989a185844d0a0c3d65c951" + "sha": "6d3be9c0aec768075e91b4a29b04fb624d72d942" }, "homepage": "https://postiz.com/agent" }, @@ -2840,7 +2840,7 @@ "source": { "source": "url", "url": "https://github.com/qdrant/skills.git", - "sha": "825ef626b4e28f766605b47fdd83aeaf73595b55" + "sha": "f90056b7a0c0491d164853eb1e42f952b685fb39" }, "homepage": "https://skills.qdrant.tech" }, @@ -2919,7 +2919,7 @@ "source": "url", "url": "https://github.com/RevenueCat/rc-claude-code-plugin.git", "path": "revenuecat", - "sha": "c84783fba12199bd7f9a2111902c4b1e6a9ddf5b" + "sha": "b9b77b12da33213c9c2e750b06cd6270c1d8ed65" }, "homepage": "https://www.revenuecat.com" }, @@ -2956,7 +2956,7 @@ "source": { "source": "url", "url": "https://github.com/Digital-Process-Tools/claude-remember.git", - "sha": "a50eee6461b3e99c29b18935d2980c283891e0f2" + "sha": "86fbfccfd0648bb06046753b5358d266374ad69f" }, "homepage": "https://github.com/Digital-Process-Tools/claude-remember" }, @@ -2984,7 +2984,7 @@ "source": { "source": "url", "url": "https://github.com/resend/resend-skills.git", - "sha": "2a69b9f39a16c043cbfad45fbfa3c141bd27b050" + "sha": "106dc3435c2bfbd7200d639e9ef6d676d03fcf0b" }, "homepage": "https://resend.com" }, @@ -2996,7 +2996,7 @@ "source": "url", "url": "https://github.com/RevenueCat/rc-claude-code-plugin.git", "path": "revenuecat", - "sha": "c84783fba12199bd7f9a2111902c4b1e6a9ddf5b" + "sha": "b9b77b12da33213c9c2e750b06cd6270c1d8ed65" }, "homepage": "https://www.revenuecat.com" }, @@ -3010,7 +3010,7 @@ "source": { "source": "url", "url": "https://github.com/rilldata/agent-skills.git", - "sha": "84f7d7c29fffe188e588d9e99e1f5245076671d5" + "sha": "e58a668dcd48a6cd6fc6d5f552ba8cd59cdfeaa1" }, "homepage": "https://docs.rilldata.com/developers/build/ai-configuration" }, @@ -3111,7 +3111,7 @@ "url": "https://github.com/forcedotcom/sf-skills.git", "path": "plugins/builder/salesforce-development", "ref": "main", - "sha": "0ca2b41c65ffaf6ae066f2d905a33e86fedac8b0" + "sha": "1a4db263678b5fe740d876e72d1b0ecec724d2f0" }, "homepage": "https://github.com/forcedotcom/sf-skills/tree/main/plugins/builder/salesforce-development" }, @@ -3769,7 +3769,7 @@ "source": { "source": "url", "url": "https://github.com/Unity-Technologies/unity-agent-plugin.git", - "sha": "7044d9317afe00777140beb2350a1330edc73d69" + "sha": "1aefde12b046a37b735a856d228eb6d427e3d31e" }, "homepage": "https://unity.com" }, @@ -3984,7 +3984,7 @@ "source": { "source": "url", "url": "https://github.com/Zoominfo/zoominfo-mcp-plugin.git", - "sha": "3ec997a1ffaaa8d5d98d81b6b9d8c3fdafab6420" + "sha": "d07402feb2b9967ccc118f55bacd41a79c822d6a" }, "homepage": "https://www.zoominfo.com" }, diff --git a/content/support/10310342-how-do-i-log-out-of-all-active-sessions.md b/content/support/10310342-how-do-i-log-out-of-all-active-sessions.md index 256274cf2..e476685ed 100644 --- a/content/support/10310342-how-do-i-log-out-of-all-active-sessions.md +++ b/content/support/10310342-how-do-i-log-out-of-all-active-sessions.md @@ -38,7 +38,7 @@ To regain access to your account on any device, you'll need to authenticate agai If you used your Claude account to authenticate into Claude Code, you can manage your authorization tokens by navigating to **[Settings > Claude Code](https://claude.ai/settings/claude-code)**. To remove a token and log out of Claude Code, click the trash can icon. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1608263923/b4fa7d6f6f08f2adffb4ea63bc58/image+%287%29.png?expires=1788548400&signature=061ae76b53a249c19d56ad492e20e43624628ca807822848cabbca22975fc99c&req=dSYnHst4nohdWvMW1HO4zVuHihT40m%2B%2FAQofdwM8qVexV4RzTBcw2Cx8%2BuDN%0A2jWIcnqgpOBgqS8mOxw%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1608263923/b4fa7d6f6f08f2adffb4ea63bc58/image+%287%29.png?expires=1788586200&signature=da0b7ea9722a019b5fa39debb776fde8e6f828ee59a55906e20c4e1eabee875b&req=dSYnHst4nohdWvMW1HO4zVuHihT43mG5AQofdwM8qVdssFxM0EIZL1dsXH77%0AcpTq0dac%2BE53kabOCOY%3D%0A) ## Unable to access your account? diff --git a/content/support/10366376-how-can-i-delete-my-claude-console-account.md b/content/support/10366376-how-can-i-delete-my-claude-console-account.md index 72b60cf0f..fba1740f7 100644 --- a/content/support/10366376-how-can-i-delete-my-claude-console-account.md +++ b/content/support/10366376-how-can-i-delete-my-claude-console-account.md @@ -36,7 +36,7 @@ If you followed the steps above to delete your Console organization but want to If you have an outstanding balance, you will see a message during the deletion flow that prompts you to pay the balance first by routing you to [Settings > Billing](https://platform.claude.com/settings/billing). -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1973957766/5c2dd87c0818a0400099a833c9b3/4cc3130a-f696-4967-9fe3-e5623c6f02bd?expires=1788548400&signature=13e3346c917244d30a434e7fe001f43c69ec1a8bf0c70734a2bfbcb1f5209006&req=dSkgFcB7moZZX%2FMW1HO4zbYXUB9nWOwfFZRyvJPpBZ991YLid58xOoZq33gz%0AyaCRJ9SCnUYxTDtUS%2B8%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1973957766/5c2dd87c0818a0400099a833c9b3/4cc3130a-f696-4967-9fe3-e5623c6f02bd?expires=1788586200&signature=b7a088ab932998b1016a9f2e8157d2838c257a78a036bec50a4e60f02a6f0333&req=dSkgFcB7moZZX%2FMW1HO4zbYXUB9nVOIZFZRyvJPpBZ9xs4wCS0cndgRL5IFB%0Aa0DdAyPRkOoIiMPRKUc%3D%0A) You must pay this outstanding balance before you’re able to move forward with the deletion process. @@ -44,6 +44,6 @@ You must pay this outstanding balance before you’re able to move forward with There are some scenarios where you will need to contact our team to delete your account. If this is the case, it will be noted when you try to delete your organization: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1973957765/19dda72a40db95d78c00c27a1a1c/6ce89be6-93ce-409c-bbea-d34be09db348?expires=1788548400&signature=24f78fffdb59ee7c231235621f7f8861fdcee91501cb141e7f2b0a4f88571b87&req=dSkgFcB7moZZXPMW1HO4zRW12%2B3IfKz9ZxDZGlqR6Gir8MflL4ynIRMS24nR%0AxcqQp0vC30%2BttnKlUUw%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1973957765/19dda72a40db95d78c00c27a1a1c/6ce89be6-93ce-409c-bbea-d34be09db348?expires=1788586200&signature=e59d69a7c5d91b671f0b356cdab4da7acbcee50709a99db92d320d12c3788424&req=dSkgFcB7moZZXPMW1HO4zRW12%2B3IcKL7ZxDZGlqR6GgZjIEBltQK5ZL%2FBPGd%0AonlzYYeXMf9WaKrSjBU%3D%0A) If you are seeing this message, this indicates that your Console organization cannot be deleted via the self-service pathway. \ No newline at end of file diff --git a/content/support/10504844-manage-user-feedback-settings-on-team-and-enterprise-plans.md b/content/support/10504844-manage-user-feedback-settings-on-team-and-enterprise-plans.md index 8905e4f44..c214e8eea 100644 --- a/content/support/10504844-manage-user-feedback-settings-on-team-and-enterprise-plans.md +++ b/content/support/10504844-manage-user-feedback-settings-on-team-and-enterprise-plans.md @@ -6,6 +6,6 @@ As a Primary Owner or Owner of a Team or Enterprise plan, you can manage the abi 2. Use the toggle to change the **Rate chats** setting for your organization: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2058292603/75752add0bed6a9f3ab217f01708/CleanShot%2B2026-02-12%2Bat%2B08_55_14-402x.png?expires=1788548400&signature=1f29ad14ead0ce3df048d6d42a7e8b46a7a34613421d42c7f01ddf85ac8b73b9&req=diAiHst3n4dfWvMW1HO4zYGm8i8ZFKDI085gFtEpvcR4pyI98aR85rZir%2B50%0AcZ2YP%2BIGMbYPgdR4av0%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2058292603/75752add0bed6a9f3ab217f01708/CleanShot%2B2026-02-12%2Bat%2B08_55_14-402x.png?expires=1788586200&signature=be3f6c18475004a2a274d6201c856fef0f74a46eb9cf2a91abfd5f16e55def34&req=diAiHst3n4dfWvMW1HO4zYGm8i8ZGK7O085gFtEpvcTvKBW%2BiAbmbEak6aMZ%0AuXlqXfd3DKI2LJV9Sk8%3D%0A) More information on how Anthropic collects, uses, and stores feedback data can be found in our Privacy Center: **[How long do you store my organization’s data?](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data)** \ No newline at end of file diff --git a/content/support/10504853-manage-user-feedback-settings-on-claude-console.md b/content/support/10504853-manage-user-feedback-settings-on-claude-console.md index 4a2367e45..903b5a9d2 100644 --- a/content/support/10504853-manage-user-feedback-settings-on-claude-console.md +++ b/content/support/10504853-manage-user-feedback-settings-on-claude-console.md @@ -8,6 +8,6 @@ To manage feedback for your Console organization: 2. Toggle the feedback switch on or off. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1729186182/ebf4032a12a8c56959ca927726ce/Screenshot+2025-09-16+at+12_32_31%E2%80%AFPM.png?expires=1788548400&signature=14d122ff04ef792a7ea9d2cc84ca625e424d597f951c732e40b549d58078d387&req=dSclH8h2m4BXW%2FMW1HO4zVpN5H8YXWBBJ%2FadMup7FQfKtvBTdRqByY56CZPR%0AaSjNV3JrX5m1llx6m2Q%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1729186182/ebf4032a12a8c56959ca927726ce/Screenshot+2025-09-16+at+12_32_31%E2%80%AFPM.png?expires=1788586200&signature=187beb4a59d687663be8ebb6479f2996ae5d4c9b5ae2744a35c346989130137a&req=dSclH8h2m4BXW%2FMW1HO4zVpN5H8YUW5HJ%2FadMup7FQd2VRrJ2M%2FzOJkjwah5%0A0ZNAy14Ewp7VEJD9O3U%3D%0A) More information on how Anthropic collects, uses, and stores feedback data can be found in our Privacy Center: [How long do you store my organization’s data?](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data) \ No newline at end of file diff --git a/content/support/10593882-share-and-unshare-chats.md b/content/support/10593882-share-and-unshare-chats.md index e9347e988..0e6a56f49 100644 --- a/content/support/10593882-share-and-unshare-chats.md +++ b/content/support/10593882-share-and-unshare-chats.md @@ -38,12 +38,12 @@ To unshare a chat: Users on free, Pro, or Max plans can review a log of shared chats by navigating to **[Settings > Privacy](https://claude.ai/settings/data-privacy-controls)**. Find the **Privacy settings** section and click “Manage” next to **Shared chats:** -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1921669913/7cc7be48cfc7a18f9f469d6cd83c/CleanShot+2026-01-08+at+10_20_43%402x.png?expires=1788548400&signature=8c929430ddd19c387436ed2d16cd5246c1231d13ca60a2375a1f730e80fafa91&req=dSklF894lIheWvMW1HO4zWn5HzsYZk1vc9cNIYuX0GEmo1NULB2kpoaZhUkf%0AVSRZm4wJ36r5V%2FWnWkU%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1921669913/7cc7be48cfc7a18f9f469d6cd83c/CleanShot+2026-01-08+at+10_20_43%402x.png?expires=1788586200&signature=0ec26245e222f8fc95c54d286ef9c5b90474193c68951e6361fbb67cb51e2572&req=dSklF894lIheWvMW1HO4zWn5HzsYakNpc9cNIYuX0GHo7SArluD6by0sHkUR%0AfACoX0hnfAlM6qDp9iA%3D%0A) This will open a **Shared chats** modal listing the title, date shared, and link to each chat, allowing you to easily review and access all your previously-shared content. From here, you also have the option to click “Unshare” next to each listed chat to revoke access to the last snapshot you shared: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1624243810/e6fe1d262597446c7fe21dff9f10/AD_4nXdW-GhByF8uKV7fCq9lTbkVB91FglSL6TSyXAOUk_MLcTV9YsEMBMkm9rgm1oXqv0k3sJh1JhlzZP6tHVkKbDJJ71pDRRtM3aVNG64MDuKDIzgmknh-XDZdNa7biTsTdwGoPr5GRg?expires=1788548400&signature=cd4136ac8807ccadbb6c8c121eb7c8306a3dd0ebc00067aef28024ddb6dcdcae&req=dSYlEst6noleWfMW1HO4ze44eC9kkBo6guvTv9woD7bO8GUbSWIRgJFggLZf%0AgZi4w0UnMFW%2F3Zq7Zjw%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1624243810/e6fe1d262597446c7fe21dff9f10/AD_4nXdW-GhByF8uKV7fCq9lTbkVB91FglSL6TSyXAOUk_MLcTV9YsEMBMkm9rgm1oXqv0k3sJh1JhlzZP6tHVkKbDJJ71pDRRtM3aVNG64MDuKDIzgmknh-XDZdNa7biTsTdwGoPr5GRg?expires=1788586200&signature=05a452c2c8ea039c25be5fa1aecb30931f8360a634b8d897a2ea7cbac28a6dca&req=dSYlEst6noleWfMW1HO4ze44eC9knBQ8guvTv9woD7YvJbT17wKvOBsb1SgO%0A7Ohxn57sUzg7mtOb3iQ%3D%0A) If you don’t have any shared chat snapshots, the **Shared chats** modal will show “No shared content found”: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1624243808/b025db8e598f0c88fb16d83d48d5/AD_4nXeUwCKnmFzzrjMHhfr5By4zk5pJlkEn3wbJ8-aNfu13Yl99IjBywpqPx9G07QRzpH1EwRY7uG7Q9m9fib98Gql1cIV7XwUCTzEgBNu79Ey8tCOS5CEVmwveIcEOxJ4fonBhe3g9MA?expires=1788548400&signature=8146ca6dc6b22b1ab1ce0564999cb4e54b3be92a06f5d1f56310c0e6e6a7afc7&req=dSYlEst6nolfUfMW1HO4zdaFnc1xhYG1DeZsm0Gz1HvEPtL4rLT8d4eWTRe0%0AXpII9Vi0FcsDxW8H9kM%3D%0A) \ No newline at end of file +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1624243808/b025db8e598f0c88fb16d83d48d5/AD_4nXeUwCKnmFzzrjMHhfr5By4zk5pJlkEn3wbJ8-aNfu13Yl99IjBywpqPx9G07QRzpH1EwRY7uG7Q9m9fib98Gql1cIV7XwUCTzEgBNu79Ey8tCOS5CEVmwveIcEOxJ4fonBhe3g9MA?expires=1788586200&signature=310ec29ccb08be4d3acff2c11b9233ff64f974c4b4ca9c70ad4110d44b8495e2&req=dSYlEst6nolfUfMW1HO4zdaFnc1xiY%2BzDeZsm0Gz1HudT67dDJzWDomMM1E%2B%0AkHVoRbu40AaMjeSztiY%3D%0A) \ No newline at end of file diff --git a/content/support/10949351-getting-started-with-local-mcp-servers-on-claude-desktop.md b/content/support/10949351-getting-started-with-local-mcp-servers-on-claude-desktop.md index 86bfd65cd..820beb57c 100644 --- a/content/support/10949351-getting-started-with-local-mcp-servers-on-claude-desktop.md +++ b/content/support/10949351-getting-started-with-local-mcp-servers-on-claude-desktop.md @@ -48,7 +48,7 @@ for specific instructions. Custom desktop extensions uploads allow Team and Enterprise plans to leverage organization-specific workflows that aren’t available in the public directory. After creating a custom desktop extension, Owners and Primary Owners can navigate to Settings > Extensions within Claude Desktop and click “Advanced settings” to access the **Extension Developer** section: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1681607607/ba6e379d2769d190f0970a0adaed/AD_4nXd4aZkqjJFpiXMPF28Pih7HmSJ9pPsnoWAfVgiLdFRFiTkO92YtXteIjvDHaPl7T0tjfpRTBOlyrMbQ_aciCNDgfIuEvV3szmKvt72x5O51DMSClXOYWk1JIRIzylwkj3joXqZcLw?expires=1788548400&signature=15596e2ebd728e0d59332852afb4d0dbd8cf7870e82daff8e8aba9bd8f4711b6&req=dSYvF89%2BmodfXvMW1HO4zWbPxEh6MzU2Hn9K2IaIG2Jmng2Zmvn1ZmejZHWi%0ANVeVzK%2FzYN1SQkLiUU0%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1681607607/ba6e379d2769d190f0970a0adaed/AD_4nXd4aZkqjJFpiXMPF28Pih7HmSJ9pPsnoWAfVgiLdFRFiTkO92YtXteIjvDHaPl7T0tjfpRTBOlyrMbQ_aciCNDgfIuEvV3szmKvt72x5O51DMSClXOYWk1JIRIzylwkj3joXqZcLw?expires=1788586200&signature=11249f02819f04931151d7b79faf92412fe6956298cb4914700ee38f3569612e&req=dSYvF89%2BmodfXvMW1HO4zWbPxEh6PzswHn9K2IaIG2JvbLnkPOEW9Q9E006y%0AwF%2BbIiQqTW9%2FvyLz06M%3D%0A) Click “Install Extension…” and select the .mcpb file. Follow the prompts to install and configure your custom desktop extension. For more in-depth information, please refer to our [desktop extension developer documentation](https://github.com/anthropics/mcpb). diff --git a/content/support/11101966-use-voice-mode.md b/content/support/11101966-use-voice-mode.md index f362e7d68..37c835e1f 100644 --- a/content/support/11101966-use-voice-mode.md +++ b/content/support/11101966-use-voice-mode.md @@ -24,7 +24,7 @@ Voice mode transforms how you interact with Claude by: 2. Tap the sound wave symbol in the lower right corner of the chat window to activate voice mode: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2042358620/1bf2311353615c1c494da1312a17/124b93a8-0a9b-4c84-9d1f-ede6ca3498dd?expires=1788548400&signature=17693edb9c1147dd2061ad4e06b57829fa55b95acb6137f2a6151ec9e71c94b6&req=diAjFMp7lYddWfMW1HO4zZyGrsZ3v18UF6uXnTLMvvCdx3VPx5gxRtQiK90v%0AP80D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2042358620/1bf2311353615c1c494da1312a17/124b93a8-0a9b-4c84-9d1f-ede6ca3498dd?expires=1788586200&signature=091f5aa987751b1bf335e0c0df10cffea33ed5a9bc23bf52110f7e1683508b94&req=diAjFMp7lYddWfMW1HO4zZyGrsZ3s1ESF6uXnTLMvvDLsy7yplQQ4ZddSHMP%0AnOPz%0A) 3. Start talking and see your prompt automatically populate in the chat input. @@ -32,7 +32,7 @@ Voice mode transforms how you interact with Claude by: 5. Claude will remain in voice mode until you click the “Stop” button in the lower right corner of the chat window: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2042352060/162f9e61f7fbeb689201dfc1cac1/6a7fafb2-31df-43be-a43f-0059d735e3c4?expires=1788548400&signature=4344024e4526c6f1c5d52b0ddf940fd794d474e23a0c50c121b35c8a8480a75c&req=diAjFMp7n4FZWfMW1HO4zU6VRfXPTLRtxNdRzYWrfF6V32LZ7tkJkzwE4LYx%0AvTAgr0Jmuin5v1ZvYQA%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2042352060/162f9e61f7fbeb689201dfc1cac1/6a7fafb2-31df-43be-a43f-0059d735e3c4?expires=1788586200&signature=4fb5eb684c64aa5fbe46bccb27f3e98eea0bde6b81b1dbc0873936a43b84d92c&req=diAjFMp7n4FZWfMW1HO4zU6VRfXPQLprxNdRzYWrfF6An5f085KVWZZeoECR%0ABpbqru1FGoChJgCd10Y%3D%0A) ### On mobile (iOS and Android) @@ -40,7 +40,7 @@ Voice mode transforms how you interact with Claude by: 2. Tap the voice mode icon (sound wave symbol next to the microphone icon) in the text input field: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2042359690/68879db64559ecf87991f73ce058/671ff972-9e08-4686-bc04-955dab4b2de3?expires=1788548400&signature=078f60371bf223547757faa997ba65f4d6497c9ba209a7fd5b79056c827cba3f&req=diAjFMp7lIdWWfMW1HO4zQTUIfx%2FlNBKD%2FRXAPlQ7LYdCZXpCeyv0YeANHNB%0AL5dO%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2042359690/68879db64559ecf87991f73ce058/671ff972-9e08-4686-bc04-955dab4b2de3?expires=1788586200&signature=885d8aaee7e675b286724041cefefc4904696406d94f7b721f1725795b2e6ad0&req=diAjFMp7lIdWWfMW1HO4zQTUIfx%2FmN5MD%2FRXAPlQ7LaLRV01e1Amp4XuGLfA%0AjXQI%0A) 3. Choose a voice to personalize your experience. @@ -78,7 +78,7 @@ To change the voice later: - **On mobile:** Click the settings button in the bottom left corner while chatting with Claude in voice mode, then tap your preferred voice and pace: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2042352063/25eca25bcfd573ecab30dd53158c/074454a6-fa5a-4c49-8b19-02d434b4ca50?expires=1788548400&signature=91c9aadef6e1d12a40f125937fe7c317f7ab106b1b9308aadba0bcb91ab51a24&req=diAjFMp7n4FZWvMW1HO4zZ3%2FGGKQZFgOy8OQfYsvK3y%2F2E7hYBb23KIHbZd%2F%0AtDz4Ijc20pKPmTAm0W4%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2042352063/25eca25bcfd573ecab30dd53158c/074454a6-fa5a-4c49-8b19-02d434b4ca50?expires=1788586200&signature=55392ba9882f53f8205e4d5fbc0d5a80845749f6fabbb12b3880d03fb3a40a7b&req=diAjFMp7n4FZWvMW1HO4zZ3%2FGGKQaFYIy8OQfYsvK3zgbQiCwsw1M1Xqay9%2F%0AGmJ%2BGOSYOgzODOCDZMs%3D%0A) ## Choose a model diff --git a/content/support/11725453-set-up-the-claude-lti-in-canvas-by-instructure.md b/content/support/11725453-set-up-the-claude-lti-in-canvas-by-instructure.md index 311731ff6..2d663046a 100644 --- a/content/support/11725453-set-up-the-claude-lti-in-canvas-by-instructure.md +++ b/content/support/11725453-set-up-the-claude-lti-in-canvas-by-instructure.md @@ -44,7 +44,7 @@ This article provides information on how to enable the Claude LTI integration in 5. Click "Install" and refresh the course page. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1611422430/c8e0875feac1f2c7cb033be74fc9/AD_4nXfLU_bui3EXcCjQ0qm70HD97neqjGayKeDer_t76utlci8gZSUjYRhw6ZSOlDdqSEcwXBzd_shAh7pQEJ-8OoE0O21DM5coOgxmO_WD5hlwiuwtS2iYXcTavhIRyQT5zKFWvfn3NA?expires=1788548400&signature=9fa0e1570f039be1040ae5fdafc555d696b87695e8f4e5b37c4ff65674fbd693&req=dSYmF818n4VcWfMW1HO4zTEDauMbn%2FuFEv2ojHLMylb3at5%2BtNFEji1u2Om%2F%0AwTrXyc4XzWk2yW%2FmNYQ%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1611422430/c8e0875feac1f2c7cb033be74fc9/AD_4nXfLU_bui3EXcCjQ0qm70HD97neqjGayKeDer_t76utlci8gZSUjYRhw6ZSOlDdqSEcwXBzd_shAh7pQEJ-8OoE0O21DM5coOgxmO_WD5hlwiuwtS2iYXcTavhIRyQT5zKFWvfn3NA?expires=1788586200&signature=7b892ef5c2abf138bce27f3060de5dcfa4220e16c31ed2087147f7487ea0573e&req=dSYmF818n4VcWfMW1HO4zTEDauMbk%2FWDEv2ojHLMylaHtz3Yf%2BA0DoUU6Asv%0Ak04xYAsNDnPIx4wmv84%3D%0A) ## Turn on the Claude LTI Integration in Claude for Education organization settings diff --git a/content/support/11817273-use-claude-s-chat-search-and-memory-to-build-on-previous-context.md b/content/support/11817273-use-claude-s-chat-search-and-memory-to-build-on-previous-context.md index badc441e4..769434b3f 100644 --- a/content/support/11817273-use-claude-s-chat-search-and-memory-to-build-on-previous-context.md +++ b/content/support/11817273-use-claude-s-chat-search-and-memory-to-build-on-previous-context.md @@ -40,7 +40,7 @@ When Claude searches your previous chats, you will see this reflected in your cu Yes, navigate to **[Settings > Memory](https://claude.ai/new#settings/customize-memory)** and switch the toggle next to "Search and reference chats" off: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2533482439/4dee2d7b267f865205feefc8f4f3/cb60c334-d1e2-4828-a01d-dfb36bbaa7eb?expires=1788548400&signature=8d979d47335d6b033ce2492f4253d2f7803dbecd0fd14a38d654f213d382664a&req=diUkFc12n4VcUPMW1HO4zY9IRAJpUdlzYNcz5nFaZkH8v%2B3W1QMusT%2BpLhJN%0AWkiOLU%2B%2FgUj5zjPVqDE%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2533482439/4dee2d7b267f865205feefc8f4f3/cb60c334-d1e2-4828-a01d-dfb36bbaa7eb?expires=1788586200&signature=5025ab504cd338a0d3e6d1dec7abaf4e15a4393df1a687a62690af6d1cdec26d&req=diUkFc12n4VcUPMW1HO4zY9IRAJpXdd1YNcz5nFaZkEg1TglZMosm5Sd5YsN%0A%2BxTu%2BkwFOlLUaEvkRqE%3D%0A) ## Can I exclude a specific past chat from searches? @@ -84,7 +84,7 @@ What Claude remembers from your chats is available when you hand it a task in Co You can toggle Claude’s memory on by navigating to **[Settings > Memory](https://claude.ai/new#settings/customize-memory)** and turning on **Generate memory from chats**: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2533482441/b5c806a8e3f68bf34c4a70724d38/d30be013-d099-4c93-99d1-23d404792f08?expires=1788548400&signature=80c7f475fee5afd67df5f3ee67f3e37c40b66abebfdd750708ee631b615c4ea5&req=diUkFc12n4VbWPMW1HO4zRlYrpNo5lgoNshWSMEMw9cNLs%2Bdkc2%2BzPpLTWXR%0AX0NmPwIxDe1q0%2BIJznM%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2533482441/b5c806a8e3f68bf34c4a70724d38/d30be013-d099-4c93-99d1-23d404792f08?expires=1788586200&signature=0808df4873f3ab0cd84a03b536f4b6a74ba6587d9bd1a95ee517143246374109&req=diUkFc12n4VbWPMW1HO4zRlYrpNo6lYuNshWSMEMw9d2Zb9ZQoU15xkWgJQx%0AC13KQs0DRhSC2zWPB3Q%3D%0A) If you want to disable Claude’s memory, click the toggle and you'll see two options: @@ -239,7 +239,7 @@ When Claude searches your previous chats, you will see this reflected in your cu Yes, navigate to **[Settings > Capabilities](https://claude.ai/settings/capabilities)** and find the **Preferences** section. Switch the toggle next to “Search and reference chats” off: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1719730889/3fafbf5ecaa0ae31d7d84a66229b/c25536c1-7433-4b94-a5e9-cd5acf97a4fd?expires=1788548400&signature=af1bc4aaede6a1bf65c1b18a2dd79faa7c26e58b9ff6dc465672eeb19121e925&req=dScmH859nYlXUPMW1HO4zRzXH1c1JznGJG68qZhl782%2BD1PHfhBZKO1X1Rkp%0AcQvYG%2FkrTaw1sKARtf0%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1719730889/3fafbf5ecaa0ae31d7d84a66229b/c25536c1-7433-4b94-a5e9-cd5acf97a4fd?expires=1788586200&signature=200cc520f2d7b1236ab97b37f7f8783e5169210d16a832bb45de8881921609c7&req=dScmH859nYlXUPMW1HO4zRzXH1c1KzfAJG68qZhl781MTxE%2BiX9C8OPnDseq%0A7tKmceMLZHQw7MAc1YU%3D%0A) ### Can I exclude a specific past chat from searches? @@ -247,7 +247,7 @@ Incognito chats are available to all Claude users (free, Pro, Max, Team, and Ent When starting a new chat with Claude outside of a project, you'll see a ghost icon in the upper right corner of your screen: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1719730893/9549b21954e0070ceb6b85231fd5/88e59234-6fc2-4229-84fe-733b33efff26?expires=1788548400&signature=324dedae28c82f7e96dc6236bf8513621a34ba75b5f8a0d6d83b7cc3d0d36dac&req=dScmH859nYlWWvMW1HO4za54sKtpOI6%2FXDpzhlKsgjMaAVUsJPPA8ulZ2%2BBw%0A4uUXqc6bW5Yhd5pLa%2BI%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1719730893/9549b21954e0070ceb6b85231fd5/88e59234-6fc2-4229-84fe-733b33efff26?expires=1788586200&signature=45692f8ee0444169a79d359fdbea6c4aa2aede787803d835daed8bfc546455ec&req=dScmH859nYlWWvMW1HO4za54sKtpNIC5XDpzhlKsgjO92Y%2BnH60jZM4759fp%0AbBpf6U%2FDctPf7h0MtGU%3D%0A) Clicking the ghost icon will open an incognito chat, creating a temporary conversation that isn’t saved to your chat history. Claude won’t pull information from incognito chats when searching previous conversations. @@ -279,7 +279,7 @@ Each project has its own separate memory space and dedicated project summary, so You can toggle Claude’s memory on by navigating to **[Settings > Capabilities](https://claude.ai/settings/capabilities)**: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1719730892/62f9f2b68d675a8e33393f06024f/89198978-192f-4c52-915d-5294b16f3fe1?expires=1788548400&signature=fafa8f87a1f33b1dc9f045469cba0375ae35af4922c4a558b7985da37ecb4245&req=dScmH859nYlWW%2FMW1HO4zTD5MMnjc%2BxBBq9N9dRTKYekPOGhAXCvJDjvGgmg%0AJrDLIc138fWvsILCYUA%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1719730892/62f9f2b68d675a8e33393f06024f/89198978-192f-4c52-915d-5294b16f3fe1?expires=1788586200&signature=f0c782bca0efade13f1658acdae59d1a29e8bb0b1f0a3a5d70ce03e35228fb8b&req=dScmH859nYlWW%2FMW1HO4zTD5MMnjf%2BJHBq9N9dRTKYcMNfv2v2pD0g1EFfe6%0AxM7MRJaQK02EHb%2FKNYE%3D%0A) If you want to disable Claude’s memory, click the toggle to see two options: diff --git a/content/support/11818288-why-am-i-being-asked-to-verify-my-payment-method.md b/content/support/11818288-why-am-i-being-asked-to-verify-my-payment-method.md index 1886ec8a9..e9361b6dc 100644 --- a/content/support/11818288-why-am-i-being-asked-to-verify-my-payment-method.md +++ b/content/support/11818288-why-am-i-being-asked-to-verify-my-payment-method.md @@ -2,7 +2,7 @@ If you see the following pop-up when you log in to your Claude account, you’ll need to click the “Verify now” button to verify your payment method: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1631413861/42c3b13d7fc44a11a88ec2b9cd03/AD_4nXeMx8QXpeZZCkfAnVSwx8KZ9n4Vr2rvPdQddyE6ZNxch__F6ZqFs1G4ZmU52Wvb7gRlwRqquTLdw8IQv-gICDyP-MXqiQK_Oe7gX3SKsCKKt2IEpMx4qDeMeeZufMaJfv16XgOH5g?expires=1788548400&signature=c52a778da981137d1c3b48429f67443a0645abca6db47839e9e2384e17677d86&req=dSYkF81%2FnolZWPMW1HO4zf7%2BjEzr7Ij2n6MrEicvimCB3rdHA40ehSncW4Ou%0Aio0GtHWfvR7sRwt2t2o%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1631413861/42c3b13d7fc44a11a88ec2b9cd03/AD_4nXeMx8QXpeZZCkfAnVSwx8KZ9n4Vr2rvPdQddyE6ZNxch__F6ZqFs1G4ZmU52Wvb7gRlwRqquTLdw8IQv-gICDyP-MXqiQK_Oe7gX3SKsCKKt2IEpMx4qDeMeeZufMaJfv16XgOH5g?expires=1788586200&signature=a45c385251c73d74d7d7cad59e7d963b631b5feebec324d8beef5ac6c33d7b67&req=dSYkF81%2FnolZWPMW1HO4zf7%2BjEzr4Ibwn6MrEicvimBRkLbyZD3a9c%2FoCti8%0AmI3JYJzaECEBARzNALM%3D%0A) ## What happens if I click “Remind me later?” diff --git a/content/support/11869629-use-claude-with-android-apps.md b/content/support/11869629-use-claude-with-android-apps.md index 2cf65d4f1..b0c940345 100644 --- a/content/support/11869629-use-claude-with-android-apps.md +++ b/content/support/11869629-use-claude-with-android-apps.md @@ -222,7 +222,7 @@ Permission requirements vary by feature: For features requiring permissions (like location or calendar access), Claude will request permission contextually with clear explanations of why the access is needed. You’ll be prompted to approve the action with three options: Allow once, Always allow, or Don't allow. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1707351614/ccb910e4b87b1e96ad9a11bbd835/b57b2130-d8d6-4499-89f6-6c12de236fd4?expires=1788548400&signature=7b1833225ace49d82b155b5eca8152701487050021d2d8db8e635d1e90bd36ca&req=dScnEcp7nIdeXfMW1HO4zQe5GleK3y3wS5x65TIld%2FA8anLOBARTxNcd9KJv%0A9S4DHhG6dPYowXNVhBI%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1707351614/ccb910e4b87b1e96ad9a11bbd835/b57b2130-d8d6-4499-89f6-6c12de236fd4?expires=1788586200&signature=147c65cca4e4735b54c3d9264bccca840fdaaf98948c87f4e7cba4d0c2bfc879&req=dScnEcp7nIdeXfMW1HO4zQe5GleK0yP2S5x65TIld%2FCjHLYWbdZWFuY02afd%0AScKERQi3K4MqPQzfayM%3D%0A) These permissions can be managed at any time in your device settings by going to Settings > Apps > Claude > Permissions. Click into each permission listed under **Allowed** and **Not allowed** to make changes. You can toggle between “Allow only while using the app” or “Ask every time” to change Claude’s access, or remove permissions by choosing “Don’t allow.” Claude will only request permissions if needed for specific features, and you can always choose to decline while still using other capabilities. diff --git a/content/support/12005970-manage-usage-credits-for-team-and-seat-based-enterprise-plans.md b/content/support/12005970-manage-usage-credits-for-team-and-seat-based-enterprise-plans.md index 942296ed2..83faca3d7 100644 --- a/content/support/12005970-manage-usage-credits-for-team-and-seat-based-enterprise-plans.md +++ b/content/support/12005970-manage-usage-credits-for-team-and-seat-based-enterprise-plans.md @@ -70,7 +70,7 @@ After navigating to **[Organization settings > Usage](https://claude.ai/admin-se The **Usage and spend limits** section will show the current limit (if any) or **Unlimited**. Clicking on "Adjust limit" opens a modal where you can either input an amount and click "Set spend limit," or click "Set to unlimited" to remove the organization-wide monthly spend limit. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2149347604/936ac4eb025d3ef1f00c3b8a26b0/image.png?expires=1788548400&signature=57bb7674635871f7e1a527514e5c924e1f5fb309161b72c9150ff8f5f0f4aaf3&req=diEjH8p6modfXfMW1HO4zQHwg6nSkiai6DwhVVpk1mB3mxCnA0eGyhfgTXTJ%0ARAZn6gxvzmKRyrDoPK8%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2149347604/936ac4eb025d3ef1f00c3b8a26b0/image.png?expires=1788674400&signature=4153821d8f7c915aac3c7a23cd6b2f0a24c4010db8308d66a8c57648764f265c&req=diEjH8p6modfXfMW3nq%2BgZ0oa6u4tYJ%2FFiXDCH3AQtMpjyQTJoODlgO%2B%2FIgG%0AsZ7eWfekFPisloTHeIJc%2F8qD1A0%3D%0A) Changes to your organization’s overall spend limit go into effect immediately. @@ -78,11 +78,11 @@ Changes to your organization’s overall spend limit go into effect immediately. Owners and Primary Owners on **seat-based Enterprise plans only** can set spend limits that apply to all users within a specific seat tier. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2149351600/c5b979c366ac2738f60ea84e85b3/CleanShot+2026-03-10+at+15_37_41%402x.png?expires=1788548400&signature=4542001fee4dff1f38aceca289f88787f306b2a06684acb2064303651ea3e5d9&req=diEjH8p7nIdfWfMW1HO4zYnqMI2RJ3iN0wfO62ivdG8qwNAgEYj3JzAHOBym%0A0aQUh5U9dNamtaK3vpI%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2149351600/c5b979c366ac2738f60ea84e85b3/CleanShot+2026-03-10+at+15_37_41%402x.png?expires=1788674400&signature=ffc3500ef7b173924d4732be3530aa55ca5776f7bd9c0ef3a39614c017d40533&req=diEjH8p7nIdfWfMW3nq%2BgXQY6jiyA4TZU25mRg8qXdp6p9QQdG0ptZdqTXft%0Av%2F3wz8eOou196IL6WJGn0hEMv68%3D%0A) Select the "By group" tab to see **Standard seats** and **Premium seats** groups. Click the "..." icon next to the current limit, then "Edit limit." This opens a modal where you can either select "Set dollar amount" and input an amount, or click "Unlimited" to remove the limit for that seat type. Click "Set limit" to save your changes. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2149362056/44993661ca2db771fe924d0346f6/image.png?expires=1788548400&signature=3d5e948a3c60dfa56e052cfcacf8c5001f319532490f0aa4593629c448a4ade4&req=diEjH8p4n4FaX%2FMW1HO4zRzvvI0OdEVCq7nEDCGq9G6%2FVUWGqmnhiGcF%2FhXe%0AgZ%2FJVwbNqYa0rpAn3rY%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2149362056/44993661ca2db771fe924d0346f6/image.png?expires=1788674400&signature=409cbd51bb6df4ac7508d604a4cfecf574629ff8b36114dd527e90607a265ca9&req=diEjH8p4n4FaX%2FMW3nq%2BgWuniGtZF%2FAfz%2BmaPNyxzzz6E%2FBrDxjMYPljnlhE%0AQ7tMCA%2FMhJOOAKK2skEsXNse3zA%3D%0A) --- @@ -90,11 +90,11 @@ Select the "By group" tab to see **Standard seats** and **Premium seats** groups Owners and Primary Owners can also set individual monthly spend limits for each member by finding **Spend limits by user** and clicking the "..." button next to the user, then "Edit limit." -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2149370853/db66f5cd03683b9cc119d0dcd6b8/image.png?expires=1788548400&signature=c287ddc1e4b8b2824de3a3ef13158d2d5eee17e3b3d67722de64fedc7afb43ae&req=diEjH8p5nYlaWvMW1HO4zaPdGQ9SUSdCe9HwvwG7ubjKr4yWpusXI9sFwiSS%0A%2BZC0qcvO%2FmnMMQ59YdY%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2149370853/db66f5cd03683b9cc119d0dcd6b8/image.png?expires=1788674400&signature=5da401bd63e5308785666580b0bb07667da8751f2d9f87752b5b6fdc58b48889&req=diEjH8p5nYlaWvMW3nq%2BgScIyWhIHAwniST9HHWu%2BKLpv3OaeAccpGKeZ9pz%0AUYFwTm88tj4r%2BOz65Kv9JpY9850%3D%0A) Enter the amount and click "Set limit." Alternatively, selecting "Set to unlimited" will remove that member's monthly spend limit (they will still be subject to any organization or seat-level spend limits). -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2149374028/97813fe3b515c2e839d8d92abd79/image.png?expires=1788548400&signature=8661b24acf2af389d01ed603de964b1ae1e473ed9967a696748ba55d391522d1&req=diEjH8p5mYFdUfMW1HO4zevsAv%2BPN%2BOOw6z2wGSwkbt7Gy2bP9teI0J90SQr%0ANhtjf52tP9ni5Ei9s7c%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2149374028/97813fe3b515c2e839d8d92abd79/image.png?expires=1788674400&signature=9f4884f3f8e1921f470e783819ef8762c96f0c15aaa24d0d9c3bf76647a534c5&req=diEjH8p5mYFdUfMW3nq%2BgbI7Rm54Qs5yIE0R4raDMDQBkfcm0%2FvxfWYYEdu6%0ABcF%2FBKNlJiLqiUuxF38j%2BG3qLuI%3D%0A) This allows owners fine control over usage credits, so you can set limits for different members based on their roles or individual needs. Once a user reaches their defined spend limit, this will automatically pause their usage credits until the end of the month. They will need to wait for their usage limits to reset before using Claude again. @@ -116,7 +116,7 @@ Members of seat-based Enterprise plans will see a "Request usage credits" link u Click this to send a request to organization Admins to either switch you to a Premium seat (if you're currently assigned to a Standard seat) or enable usage credits for your user account. This will change to **Request sent to admin** after clicking it, indicating that you submitted a request for a seat tier increase or usage credits to an organization Admin. -Admins and Owners can review these requests in **[Organization settings > Usage](https://claude.ai/admin-settings/usage)**. Clicking into "Review requests" will open a modal where each requester is listed, along with their current seat, and the time they asked for more usage. Click "Increase limit" next to each request you want to approve. Admins and above will also receive a daily email including all your organization's outstanding requests. +Owners, Primary Owners, and custom roles with the Billing permission set to "Can manage" can review these requests in **[Organization settings > Usage](https://claude.ai/admin-settings/usage)**. Clicking into "Review requests" will open a modal where each requester is listed, along with their current seat, and the time they asked for more usage. Click "Increase limit" next to each request you want to approve. Admins and above will also receive a daily email including all your organization's outstanding requests. ### Disable usage credit requests diff --git a/content/support/12012173-get-started-with-claude-in-chrome.md b/content/support/12012173-get-started-with-claude-in-chrome.md index 9889ba40b..ac8c51a27 100644 --- a/content/support/12012173-get-started-with-claude-in-chrome.md +++ b/content/support/12012173-get-started-with-claude-in-chrome.md @@ -38,7 +38,7 @@ Follow these steps to connect Claude in Chrome in your desktop app: 4. Toggle the connector on, then download and install the extension if you haven’t already. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2604933811/ae37c41fc808dbdf48d135338334/6cc9ba4b-9d31-43a2-ab80-8048b5f9d791?expires=1788548400&signature=489c172eca0f83d6ec91ddf82b78554ae15640b4c8c6e75251bf032abe966784&req=diYnEsB9noleWPMW1HO4zUOPbPTDkuqJnt%2F2nPMwUPgU0JCyIg%2BX1fV7I0xA%0AeRQysifkE0uh68t7AtM%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2604933811/ae37c41fc808dbdf48d135338334/6cc9ba4b-9d31-43a2-ab80-8048b5f9d791?expires=1788586200&signature=4d3192d882ff0a8778cac5242167d546694dc66587c2732dc9ffe7e1a2ddfaa6&req=diYnEsB9noleWPMW1HO4zUOPbPTDnuSPnt%2F2nPMwUPjwolJQYrMy0QFkRVkk%0A8hpyzK03NDa%2BGZQbLmE%3D%0A) Completing these steps will add Claude in Chrome to the “Connectors” drop-down on your chats with Claude. This is disabled by default, so you’ll need to enable it manually for each conversation. diff --git a/content/support/12083917-change-your-team-plan-from-monthly-to-annual-billing.md b/content/support/12083917-change-your-team-plan-from-monthly-to-annual-billing.md index 7398999e6..252872f04 100644 --- a/content/support/12083917-change-your-team-plan-from-monthly-to-annual-billing.md +++ b/content/support/12083917-change-your-team-plan-from-monthly-to-annual-billing.md @@ -8,11 +8,11 @@ Owners and Primary Owners of Team plans with monthly subscriptions can switch fr 3. Or from /upgrade, click the “Switch to Annual plan” button: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1690325734/d47f714680d78408d6022d06b8d1/image.png?expires=1788642000&signature=b4b16b96b8f6f23912363be849904cf5c254f1c9d7c0bc8dda6c9ec2e8191230&req=dSYuFsp8mIZcXfMW3Hu4gZzas%2FXtsTlWn2rRiVwqPzaNMaG%2FsSMKYdTea5Fg%0A5g%3D%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1690325734/d47f714680d78408d6022d06b8d1/image.png?expires=1788696000&signature=2c0f96d5b8ef6e3bde2437d51ddf668fa761505f40a09c670322da73d212254e&req=dSYuFsp8mIZcXfMW3Hu4gZzas%2FXtsTlbm2rRiVwqPzaQDg859eWz5QVhMXP4%0Azw%3D%3D%0A) 4. The confirmation screen will display the total cost for your upgrade from monthly to annual billing: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1690326039/3a91cdc5fff57d188a18ecc6273f/image.png?expires=1788642000&signature=2250cedc586c61bd504ff22b91cc0bee0e624518f78b2e53daae3657b8139d39&req=dSYuFsp8m4FcUPMW3Hu4gbNj%2Bk78VAvlie5vzcg6znXzZ8Rk7wvIdt8Ntwc3%0AmQ%3D%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1690326039/3a91cdc5fff57d188a18ecc6273f/image.png?expires=1788696000&signature=1d81a1b197caa0fc6826a99b814c7aa3013d51f3f8d2055d4f2dca72ade2de17&req=dSYuFsp8m4FcUPMW3Hu4gbNj%2Bk78VAvoje5vzcg6znWDrms9Lc4BAPf6Srj%2B%0Acw%3D%3D%0A) 5. Click “Confirm subscription.” diff --git a/content/support/12111783-create-and-edit-files-with-claude.md b/content/support/12111783-create-and-edit-files-with-claude.md index ddaa1b0d8..66ba0a51f 100644 --- a/content/support/12111783-create-and-edit-files-with-claude.md +++ b/content/support/12111783-create-and-edit-files-with-claude.md @@ -48,7 +48,7 @@ These capabilities make it easy to produce professional documents by simply chat To give Claude access to external data sources, toggle **Allow network egress** on: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2054774005/25bcfffba6c249cd128d6c3f6d52/CleanShot+2026-02-11+at+16_34_47%402x.png?expires=1788548400&signature=effc75b7350ef9145842df16ba1e2d6389fb8af0cfcd4352ce900d145ea20b00&req=diAiEs55mYFfXPMW1HO4zYFJywVACJHKPQVowIiib2l4mM%2Bvg1sxOe3RKpuU%0AybQReM9Pzseh6B0EOus%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2054774005/25bcfffba6c249cd128d6c3f6d52/CleanShot+2026-02-11+at+16_34_47%402x.png?expires=1788586200&signature=71c894c5bcc14d5f064473b8a947d56734b4f77ed7a546f5165a78c16c532152&req=diAiEs55mYFfXPMW1HO4zYFJywVABJ%2FMPQVowIiib2kGynbLdgRB80holXRZ%0AvNY7D%2BgGBQ%2BzUHN7ExU%3D%0A) ### Enabling on Claude Mobile @@ -66,11 +66,11 @@ Team and Enterprise organization owners can control network access settings in * - **Allow network egress to package managers and specific domains:** Claude can access package managers plus additional domains you specify. Add domains individually to whitelist specific resources your organization needs: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1789945362/ad72504d5429960f369b8b91b43c/86f06c0e-6eaa-4574-a4cb-2c38b273613a?expires=1788548400&signature=0dcf65b57f9d0dfcc36b49ae136a8521a4484e1ac27bc377f8c9ca9ef5e24fef&req=dScvH8B6mIJZW%2FMW1HO4zXJcBmVGkSFPpMW6Iph6YZe1IapGlLhXThoRGEvr%0AMsG1IR5klUjTZvwGDSQ%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1789945362/ad72504d5429960f369b8b91b43c/86f06c0e-6eaa-4574-a4cb-2c38b273613a?expires=1788586200&signature=1323c44e760471baff5f1d81bf4c536e9df4d677c21ab7c2d109e3e300ac4d7e&req=dScvH8B6mIJZW%2FMW1HO4zXJcBmVGnS9JpMW6Iph6YZfX6uFIbWvM7hPm%2BhQ8%0A9Na2fagEu6tFdw%2FRkK0%3D%0A) **All domains:** Claude has full internet access except for domains on Anthropic's legal blocklist. While this provides maximum flexibility for file creation and analysis tasks, it’s also the riskiest option. Please review the **[security considerations below](#h_0ee9d698a1)** before enabling “All domains”: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1789945361/e3188cb8edb9ca7c303615da6378/f1c99a7d-5956-48d5-9ec7-b7ae6c8c3d28?expires=1788548400&signature=d0804d22680c66351df09d39da7a917370b9c77b1985ed9ac3a24c2572a47a5d&req=dScvH8B6mIJZWPMW1HO4zdnseByX6jemqgKIA6CM1tos4EGSKdUYiTzqQeQb%0AHl%2FWmJoQQDG1ueMG5LM%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1789945361/e3188cb8edb9ca7c303615da6378/f1c99a7d-5956-48d5-9ec7-b7ae6c8c3d28?expires=1788586200&signature=3c535ebcf2702a5182ed7b9d5adae94f0e188127a542f11b21382f7d64c88bb1&req=dScvH8B6mIJZWPMW1HO4zdnseByX5jmgqgKIA6CM1tpi9E9kVX8mvucLhrbH%0AyP4AUOB595UGm3abjhU%3D%0A) --- diff --git a/content/support/12157520-claude-code-usage-analytics.md b/content/support/12157520-claude-code-usage-analytics.md index b7e8bbb63..e5ab164be 100644 --- a/content/support/12157520-claude-code-usage-analytics.md +++ b/content/support/12157520-claude-code-usage-analytics.md @@ -50,7 +50,7 @@ The **Usage** tab displays the following metrics for your organization. Data on - **Top commands**: The Claude Code commands used most often across your organization. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1717579277/46c512f4b3ed05c359cecd78ed5c/e0ce2c19-39e2-411f-9a1f-cb1d46439a42?expires=1788548400&signature=e82078aa157b998f86ac97a0e3ad82b5812bf69040da813dd48dca914543ea47&req=dScmEcx5lINYXvMW1HO4zfiEP65Vi3HKCX9h5MbdDjPQlFwKll3%2BTTskiR2D%0AoCeA01%2Bzq1uHkHvN1os%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1717579277/46c512f4b3ed05c359cecd78ed5c/e0ce2c19-39e2-411f-9a1f-cb1d46439a42?expires=1788586200&signature=a2adfd392d43b8cb9fab330eb2a0c09a34236bc0def0feaff7a93a354cd37951&req=dScmEcx5lINYXvMW1HO4zfiEP65Vh3%2FMCX9h5MbdDjMmwnLV875K2ByqNXIS%0AML33L0UJOOWwLRRnIzM%3D%0A) ### User-level metrics diff --git a/content/support/12260368-use-incognito-chats.md b/content/support/12260368-use-incognito-chats.md index c3270b835..bbebd650b 100644 --- a/content/support/12260368-use-incognito-chats.md +++ b/content/support/12260368-use-incognito-chats.md @@ -30,7 +30,7 @@ Incognito chats are temporary conversations that aren't saved to your chat histo When starting a new chat with Claude outside of a project, you'll see a ghost icon in the upper right corner of your screen: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1719768744/c7a2fa56cf284e48472f3b9c4dbf/030563f8-9f97-4891-a749-9ae95968a063?expires=1788548400&signature=595f035b0481607a2c94e128ea2ba97700a4ab7f26b3dc127006aea1647e9765&req=dScmH854lYZbXfMW1HO4zeUcuwq4au2PDCAt3Cx%2FSO3IJ73JGJZlp6JBLqQz%0ADIl%2BkcYjyLRoxIMKtY4%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1719768744/c7a2fa56cf284e48472f3b9c4dbf/030563f8-9f97-4891-a749-9ae95968a063?expires=1788586200&signature=77763c6cb0c3973d986e064f8e47170c9ec9100daa6963a6e0c35c1aec021e02&req=dScmH854lYZbXfMW1HO4zeUcuwq4ZuOJDCAt3Cx%2FSO0%2F4IqmJBXaafNAFbGU%0Ay97ZqHIXGNCbaPGfiuo%3D%0A) 1. Click the ghost icon to enable incognito mode. diff --git a/content/support/12293051-use-claude-in-xcode.md b/content/support/12293051-use-claude-in-xcode.md index ff101b27d..1c5609ce6 100644 --- a/content/support/12293051-use-claude-in-xcode.md +++ b/content/support/12293051-use-claude-in-xcode.md @@ -34,7 +34,7 @@ To start using Claude in Xcode: 3. Log in with your Claude account. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1727371585/b18ca03a6357c52d12d10386f28e/dab2dcb2-f670-4173-b77d-38767a34cec1?expires=1788548400&signature=463f1245d1f61f36cada3f3c7a166a2a033e6c08a5f6c86d3afe1c6f27d42610&req=dSclEcp5nIRXXPMW1HO4zUAXI8QHVqDQFalhp3bugHJTiQzwnpxWiMGqAG6l%0Afhfc%2BuusE2eBZTeIbVs%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1727371585/b18ca03a6357c52d12d10386f28e/dab2dcb2-f670-4173-b77d-38767a34cec1?expires=1788586200&signature=24b1da3764581a9bca8200bf410c1ef6d8dde68f0c3ab7418dea0e74385eb6f8&req=dSclEcp5nIRXXPMW1HO4zUAXI8QHWq7WFalhp3bugHL0mYQ77n3BrWxrBM03%0AtDDWMnNPCQ1dy9UqBnw%3D%0A) ## Usage limits diff --git a/content/support/12429409-manage-usage-credits-for-paid-claude-plans.md b/content/support/12429409-manage-usage-credits-for-paid-claude-plans.md index 8b58be281..fa8b17e14 100644 --- a/content/support/12429409-manage-usage-credits-for-paid-claude-plans.md +++ b/content/support/12429409-manage-usage-credits-for-paid-claude-plans.md @@ -46,7 +46,7 @@ To enable usage credits on your paid Claude plan: 8. You can also enable auto-reload to automatically make a purchase when your balance falls below a threshold you set: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1805819785/5e203c38e6ba3f76bfd1dab0d5ce/fe062e7c-18cb-48cc-a7e2-754ac6e6c4be?expires=1788548400&signature=6fbce16f2d21e3a3ad5232a4924bc237638eb1cd7ad9944fcd8b0146a7587be0&req=dSgnE8F%2FlIZXXPMW1HO4zYj2ARqcofg8opE7m38YdffZ%2FjCS7sWJdK7VZUR8%0A6%2FDsh6ZiyLwZ5VGN%2B6E%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1805819785/5e203c38e6ba3f76bfd1dab0d5ce/fe062e7c-18cb-48cc-a7e2-754ac6e6c4be?expires=1788586200&signature=1fa86038ec1de89bd4d4e49bf8491cc121da288237864456c5ab02ee28cd81ba&req=dSgnE8F%2FlIZXXPMW1HO4zYj2ARqcrfY6opE7m38Ydfe9eAJ4olSJLwBq23jK%0Amz1yaeg7J3PNMiBHBlY%3D%0A) **Note:** There is a daily redemption limit of $2000. diff --git a/content/support/12466728-troubleshoot-claude-error-messages.md b/content/support/12466728-troubleshoot-claude-error-messages.md index 1d2f59955..02c20515c 100644 --- a/content/support/12466728-troubleshoot-claude-error-messages.md +++ b/content/support/12466728-troubleshoot-claude-error-messages.md @@ -58,4 +58,4 @@ Capacity issues will not appear on our status page because they represent normal Service incidents are disruptions where Claude is unavailable or significantly degraded for all or most users. These represent actual technical problems with our systems. To check for confirmed incidents, visit status.claude.com, where you'll find real-time updates on scope, impact, and resolution progress for any active incidents. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1753796247/e6a8c6ef8653b229c5758e881242/c2fc6fc0-d163-4119-93e0-394104d86bc9?expires=1788548400&signature=c1a755f0c19d0ca2f6f6c0a63679b023618be91dfb10851715d03bc9bed87dfe&req=dSciFc53m4NbXvMW1HO4za4BXqcm1rrA7y68oYp%2BYg%2BQTfab8qLJ8IRjV%2Fgr%0A63JmXlqPXf5eu35KzBs%3D%0A) \ No newline at end of file +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1753796247/e6a8c6ef8653b229c5758e881242/c2fc6fc0-d163-4119-93e0-394104d86bc9?expires=1788586200&signature=028747c07a80455b792d74888b489111eb66d4d95465bbd3c1f111bcfaa0c9b5&req=dSciFc53m4NbXvMW1HO4za4BXqcm2rTG7y68oYp%2BYg9ku7u5uZ88ogbOIoHE%0AVbVYNJL9sE9bZUCL%2FNE%3D%0A) \ No newline at end of file diff --git a/content/support/12592343-enabling-and-using-the-desktop-extension-allowlist.md b/content/support/12592343-enabling-and-using-the-desktop-extension-allowlist.md index ee582a3db..820399728 100644 --- a/content/support/12592343-enabling-and-using-the-desktop-extension-allowlist.md +++ b/content/support/12592343-enabling-and-using-the-desktop-extension-allowlist.md @@ -20,11 +20,11 @@ The desktop extension allowlist is disabled by default, so an organization Owner 4. Switch to the "Desktop" tab: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1781755172/63c92550571842577ad435860ec5/6f5cc4e1-ff7d-48de-863a-c4e6184d4605?expires=1788548400&signature=fb3036a82faa7240e10aaa72ef7f0d27fbcfe1f98443b507eae8eab311310e12&req=dScvF857mIBYW%2FMW1HO4zQ9pXUIP%2B3jf0ugSQm1MFW%2BlYQhCNNrB6caJp%2FHn%0AEf%2Bo%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1781755172/63c92550571842577ad435860ec5/6f5cc4e1-ff7d-48de-863a-c4e6184d4605?expires=1788586200&signature=00e8801f071c2b579b36506d41e22567fa4b69f2926a337d3a70b6e35e398054&req=dScvF857mIBYW%2FMW1HO4zQ9pXUIP93bZ0ugSQm1MFW%2FvO%2B6mCGbLqbmD4bg%2F%0AYowB%0A) 5. Toggle **Allowlist** on: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1781755578/a6bafff5f084dc86ae463703fd3d/6cf0ee18-4e71-4129-98e8-cc08174e3c3a?expires=1788548400&signature=d7bf04b12d420eda18b2480fe1e64600406343dc087d0e666bef662ee0f21e68&req=dScvF857mIRYUfMW1HO4zaj0BHkuTa8ATAorLxpdoc%2ByTufS72yi%2BvfPE4Bt%0AsuAu%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1781755578/a6bafff5f084dc86ae463703fd3d/6cf0ee18-4e71-4129-98e8-cc08174e3c3a?expires=1788586200&signature=67c00a3f922730e0bd5f8fcf56f964a5d3affd7fe3660e49b0068526483256fc&req=dScvF857mIRYUfMW1HO4zaj0BHkuQaEGTAorLxpdoc%2Fz126pt8mvfLlbtrvk%0AXfII%0A) ## What happens after enabling the allowlist? @@ -42,7 +42,7 @@ Consider completing the allowlist setup during off-hours to minimize disruption **Important:** The allowlist requires Claude Desktop version 0.13.91 or higher, so users should update the desktop app by clicking “Claude”, then either “Check for updates” or “Restart to update to Claude 0.13.91”: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1781756960/ad18af50c83d35f2673656c23e00/a7ee450f-0c7d-42d6-a75f-fb1bc088cb52?expires=1788548400&signature=f8255f7e2423371fe6dedc2ca2584b73698bc6c598ebe4e87b173f21aad8ef10&req=dScvF857m4hZWfMW1HO4zYUJqYuvDjrvCEDZ5AdBjIZe2LPsXu2h8rngUQ5T%0AApqI3ujQ3XNE%2BJXF4tY%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1781756960/ad18af50c83d35f2673656c23e00/a7ee450f-0c7d-42d6-a75f-fb1bc088cb52?expires=1788586200&signature=75309f76adc94053666d3e3998681df6974ffe4c934fa348e2c17f4d15de9e55&req=dScvF857m4hZWfMW1HO4zYUJqYuvAjTpCEDZ5AdBjIbQ%2BrTLAxYHGTwDSFTB%0Aa8Ff1e9oB%2F83BXfP8Hg%3D%0A) ## Managing allowed extensions @@ -60,7 +60,7 @@ After enabling the allowlist, you can choose which extensions to allow: If you want to remove an extension from the allowlist, click the “...” button and “Remove from allowlist.” -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1781751250/6558c0f59aea7976bd44b0213d76/e750f02b-cd0d-437e-a83f-9ac362cdf456?expires=1788548400&signature=eaa837aec994ecb967cffc7f0a519a2652e55d566bbb04f395e2ddb23b5db8c0&req=dScvF857nINaWfMW1HO4zTrxBaAs%2B1%2BRqXridZhfx1IpAMmkVvG2UyW04Ut8%0ANeEH3ddNf6dYq0CRvwY%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1781751250/6558c0f59aea7976bd44b0213d76/e750f02b-cd0d-437e-a83f-9ac362cdf456?expires=1788586200&signature=4bcc6b1ad1d5d55c36db85714df7c9b2ef14f4c7191b30e191eaa05f73487f6b&req=dScvF857nINaWfMW1HO4zTrxBaAs91GXqXridZhfx1LOXuu1e7hFmTMzbo0N%0Ab%2B2ylpOvsMfqptmbu1I%3D%0A) ## Uploading custom extensions diff --git a/content/support/12618689-claude-code-on-the-web.md b/content/support/12618689-claude-code-on-the-web.md index bf53b9604..92d8c7a83 100644 --- a/content/support/12618689-claude-code-on-the-web.md +++ b/content/support/12618689-claude-code-on-the-web.md @@ -10,7 +10,7 @@ This feature works with repositories you may not have on your local machine. You Claude Code for web enables asynchronous development workflows. With Claude Code in your terminal or editor, you typically work synchronously: you make a request, wait for Claude to respond, review the changes, then make another request. Synchronous work like this gives you fine-grained control but requires your attention throughout the process. Claude Code on the web handles this differently: you can assign a larger task, let Claude work independently, and return later to review the completed work. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1786446157/07ec74cd46317f8278083a317841/6448f3ee-c6df-4417-8a13-90d8c2ca3d55?expires=1788548400&signature=fb1d606b680bc1d5c3f4ad6f6b664f361d08be401bb3269d173321c5b6884e52&req=dScvEM16m4BaXvMW1HO4zR8%2BAFuFRpVy7XrRA1YwWGuJRzdtmSqvTZoJIKvu%0A8xd50jBlFilaYuSnK7A%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1786446157/07ec74cd46317f8278083a317841/6448f3ee-c6df-4417-8a13-90d8c2ca3d55?expires=1788586200&signature=64f2be6b57d3de3ca0449856cc91a4818669a091315a10e9e540bf273838d4e8&req=dScvEM16m4BaXvMW1HO4zR8%2BAFuFSpt07XrRA1YwWGuY6BquuBQK6lQxKV5f%0AK%2FMUb2TaqOn1TgQRkt4%3D%0A) You can also run multiple tasks in parallel. Since each task runs in its own isolated environment, you can have Claude working on several different issues or repositories simultaneously. Each task proceeds independently and creates its own pull request when complete. More than one task can work on the same repository at the same time. @@ -18,13 +18,13 @@ You can also run multiple tasks in parallel. Since each task runs in its own iso When you start a task, Claude Code on the web creates an isolated virtual machine for your work. Your GitHub repository is cloned into this environment, which comes pre-configured with common development tools and language ecosystems. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1786446158/c092f1383826cb871493f74169d4/97b7cb98-5da2-438e-a920-e170b8b9790e?expires=1788548400&signature=823a5a67645b36137720e5411decf1474e04afd2071b08b256b96e88e59a2831&req=dScvEM16m4BaUfMW1HO4zcR0rZ4xi%2BHE7DtpMiX%2FBYmuxwFXL7EwXoOIj3X%2B%0AKdNVbBA%2F5EIZ9RUpViA%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1786446158/c092f1383826cb871493f74169d4/97b7cb98-5da2-438e-a920-e170b8b9790e?expires=1788586200&signature=7cd8ef3440073db67d8ab2f78868ced2a20799cdf017115586086bc8880dcb55&req=dScvEM16m4BaUfMW1HO4zcR0rZ4xh%2B%2FC7DtpMiX%2FBYkDn4JAZtM%2BN%2FVrBP2a%0AHt8QtW4jIbABMywwF2k%3D%0A) Claude prepares the environment by running any setup commands you've defined in your repository's configuration. This includes installing dependencies, setting up databases, or running other initialization steps your project needs. If your task requires network access, maybe to install packages or fetch data, you can configure the level of internet access the environment has. Once the environment is ready, Claude begins working on your task. Claude reads your code, makes changes, writes tests, and runs commands to verify the work. You can monitor progress and provide guidance through the web interface if needed. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1786446156/83ecf0a5b98eddc9ffc9694c50f7/353589ce-b678-441d-8909-71b45fa2d065?expires=1788548400&signature=5b8b5b6324c8d2d422bb0a8e74063108a9b50a436d6d3f2b149b1f594c093b0d&req=dScvEM16m4BaX%2FMW1HO4zVbcTGuG58zKUQl3YqgIJdb9wPbeFzT5%2FpBZRgvD%0A4ttFgqOsd0RdpyiKfUM%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1786446156/83ecf0a5b98eddc9ffc9694c50f7/353589ce-b678-441d-8909-71b45fa2d065?expires=1788586200&signature=c3fba4b5f4e246c267d6bd278b6d8aff9ffb6f9208dac62b65801d09ed4859f9&req=dScvEM16m4BaX%2FMW1HO4zVbcTGuG68LMUQl3YqgIJda0gDKZipr2Y92BhRlJ%0AMNWWW9EA6w8pW1lmCmY%3D%0A) When Claude completes the task, it pushes the changes to a new branch in your GitHub repository. You receive a notification and can review the changes, then create a pull request directly from the interface. The pull request includes all of Claude's work, ready for your review and any additional changes you want to make. diff --git a/content/support/12626668-use-quick-entry-with-claude-desktop-on-mac.md b/content/support/12626668-use-quick-entry-with-claude-desktop-on-mac.md index 19695d6a1..5a5065eb4 100644 --- a/content/support/12626668-use-quick-entry-with-claude-desktop-on-mac.md +++ b/content/support/12626668-use-quick-entry-with-claude-desktop-on-mac.md @@ -40,7 +40,7 @@ When you first open the updated version of Claude Desktop, you'll see a prompt t Once enabled, double-tapping Option will open a text box where you can type your message and start a new chat. You can also click "New chat" to see your five most recent conversations. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1893088365/2ca4b782dda90abea1fe5f4150af/CleanShot+2025-12-18+at+13_14_30%402x.png?expires=1788548400&signature=e8782dd4e2c10e2ffe9c14a67679ee323cb8c77a747f39975196245efe9d390b&req=dSguFcl2lYJZXPMW1HO4zWggD9ZUopSeRC8c%2FcM5c2JgDncErkByPi69ZteQ%0AwHTYVRutP%2FTFlG2DaDc%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1893088365/2ca4b782dda90abea1fe5f4150af/CleanShot+2025-12-18+at+13_14_30%402x.png?expires=1788586200&signature=69b0dfbf7266e213955cac7adab245e4a24f1fa71ecbb89d67890b8829f2ea8e&req=dSguFcl2lYJZXPMW1HO4zWggD9ZUrpqYRC8c%2FcM5c2KyrmO0SKm0QXQw9PcS%0AwKiJ%2BF%2BS2DBOE0LKYZk%3D%0A) ### Enable the voice shortcut (optional) diff --git a/content/support/12883420-view-usage-analytics-for-team-and-enterprise-plans.md b/content/support/12883420-view-usage-analytics-for-team-and-enterprise-plans.md index c676d535a..5eb8eda96 100644 --- a/content/support/12883420-view-usage-analytics-for-team-and-enterprise-plans.md +++ b/content/support/12883420-view-usage-analytics-for-team-and-enterprise-plans.md @@ -22,7 +22,7 @@ This page includes the following analytics: - Sessions in Cowork -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515895966/9f231a620f47d49e0ee648152189/848c1787-4eaa-4809-8fd2-1dbe2722560f?expires=1788548400&signature=091012d2679e64b2aef64c3fd8523959c1079c8029fa208dab43036116fbe31a&req=diUmE8F3mIhZX%2FMW1HO4zZL6wa53n411ExEG4dCAGDYgElqdtBxHWaDm2llN%0A%2Bac7YVsj2l39QPPonCg%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515895966/9f231a620f47d49e0ee648152189/848c1787-4eaa-4809-8fd2-1dbe2722560f?expires=1788586200&signature=7743afa2ec4acf1273aac03a35928e33aa3ecc5ed6d982f97cef01af03c2c4ed&req=diUmE8F3mIhZX%2FMW1HO4zZL6wa53k4NzExEG4dCAGDZCjwkUyKBuoyR5k25f%0AEIQ66bsn4Szk7MuTzxc%3D%0A) ### Who’s using Claude? @@ -34,7 +34,7 @@ This page includes the following analytics: Use the dropdown on the **Active members and assigned seats** chart to filter by product, including Claude Design. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515896351/4d955858e6662c37489cc1470871/457cf159-8c2a-4403-ba22-cb92cb47e459?expires=1788548400&signature=353eecf0596627c1d018a29ad2976be1a003d53858ae718670be2fe7b352ce2c&req=diUmE8F3m4JaWPMW1HO4zYEqej%2BsRpirYqPRsgaNdTw%2BksFaBELh%2BWyZvi8K%0AcvfK1YlQt9Jl%2FPbxFY8%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515896351/4d955858e6662c37489cc1470871/457cf159-8c2a-4403-ba22-cb92cb47e459?expires=1788586200&signature=2eac2d557167bfecf86e3c88fb0ac6074a9a41b3eb20eff0a37cb2852d8b8ea2&req=diUmE8F3m4JaWPMW1HO4zYEqej%2BsSpatYqPRsgaNdTxnN0t%2Bc%2B2MfGc%2BRYbK%0A%2Ft%2BZrFQhe8B5sLosAAs%3D%0A) ### How are they using Claude? @@ -48,9 +48,9 @@ Use the dropdown on the **Active members and assigned seats** chart to filter by - How agentic is their work? (beta) -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2583875713/e3cb3c329f3b643cb9a3809876b3/image.png?expires=1788548400&signature=3ad9a224618d2a2f52a1e76fcfd084dede730dc3600e66886842565e8fd478f2&req=diUvFcF5mIZeWvMW1HO4zciS3aDsnrZvDFD6TO7tG4iQnIca1lUik%2FH23XMX%0Aovv%2FJc6PXOo4PeRPzT8%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2583875713/e3cb3c329f3b643cb9a3809876b3/image.png?expires=1788586200&signature=0039df443e9c9867d6236e569b7696b46f8476c95c6612bba92893321617a5f2&req=diUvFcF5mIZeWvMW1HO4zciS3aDskrhpDFD6TO7tG4gfcRr064dC%2FoY43jm8%0AhPDbOPdAXzuGbgovV50%3D%0A) -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515896563/abf008596ce5501297a609696362/fce5423c-4769-4b73-9a0a-c50f6407ebea?expires=1788548400&signature=3a9e7d1a364588b19419c815375f906c8c3c9e7c5990e05d5adbc6f5c7ac1ab6&req=diUmE8F3m4RZWvMW1HO4zR%2BIDo9ruf%2FzLS3kobW3ZgRcxil7XPo86lGMuoYw%0AZ7ED1cxujwn3DLj%2BRxU%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515896563/abf008596ce5501297a609696362/fce5423c-4769-4b73-9a0a-c50f6407ebea?expires=1788586200&signature=0f49652a96506ae4ec6facb94f53dc3c2ff26640f7f7308505777a98ee147de4&req=diUmE8F3m4RZWvMW1HO4zR%2BIDo9rtfH1LS3kobW3ZgRsRZFVAekLY5I9rjM4%0AnRUuGYoDadtL1MEUYno%3D%0A) ### What are the results? @@ -66,7 +66,7 @@ Use the dropdown on the **Active members and assigned seats** chart to filter by - Estimated time saved -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515896943/dd415f03afe56ca38308ef987f86/189e8ebc-5594-4f4b-bd84-e3c11c824d5b?expires=1788548400&signature=aace5957a9ed7f611c6ba2d40c663a007255c53838d7837082e228169f987914&req=diUmE8F3m4hbWvMW1HO4zfJThCw6rdRCiovaLYNN7Rk882HJm6beTPTrCGX0%0ApD598PVvtck6GsKkr5I%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515896943/dd415f03afe56ca38308ef987f86/189e8ebc-5594-4f4b-bd84-e3c11c824d5b?expires=1788586200&signature=4accdf933e170bc17116f2f15a606178b74b9cf7766baa333b3f4857217c052e&req=diUmE8F3m4hbWvMW1HO4zfJThCw6odpEiovaLYNN7RlZvIKPJeZIqz5m86%2BF%0A00jmLrgUtek%2BeEbIumo%3D%0A) ### How much is Claude costing? @@ -82,9 +82,9 @@ This section includes the following analytics: - Spend by model (month-to-date, quarter-to-date, year-to-date, 1 year) -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515896942/b403f2d216fc40b5195911020b8e/446b99f1-3187-4b79-b2be-9f17b1632ff8?expires=1788548400&signature=1356da464fc5e6d98b5310ecc4e39ddfd17857091be96e669533a8d6cb7d33a7&req=diUmE8F3m4hbW%2FMW1HO4zYE%2BQ9YH6DnZWbBLGZ4vBJVnRThnx8OC5VVSDs1%2F%0AlUfBEtezVhAOO35fHSc%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515896942/b403f2d216fc40b5195911020b8e/446b99f1-3187-4b79-b2be-9f17b1632ff8?expires=1788586200&signature=72d36b180407285d8fa4850a9cdf50f02838b89888737298f53409c6e0f439fc&req=diUmE8F3m4hbW%2FMW1HO4zYE%2BQ9YH5DffWbBLGZ4vBJWR3B6q4jBKndgqHQNz%0AqOR0cbS4fxIbzvxK9l0%3D%0A) -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515896941/2239ce38639df339b24d5af1cb50/f829bc2a-ee52-4135-9b13-09ef1b7d66d6?expires=1788548400&signature=5f211d43a1f4b00c7e494185abcf7e62286760c4646b7216fb39f829a07d8ae2&req=diUmE8F3m4hbWPMW1HO4zTz0NuIHI8FUC%2BtvTPa1I7HudWnbJGyJkFhL8iji%0AH2oMC2gHjL%2F1UwyEVZE%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515896941/2239ce38639df339b24d5af1cb50/f829bc2a-ee52-4135-9b13-09ef1b7d66d6?expires=1788586200&signature=2f5ff3d1e8327702b856e4c22e5aa9fb0542ee322ba571df77e5d7dc0cfddc1d&req=diUmE8F3m4hbWPMW1HO4zTz0NuIHL89SC%2BtvTPa1I7GdZ%2FbDZs1Jv6RGjwqu%0AarJSRVR%2Bwq0efzOIwoE%3D%0A) ## Export a spend report @@ -160,7 +160,7 @@ Navigate to **[Analytics > Claude Chat](https://claude.ai/analytics/usage)** to - Top members by chats -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515898793/405db0c492da11886c28a2b82731/71a55afc-1cef-4c50-b7e1-86775cb9a168?expires=1788548400&signature=272351e714de90274bd776b71b468e23f5bb43b02a05a8bc12d725a7f472dd75&req=diUmE8F3lYZWWvMW1HO4zbhc8fWZZewlTcfMEUwBBiXJhOu18Pn88AvVIzQq%0AZcm7v7Sn6aDtVqZlnlI%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515898793/405db0c492da11886c28a2b82731/71a55afc-1cef-4c50-b7e1-86775cb9a168?expires=1788586200&signature=73526d518491c16b1c8622060d33856c4d3218b44a68236129afb9315ae06b97&req=diUmE8F3lYZWWvMW1HO4zbhc8fWZaeIjTcfMEUwBBiXQrOgFH2%2FjYD6bNuD1%0Ai5Dddc7eaU7BO7aUHbY%3D%0A) ### Projects @@ -172,7 +172,7 @@ Navigate to **[Analytics > Claude Chat](https://claude.ai/analytics/usage)** to - Top members by project usage -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515899610/91d93108f0767e795fb9e488e882/71607d6d-dff1-4a13-a445-aa1d79850eed?expires=1788548400&signature=95b1aeb7375a28d9b6a54cf34b86d2c3a3e9c17ecf4da3fa4dd759d14e9a2285&req=diUmE8F3lIdeWfMW1HO4zWhGoTScnyumExu5cYiHHN%2BslW8cocHB%2FNeH8mtd%0AgW7msRDrVHeZxKPqPsM%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515899610/91d93108f0767e795fb9e488e882/71607d6d-dff1-4a13-a445-aa1d79850eed?expires=1788586200&signature=1351916f1b305f77ae98c8bbabaa3c7be6a3ef9e0f94ca20687114607908204f&req=diUmE8F3lIdeWfMW1HO4zWhGoTSckyWgExu5cYiHHN%2BCtOzOVHe73CH5dlOV%0A0shGuPHrA%2B3ilQP%2FNl4%3D%0A) ### Artifacts @@ -182,7 +182,7 @@ Navigate to **[Analytics > Claude Chat](https://claude.ai/analytics/usage)** to - Top 10 users by artifacts generated (month-to-date, quarter-to-date, year-to-date, 1 year) -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515899838/33d737f2357d6e485704669962ae/43faadc3-47da-4a93-bbb7-47a7983e7441?expires=1788548400&signature=f76e73454297ebb48dc9f715ed4a554870c5a0dfb83a956ece035bc7a31d5aae&req=diUmE8F3lIlcUfMW1HO4zcSk4rLXeubEjHDogqK0V%2BzE5P46kIbZKOX9IMo3%0As8Q7HJ1AlgUlhiZK8Yg%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515899838/33d737f2357d6e485704669962ae/43faadc3-47da-4a93-bbb7-47a7983e7441?expires=1788586200&signature=e78f448743895a136fdb4d85622638544f930e2f7f87573af38aec046d7bd8fa&req=diUmE8F3lIlcUfMW1HO4zcSk4rLXdujCjHDogqK0V%2ByHUnqsKrIb3Q9dujpS%0AN58lnU%2BKPoF2Ln3hdP0%3D%0A) --- @@ -278,7 +278,7 @@ Navigate to **[Analytics > Cowork](https://claude.ai/analytics/cowork)** to view - Daily, weekly, and monthly active Cowork users -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515901489/8005693d55b7fefbfe9233258d39/106c22a0-3f47-47a6-abbd-4788dd70f218?expires=1788548400&signature=d849398663e161cc2a1c04408b4074b0f00b0d9b7b5d90442bc9a93e19e467e1&req=diUmE8B%2BnIVXUPMW1HO4zX7WEoC0WUmsFSi1Z3SzLLtWWdQSqdZ%2BsWMDluoP%0Aoo8NxR7k29zO7M3n3mM%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2515901489/8005693d55b7fefbfe9233258d39/106c22a0-3f47-47a6-abbd-4788dd70f218?expires=1788586200&signature=bf19b57fa9ca2453698e447099a828f469d16ec2ea15e4b90ba6dbe7c5cf9b73&req=diUmE8B%2BnIVXUPMW1HO4zX7WEoC0VUeqFSi1Z3SzLLvl7KeYKr%2BnyrnMV5Hx%0A8Zxyyma4TYTcTnHV7tw%3D%0A) **Note:** Cowork analytics are available alongside Chat and Claude Code data in the **[Analytics API](https://platform.claude.com/docs/en/manage-claude/analytics-api)**. @@ -294,7 +294,7 @@ Navigate to **[Analytics > Surveys](https://claude.ai/analytics/surveys)** to as On Enterprise plans with usage-based billing, when your admin turns on individual usage analytics, any member of the organization can see their own usage broken down by product, model, and skill, along with where they stand against any spend limits set for them. Individual usage analytics are available in **[Settings > Usage](https://claude.ai/settings/usage)**. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2533906328/1f5cd0a57def40676410f8f379b4/member-usage-30d-model.png?expires=1788548400&signature=f6b84490aef5f3250759f70e036bbb837cf4c3df6cf76fa0717cc4860cdd4d2a&req=diUkFcB%2Bm4JdUfMW1HO4zfveB6fAeOPeWGUKUw6QS48E%2FY6Ju9z8mFraKaC2%0AtJAcM9htL9a9tdWLK7Q%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2533906328/1f5cd0a57def40676410f8f379b4/member-usage-30d-model.png?expires=1788586200&signature=4a821f083ed49bea273c59f8d08e1f2fdfddf3c1d5bf1981094e20368f8a2f57&req=diUkFcB%2Bm4JdUfMW1HO4zfveB6fAdO3YWGUKUw6QS4%2FJ1L%2B%2FPouOaBwUqiDS%0AL63qMvj5X7qZOSWEJk4%3D%0A) --- diff --git a/content/support/12902446-claude-in-chrome-permissions-guide.md b/content/support/12902446-claude-in-chrome-permissions-guide.md index 19452deed..8cfbb7d72 100644 --- a/content/support/12902446-claude-in-chrome-permissions-guide.md +++ b/content/support/12902446-claude-in-chrome-permissions-guide.md @@ -28,7 +28,7 @@ In "Manually approve," Claude checks with you before it acts. What that looks li Claude creates a plan from your prompt, which you can approve before Claude starts. The plan specifies which websites you're allowing Claude to access, as well as the approach it will follow: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1843320727/8d1c859ae9b8e0cdb536d024bf40/9bc3d239-8eb6-4bae-a032-a236f88ee606?expires=1788548400&signature=119148ee6da9f4540e8b2ebed0bde566268c96a4ffcfc11557a669d2c0f7bde7&req=dSgjFcp8nYZdXvMW1HO4zYqyZcpI%2BIqzgN0ADj5oqFDhFVs2yyPZXUJF%2BkXe%0AhtMNJyce25NqS9bWrLY%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1843320727/8d1c859ae9b8e0cdb536d024bf40/9bc3d239-8eb6-4bae-a032-a236f88ee606?expires=1788586200&signature=5adee736837775dbb476dcc7fd6f832e4303a435cb801f0aef553eae31737221&req=dSgjFcp8nYZdXvMW1HO4zYqyZcpI9IS1gN0ADj5oqFBJUKLRA3SN%2FvgGdLcf%0ALFeW3Jt0bb%2FhX%2Fh3ID0%3D%0A) Note that Claude will only use the websites listed in the plan, so you’ll need to manually approve any additional access requests. @@ -62,7 +62,7 @@ When you choose "Skip all approvals," Claude doesn't pause to ask, and nothing c There are some websites on which Claude requires approval for every action. If you navigate to one of these sites, a **New permissions required** prompt will appear in the extension side panel, Claude Cowork, or Claude Code where Claude will ask for permission before accessing the page or taking any action. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2604970825/d7b961271be69e7541b406df1efd/d845324e-6b4a-4f54-83b9-0bea86ec09c6?expires=1788548400&signature=4b2539ee083df25cdb6788b261d133c41fd256eab91bc62c3020fa0a59c7f706&req=diYnEsB5nYldXPMW1HO4zZ3Nqm51jCTo7A4lHPBihAVfMgrhT5lJlCJ%2BKK7c%0AsgBgvGANpCtvbfhMX%2FM%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2604970825/d7b961271be69e7541b406df1efd/d845324e-6b4a-4f54-83b9-0bea86ec09c6?expires=1788586200&signature=050cc4fc72c274a6d5ed87ccb5bcc37f670d3e94b3bd408087a0661a0cab9e50&req=diYnEsB5nYldXPMW1HO4zZ3Nqm51gCru7A4lHPBihAVFIzha2doi%2BAEGVP8r%0AA2Ktil4OVxcadawA9K8%3D%0A) ### Permission options diff --git a/content/support/13132885-set-up-single-sign-on-sso.md b/content/support/13132885-set-up-single-sign-on-sso.md index 9d0295d70..c9e6270f2 100644 --- a/content/support/13132885-set-up-single-sign-on-sso.md +++ b/content/support/13132885-set-up-single-sign-on-sso.md @@ -42,7 +42,7 @@ You can verify multiple domains for a single organization, but all domains must 3. Enter the domain(s) you want to verify in the **Update organization email domains** modal and click the “+” button: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2498843282/561d5ceb1c3a5df75bdfee8bfc3f/d2491145-362d-490b-bdcf-66a0a7656ddc?expires=1788548400&signature=42afbea426764d3e388eabe625e0fe647779bc675ae48ba8a23175a960525b63&req=diQuHsF6noNXW%2FMW1HO4zSdmHnQ8%2FsyIe3H0OpmIzWFl%2BUEv3MRXuGhj2t39%0AeU34%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2498843282/561d5ceb1c3a5df75bdfee8bfc3f/d2491145-362d-490b-bdcf-66a0a7656ddc?expires=1788586200&signature=57ff35bb51ee6014056777012801b4e370223db5d425e16c33234f40e3b4ac68&req=diQuHsF6noNXW%2FMW1HO4zSdmHnQ88sKOe3H0OpmIzWEDczCbZQj3EjZj0%2B0b%0AAOT3%0A) 4. Click “Save” when you’re finished adding domains. @@ -50,7 +50,7 @@ You can verify multiple domains for a single organization, but all domains must 6. Enter your domain in the text box and click “Continue”: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2047042630/0617a562cd28a7ff0e607d66a30b/6bd08e1d-2b65-40ab-bc79-a257153854c1?expires=1788548400&signature=e2558c533ccaa879e265541a79a61d216ef007492590720aa16013a6b356a658&req=diAjEcl6n4dcWfMW1HO4zWHctRWSk9muyoyXAW0OlXoes%2B48o7bHhsSbgmjm%0A3CGv%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2047042630/0617a562cd28a7ff0e607d66a30b/6bd08e1d-2b65-40ab-bc79-a257153854c1?expires=1788586200&signature=a19ed71396bf1f4311693ed76077ee1a52c046bac81f707a920b67b671d50aa8&req=diAjEcl6n4dcWfMW1HO4zWHctRWSn9eoyoyXAW0OlXpUZlbkO68DiR4mn4vM%0A4PEQ%0A) 7. The setup screen displays a TXT record. **Copy the full Value using the copy button**—it begins with `anthropic-domain-verification-` and is longer than what's visible in the box. In your DNS provider, add a TXT record to your domain and **Value** set to the copied string. The domain must match exactly what you entered in the previous step, including any subdomains. Add it alongside any existing TXT records; don't replace them. The value is case-sensitive, so paste it exactly. Please refer to your DNS provider's documentation on this topic. @@ -76,7 +76,7 @@ Clicking "Refresh" re-checks your DNS; it won't show Verified until the publishe If the record is correct and propagated but the status still shows Pending, contact Support. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2047044496/b8df54a0331784cc9ae8f00112aa/bf9609c1-dc93-4665-a066-4cae2fe4b002?expires=1788548400&signature=bfa03e44af960849814f4cb5431099fafb957d838ef5800c770c37e12a293ebc&req=diAjEcl6mYVWX%2FMW1HO4zVjmWSEFa3y9PM2D8Zcdgrj5rJmRV0Jo2XNN7Frf%0A%2BcfVP1VuAHiIiLhn%2BBA%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2047044496/b8df54a0331784cc9ae8f00112aa/bf9609c1-dc93-4665-a066-4cae2fe4b002?expires=1788586200&signature=6e1ae80ba02555ca3e2a1ebcf20a2f91ceb78d8c146feaf741ee1b2af41b5515&req=diAjEcl6mYVWX%2FMW1HO4zVjmWSEFZ3K7PM2D8ZcdgriPtfcRHgyG8LY8mdoc%0AJQCOGFHCwM3oD8yUgUo%3D%0A) **Note:** Once your domain is verified, you'll see a **Restrict organization creation** toggle under **Security** on the Organization and access organization settings page. Enable this if you want to prevent users from creating new Claude or Console organizations—including personal accounts—using your verified domains. @@ -116,7 +116,7 @@ For IdP-specific setup instructions, see: You can now choose to toggle on **Require SSO for Console** and/or **Require SSO for Claude,** on the **Organization and access** page, under the **Authentication** section: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312690200/bd2403586d4f6651ccd79e2a45af/b9f8d7ce-0def-49d9-bfb2-3a14352d7214?expires=1788548400&signature=a3bddb4c57d9eba455cbfd8a9046c05556984e945718a5384cb0a179ef3d19be&req=diMmFM93nYNfWfMW1HO4zdAICwekBnQOItXtKivx6ZEFh9jllF9o0%2F6FfClh%0AY%2BFHzuJTaf37XINHrfo%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312690200/bd2403586d4f6651ccd79e2a45af/b9f8d7ce-0def-49d9-bfb2-3a14352d7214?expires=1788586200&signature=c0ade47b8a305e0389e303bd37062fc838a200da376081a90cb0f612f100233f&req=diMmFM93nYNfWfMW1HO4zdAICwekCnoIItXtKivx6ZG5cmZRFQHs49EidoCJ%0Agehjat5DDIEVB7zFXds%3D%0A) When SSO is required, users must use the “Continue with SSO” option to log in to their Claude/Console accounts. When SSO is not required, they will have the option to choose “Continue with SSO” or “Continue with email.” diff --git a/content/support/13133195-set-up-jit-or-scim-provisioning.md b/content/support/13133195-set-up-jit-or-scim-provisioning.md index df97d78cf..3c78c879b 100644 --- a/content/support/13133195-set-up-jit-or-scim-provisioning.md +++ b/content/support/13133195-set-up-jit-or-scim-provisioning.md @@ -36,7 +36,7 @@ Use this table to help decide which provisioning mode is right for your organiza Both JIT and SCIM can be combined with **Enable group mappings** to control role or seat tier assignment based on IdP group membership. If you select either of these options for your provisioning mode, **Enable group mappings** will appear within the **User provisioning** section: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312706099/35d5d3ec149880a96bb7acec59f6/a4cfce55-86bf-40b0-b455-c8f412d48e9e?expires=1788548400&signature=32b27c726ade14cdb0d6a93810693854329cbe41dd74142997d9bb1fd14c0eb6&req=diMmFM5%2Bm4FWUPMW1HO4zXBDQ6NRCVJyxFMG%2BIEvQSemenGzulzjKd6%2FU%2F0y%0A9ppPMU0FUcvICnfVLk4%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312706099/35d5d3ec149880a96bb7acec59f6/a4cfce55-86bf-40b0-b455-c8f412d48e9e?expires=1788586200&signature=722e6c104dd7e3fae9eeaae7bdff9516d903318d1602690cba85ae81c1a0140c&req=diMmFM5%2Bm4FWUPMW1HO4zXBDQ6NRBVx0xFMG%2BIEvQSdDbIWpL9sG4SPe001i%0A2AKi6SzHpnn2NpS63NA%3D%0A) **Important:** Group mappings set a user’s role type and seat tier only. Users with the Custom role get their permissions from groups in Claude, and those groups sync from your IdP only when your provisioning mode is SCIM directory sync. With JIT, you need to create groups and add users to them manually in **[Organization settings > Groups](https://claude.ai/admin-settings/groups)**. If you map an IdP group to the Custom role under JIT without doing this, those users have no permissions when they log in. Learn more about **[managing groups on Enterprise plans](https://support.claude.com/en/articles/13799932)**. @@ -122,7 +122,7 @@ Once your IdP is connected, continue to Step 3. 4. Toggle **Enable group mappings** on (if it’s not already): - ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312714635/b57870b51e6511c8293637bceee2/da1ceabc-b6bc-451b-9cda-24ff6aa90d02?expires=1788548400&signature=25b9818a907c43c2b58dce493f15ecc18a7fbe3d7353ad72b0b78c7daa25f9be&req=diMmFM5%2FmYdcXPMW1HO4zeBEbs3dk%2FJMyb72rapuHpPvXWZoK0weWU%2BxuB31%0AunP0%0A) + ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312714635/b57870b51e6511c8293637bceee2/da1ceabc-b6bc-451b-9cda-24ff6aa90d02?expires=1788586200&signature=c3148d259191390c67eb54b14a43bef1bb98ef3bd1a303ac242ec163a3bce117&req=diMmFM5%2FmYdcXPMW1HO4zeBEbs3dn%2FxKyb72rapuHpPcY%2BOupZ8TYwaZ7%2F55%0AkFFc%0A) 5. In the **Enable group mappings** section, click “Add” next to each role and select the corresponding group from your IdP in the dropdown. @@ -174,7 +174,7 @@ Verify you have enough seats purchased and available to add members to your org. 4. **For SCIM:** Click "Sync" to prompt an immediate sync, or wait for the automatic sync cycle: - ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312717421/c97fce49ad17d4660880a05fbaaf/59fbfa2a-1072-4662-8ca5-102970d5a795?expires=1788548400&signature=993450cca711fc91757a75c7c95ad492dd5b00ed1bbfdf591bac332ff3c8efcd&req=diMmFM5%2FmoVdWPMW1HO4zZ9La1WoHcLG5hujYvMis4dKeZFkNecGMmVs0QtO%0AWqF9%0A) + ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312717421/c97fce49ad17d4660880a05fbaaf/59fbfa2a-1072-4662-8ca5-102970d5a795?expires=1788586200&signature=4cd258a83ba1cf6f02295dd6b497504890551b7fd004e588cfec3be7abe49388&req=diMmFM5%2FmoVdWPMW1HO4zZ9La1WoEczA5hujYvMis4e%2BBu0K7%2B86cyIgS%2F%2Bj%0AZder%0A) ### Users mapped to the Custom role can't access anything after logging in diff --git a/content/support/13163631-configuring-session-security-settings.md b/content/support/13163631-configuring-session-security-settings.md index 58501029a..4d64e910f 100644 --- a/content/support/13163631-configuring-session-security-settings.md +++ b/content/support/13163631-configuring-session-security-settings.md @@ -18,7 +18,7 @@ Session duration controls allow Enterprise and Console Admins to set a maximum s 5. Confirm your selection by clicking “Enable.” -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1888469436/1725e63ea1a2615948faecf4ec73/9bd276a1-7329-414d-87a1-d04dac93fff7?expires=1788548400&signature=89208c93c44fbb42f446d75cc2e681f14986582607d048b46090b0c052c1a68f&req=dSgvHs14lIVcX%2FMW1HO4zQNx6%2BoiR1JUg%2F6XaftFnjyPHMVewOp5itHRknp8%0AWkOZ%2FTWFWmHOl78Gh2c%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1888469436/1725e63ea1a2615948faecf4ec73/9bd276a1-7329-414d-87a1-d04dac93fff7?expires=1788586200&signature=28830c23d69e89fa5bf3220ac1131589e70592710ea2489ae8a55413bf96db0b&req=dSgvHs14lIVcX%2FMW1HO4zQNx6%2BoiS1xSg%2F6XaftFnjzl8sEwxN4Kdjbahoz3%0AyyODCcyzor8cc1IMpOs%3D%0A) ### For Console Admins @@ -32,7 +32,7 @@ Session duration controls allow Enterprise and Console Admins to set a maximum s 5. Confirm your selection by clicking “Enable.” -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1888469435/7a766bbe02e61c7d8f05deb5b8f0/b0bda400-47c6-43dd-9907-131ebe180b36?expires=1788548400&signature=071d27b166ba67d393c81f24b874f319b8f98052a2c455a74471ec797e79a17d&req=dSgvHs14lIVcXPMW1HO4zWzx2LEzI3clXZ5D7eVpMtdcUzHr7VvhzOp4jvza%0ArlrCHBVAcr2DtqPfx0w%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1888469435/7a766bbe02e61c7d8f05deb5b8f0/b0bda400-47c6-43dd-9907-131ebe180b36?expires=1788586200&signature=33048bd6d93d9aae46cad6ee703d87c78a5d03b5f4e9eeff216e6b79a264760c&req=dSgvHs14lIVcXPMW1HO4zWzx2LEzL3kjXZ5D7eVpMtc4b4GlqLR1w6csG6ES%0ArU8PNqaeAm0NVyfSROk%3D%0A) ### What happens after enabling shortened session length? @@ -50,7 +50,7 @@ You can change the session duration at any time by selecting a new value from th - Sessions scheduled to expire beyond the new duration will have their expiration shortened accordingly. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1888469437/46ac5bc55484ca01556d87a5ade7/b01a7651-ad65-4b32-93ff-16dbc9ca97c0?expires=1788548400&signature=afc7cf2bca405e92c520b8d1957bd37e3099f527acb177be976e7d8c063a5035&req=dSgvHs14lIVcXvMW1HO4zZ7mWsCe4zGnA00cbyPOLDX8lLlCZqdPWo4QW2do%0AUruT6mFwvICJnamyjos%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1888469437/46ac5bc55484ca01556d87a5ade7/b01a7651-ad65-4b32-93ff-16dbc9ca97c0?expires=1788586200&signature=d994f4b8d5715e9a57bdd021bbc001c164de003b98c5bbeedf31b19e71d6bd70&req=dSgvHs14lIVcXvMW1HO4zZ7mWsCe7z%2BhA00cbyPOLDUBQP6CY8zP874u1juZ%0AKcY5nv9xu5tjJdImXMw%3D%0A) ## Disabling session length settings diff --git a/content/support/13189465-log-in-to-your-claude-account.md b/content/support/13189465-log-in-to-your-claude-account.md index a5284654f..1bb3b8693 100644 --- a/content/support/13189465-log-in-to-your-claude-account.md +++ b/content/support/13189465-log-in-to-your-claude-account.md @@ -2,7 +2,7 @@ When you open Claude on a web browser ([claude.ai](http://claude.ai)), the desktop app, or a mobile app, you will see two different options for logging in to your Claude account. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1893216804/f2209c3ec6cf4fc2e803d13bbc9d/40520c9e-ff82-4a7c-adca-5a064fe18d8c?expires=1788548400&signature=b61d13ec9b50c2290c4f2a5a2d03db6a2783f70baf620f8ef3a67d85c31bb8f0&req=dSguFct%2Fm4lfXfMW1HO4zXg5BoqJ5xqwzWhrqpWiTMlECS6VeOUgSwc7YIh1%0ACw7L%2BFN%2FTFhwWJJ%2BNdY%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1893216804/f2209c3ec6cf4fc2e803d13bbc9d/40520c9e-ff82-4a7c-adca-5a064fe18d8c?expires=1788586200&signature=019d5f1c71f009480c34aae71be64e3243d748989978ed171d212d7e8074f69b&req=dSguFct%2Fm4lfXfMW1HO4zXg5BoqJ6xS2zWhrqpWiTMkZzb2kzyQeWrC3Qpe%2F%0AisKQY%2Bz4z1OMccf1hCk%3D%0A) ## Continue with Google diff --git a/content/support/13325567-account-management-faqs.md b/content/support/13325567-account-management-faqs.md index e87127801..868dd96c4 100644 --- a/content/support/13325567-account-management-faqs.md +++ b/content/support/13325567-account-management-faqs.md @@ -44,6 +44,6 @@ The email domain that was used to create your Team or Enterprise plan organizati Owners can remove domains by opening up the same modal and clicking the trash can icon to the right of the domain: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2053873852/1cbccea3b7067e03205f2ff8546b/CleanShot+2026-02-11+at+11_16_07%402x.png?expires=1788548400&signature=da97e35812643de6dc775e3c44a6a2ab18610769229f2aae55350f09a87d898e&req=diAiFcF5nolaW%2FMW1HO4zUrhFuOdbQAekeFUnrkrQZjmAZ2LB4eU4ROxCNe%2B%0ATrXebjOzq9beyarskRQ%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2053873852/1cbccea3b7067e03205f2ff8546b/CleanShot+2026-02-11+at+11_16_07%402x.png?expires=1788586200&signature=42d021505e391216943cbf9ccddb0dbd4fa685b56e07b12df0bf2aa32694449c&req=diAiFcF5nolaW%2FMW1HO4zUrhFuOdYQ4YkeFUnrkrQZivB7UGtazmZeiZu1n1%0Ad2bX06UPTlcohHbu4K8%3D%0A) While the account creator must use a business email address, you can add public domains like @gmail.com, @yahoo.com, and @hotmail.com as allowed domains for other members of your organization. \ No newline at end of file diff --git a/content/support/13345190-get-started-with-claude-cowork.md b/content/support/13345190-get-started-with-claude-cowork.md index 7fc47138c..31a90589f 100644 --- a/content/support/13345190-get-started-with-claude-cowork.md +++ b/content/support/13345190-get-started-with-claude-cowork.md @@ -178,7 +178,7 @@ To set global instructions: 3. Type your instructions in the text box and click "Save": -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2525926874/15324ac4155d7802272e8bdef04b/ec66cd09-a4db-4f1d-8f30-226c9d126333?expires=1788548400&signature=7364330f6c0eb12bc3cafcd9051a534fc775e6696bf63294df5fe058cd8bdaca&req=diUlE8B8m4lYXfMW1HO4zcDl6tDpMlm08iWjaktE940bhyCoMU6lbf5mbF0P%0A3E0xpXmZDukeA1iPy5s%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2525926874/15324ac4155d7802272e8bdef04b/ec66cd09-a4db-4f1d-8f30-226c9d126333?expires=1788586200&signature=69c31953210347c43cfc944c3b515c7b4848a339e6fa3cd2ab118ab46a5477a1&req=diUlE8B8m4lYXfMW1HO4zcDl6tDpPley8iWjaktE941XVw9gGPO92fKSHhno%0AHuEO%2FBvw%2FFLKHh1kKCw%3D%0A) ### Folder instructions diff --git a/content/support/13346458-customizing-your-console-appearance-settings.md b/content/support/13346458-customizing-your-console-appearance-settings.md index 5d19119d4..e301ef768 100644 --- a/content/support/13346458-customizing-your-console-appearance-settings.md +++ b/content/support/13346458-customizing-your-console-appearance-settings.md @@ -8,4 +8,4 @@ 3. Select from Light, System, or Dark under **Color mode**. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1922579101/ede30d38dca693c59f9c15d79e69/CleanShot+2026-01-08+at+15_45_20%402x.png?expires=1788548400&signature=0656800ec9f00214031a6e225009c7c8eccf7ab04e7655658a7dcdb59d145bc7&req=dSklFMx5lIBfWPMW1HO4zRpFC8ABSRpyO9Kw38RlAYJeB5Sk8D0pvBWia8Gr%0AlAwNLQF3yyFf231jtwQ%3D%0A) \ No newline at end of file +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1922579101/ede30d38dca693c59f9c15d79e69/CleanShot+2026-01-08+at+15_45_20%402x.png?expires=1788586200&signature=c10d0cade9b47a95c1d3d66630a9d4c3ed029cf340415489a3d7245f509ed8f0&req=dSklFMx5lIBfWPMW1HO4zRpFC8ABRRR0O9Kw38RlAYIGzs%2FOeH9wMZSDdDnH%0AK8p55hWYiHo8iXfn4EA%3D%0A) \ No newline at end of file diff --git a/content/support/13371040-log-in-to-your-console-account.md b/content/support/13371040-log-in-to-your-console-account.md index 1d388986c..6698d44f0 100644 --- a/content/support/13371040-log-in-to-your-console-account.md +++ b/content/support/13371040-log-in-to-your-console-account.md @@ -2,7 +2,7 @@ When you navigate to the **[Claude Console](https://platform.claude.com)**, you will see two different options for logging in to your Console account. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1935026646/d90d1613a3dbe763fef5abb96e3c/image.png?expires=1788548400&signature=c73ec6517caa3820952200b77938acc1fd643ce169599dd8bcfceb7ba36033b4&req=dSkkE8l8m4dbX%2FMW1HO4zcrI54HppIgJ8vUNcPt4%2B71Wl9l4aQU9%2BtRX00ie%0AcVw%2FnfIFdnTPwoypPSE%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1935026646/d90d1613a3dbe763fef5abb96e3c/image.png?expires=1788586200&signature=052d7b15d23d7f03aeb42c0b107250eacf06829203a5a881656f264055eee58f&req=dSkkE8l8m4dbX%2FMW1HO4zcrI54HpqIYP8vUNcPt4%2B70CuyE64EXxXrP7Wsw5%0AOwiFxKSyiZXwlQVAOzU%3D%0A) ## Continue with Google diff --git a/content/support/13641943-visual-and-interactive-content.md b/content/support/13641943-visual-and-interactive-content.md index df69af0b9..547c76571 100644 --- a/content/support/13641943-visual-and-interactive-content.md +++ b/content/support/13641943-visual-and-interactive-content.md @@ -18,7 +18,7 @@ Claude can show current weather conditions and forecasts when you ask about the Claude automatically displays temperatures in Fahrenheit for US locations and Celsius for everywhere else. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2040544927/3a9c695b24df387ecdd766ad308c/8be9f393-dcb0-4ff8-89e8-5fa47bedaa38?expires=1788548400&signature=2f8cdff4dccb1aab9813f736508ea374d26276de575a788408dcb63802f5eede&req=diAjFsx6mYhdXvMW1HO4zXlB7Ta%2F0RCMdgndksVD5R3zaUGd8q6CtvCEqp%2FH%0A%2Fs%2F0peu0m9P%2BJOciKUc%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2040544927/3a9c695b24df387ecdd766ad308c/8be9f393-dcb0-4ff8-89e8-5fa47bedaa38?expires=1788586200&signature=54a3ef7ee46f2084c72d3248ea4080f602617c06830c4fd4a21569dc6ffcd0cd&req=diAjFsx6mYhdXvMW1HO4zXlB7Ta%2F3R6KdgndksVD5R0Mcao%2FkjKj3mIyypjp%0AGeIuwVLrHpBrqzB9iws%3D%0A) Weather is powered by Google Maps (). @@ -28,7 +28,7 @@ When you ask about recipes, Claude can display formatted recipe cards that are e **Note:** Visual recipe cards are available on web and desktop only. On mobile, Claude provides recipe information as text in the conversation. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2040544929/12f4c51eda7779d65d3ea2c7ab16/d0f4a314-cff8-421a-b401-10c2bf50374e?expires=1788548400&signature=9e0e35473a38511d15f8235f16bbd2182fbdb4f0983257633c185306202791ae&req=diAjFsx6mYhdUPMW1HO4zUQpe7gQ1lyTrIPm%2FImZVg0YnbgS15ezPXWqLQCy%0AF6hSiZ2bdw52JmVxRcg%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2040544929/12f4c51eda7779d65d3ea2c7ab16/d0f4a314-cff8-421a-b401-10c2bf50374e?expires=1788586200&signature=2afc3579a755fc81cc3d474111e3ec9fbca53663b62f123396ddbb165b021a3b&req=diAjFsx6mYhdUPMW1HO4zUQpe7gQ2lKVrIPm%2FImZVg2wq6Ti%2Bj5hzupqu%2Bmx%0AjSp%2F3CvfMApIAONFBgc%3D%0A) ### Custom visuals @@ -76,7 +76,7 @@ For example, if you ask Claude to help you plan a trip, it might ask you to: This content appears at the bottom of the chat. You can still type a response if you prefer. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2040544930/9ad066e137d11e4b559b0217e12d/9bf30d2d-1715-42b3-9da5-2a9298f41f08?expires=1788548400&signature=d6f87ed78c81216c97d197ab0aedeb46b123ecea9980bb467c7c208be5309ee5&req=diAjFsx6mYhcWfMW1HO4zWmF5%2F27bRamx4wz0C7CTAJAwuJrYrexP9CAEx7e%0AEA027rK7C%2B278xqo0iY%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2040544930/9ad066e137d11e4b559b0217e12d/9bf30d2d-1715-42b3-9da5-2a9298f41f08?expires=1788586200&signature=993d245586bdf0dea9036a66dcf4cf6f699529945da92720381031df655f1e6b&req=diAjFsx6mYhcWfMW1HO4zWmF5%2F27YRigx4wz0C7CTAIKMDyb7FkJ1R0NMJV6%0AT2lWqXXvZrDmHq5y0I8%3D%0A) --- diff --git a/content/support/13756069-public-sector-faqs.md b/content/support/13756069-public-sector-faqs.md index 30bc39d03..8f505ea79 100644 --- a/content/support/13756069-public-sector-faqs.md +++ b/content/support/13756069-public-sector-faqs.md @@ -6,7 +6,7 @@ Select your product based on both your technical/functional requirements, and also your compliance/security/deployment environment requirements. Here is a list of options: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2197717161/79965a24090029e9e58c727c3c24/pubsec-product-matrix_png+%281%29.jpg?expires=1788548400&signature=182ef4b9fd893459ad16ac94d100431ff2a416a9ca74fa70889892cee85537db&req=diEuEc5%2FmoBZWPMW1HO4zU94LlEgGdU02WxtU42UVC1nC3UPcGyANvfKIbWV%0AxAWMFwkv8mJZ%2FHu%2FTws%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2197717161/79965a24090029e9e58c727c3c24/pubsec-product-matrix_png+%281%29.jpg?expires=1788586200&signature=497339119ceb8b7f398436c553486ce9e730fa5bea7be32379f18b4c6b3ded49&req=diEuEc5%2FmoBZWPMW1HO4zU94LlEgFdsy2WxtU42UVC37vlUxJybjilHW%2Fgv9%0Af7FbW156qhjVIVV%2BtEw%3D%0A) ### What is Claude for Government (C4G)? diff --git a/content/support/13837440-use-plugins-in-claude.md b/content/support/13837440-use-plugins-in-claude.md index e39aa0234..2406b1f4a 100644 --- a/content/support/13837440-use-plugins-in-claude.md +++ b/content/support/13837440-use-plugins-in-claude.md @@ -38,9 +38,9 @@ For the full collection of Anthropic-built plugins, visit **[GitHub](https://git In Cowork, open the "Cowork" tab first, then open **Customize**. -You can also upload a custom plugin file if you built one yourself or received one from a colleague. On Claude Desktop and in Cowork, plugins you add yourself are saved locally to your computer. +You can also upload a custom plugin file if you built one yourself. On Team and Enterprise plans, a colleague can share a plugin with you directly instead of sending you the file. See **[Use a plugin shared with you](#h_ef985546b4)** below. On Claude Desktop and in Cowork, plugins you add yourself are saved locally to your computer. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2100409211/fc01614dde1a616fa31ffaa9cb04/47bacf5b-a810-45b5-a468-9769f1a58ef8?expires=1788548400&signature=393ee3a079e1cd0bb116c45dd0a8c175fb45a9805d21153e0a04dc13bfd1fc2a&req=diEnFs1%2BlINeWPMW1HO4zZF3Ih3YN%2F1RxakFVfq5Www3JqggEVooHeRHGFli%0A%2BSTqINtWM6dDHq57JuQ%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2100409211/fc01614dde1a616fa31ffaa9cb04/47bacf5b-a810-45b5-a468-9769f1a58ef8?expires=1788674400&signature=bd6f516b99c1ee0a2c5d4bb040cc9ae0255114641135193335f3dc36870509b9&req=diEnFs1%2BlINeWPMW3nq%2BgVBR61lPspoU3ilCn8XYmtC5uDZwJDOPmveFyMgA%0AtmuzlkXKMrKrRP8J4L6D5hAiAjk%3D%0A) If you're on the Enterprise plan and your organization has skill scanning turned on, plugins are checked for malicious content when they're installed or updated. A plugin with malicious content is blocked, and one that may carry risk shows a caution banner. Learn more about **[skill and plugin scanning](https://support.claude.com/en/articles/15927065)**. @@ -50,7 +50,7 @@ If you're on the Enterprise plan and your organization has skill scanning turned Each plugin you install adds skills you can use while working with Claude. Type "/" or click the "+" button to see the available skills from your installed plugins, in chat and in Cowork. Click any skill to see its details. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2157396844/4a790e10f5b88df770783df1d7e9/image.png?expires=1788548400&signature=df6df3ff739c136cd803d27163867caec657d37f400fa6c994b9b8b3be8b9237&req=diEiEcp3m4lbXfMW1HO4zf4NBP75h0iQmKUxugP2BQv6%2BqAnAH8aPms2ytUI%0ArR2yJ6KtRjvmp3wltWk%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2157396844/4a790e10f5b88df770783df1d7e9/image.png?expires=1788674400&signature=63e0720a7cebba4473d80d5978264bd67a037bc94af2baf9886a07314d0049ba&req=diEiEcp3m4lbXfMW3nq%2BgasPOp6LFQbtIeApIe1p%2BLZEH2XVMBx94Cg0HKYP%0As05Q7zqmfxIo15rNnDY2Sr93vNQ%3D%0A) --- @@ -72,6 +72,66 @@ Want to create something from scratch? The "Plugin Create" plugin walks you thro --- +## Turn on plugin sharing for your organization + +Owners and Primary Owners of Team and Enterprise organizations can turn on skill and plugin sharing for members of the organization. Plugin sharing uses the same settings and toggles as skill sharing. + +To enable plugin sharing: + +1. Navigate to **[Organization settings > Skills](https://claude.ai/admin-settings/skills).** + +2. Click the "Policy" tab. + +3. To enable sharing between specific people, toggle on **Skill sharing**. + +4. To enable sharing with groups, toggle on **Share with groups**. If you have custom roles, you also need to enable the **Share skills with groups** capability in the custom role. + +--- + +## Share a plugin + +After an Owner or Primary Owner turns on plugin sharing, you can share a plugin you uploaded or created in Customize with specific colleagues (Team and Enterprise plans) or with a group (Enterprise plans). The people you share with get your current version, and you can stop sharing at any time. Plugins you installed from a marketplace, and plugins saved locally in Claude Desktop or Cowork, can't be shared. + +**Note:** If you don't see the option to share, check with your organization owner. + +To share a plugin: + +1. Navigate to **[Customize > Plugins](https://claude.ai/new#settings/customize-plugins)**. + +2. Find the plugin you created. + +3. Click the three-dot menu "..." next to it, then select "Share." + +4. Choose who to share with: + + 1. **Specific people:** Enter names or emails to share directly. Sharing creates a link that opens the item for anyone it's shared with. The plugin appears in the **Shared with you** section of each recipient's Plugins tab, grayed out until they enable it, and shows your name as the owner. + + 2. **A group (Enterprise plans only):** Share with a group your organization has already set up. The plugin appears in every group member's Plugins tab under **Shared with you**, grayed out until they enable it. Requires the **Share with groups** toggle. + +5. Click "Share." + +The plugin appears in each recipient's **Shared with you** section, labeled with your name, and stays off until they turn it on. Shared plugins are view-only. Recipients can enable and use the plugin, but they can't edit the contents. If you update the plugin later, recipients automatically get the updated version at next use. You can remove someone's access at any time, and access is removed automatically if they leave the organization. + +To copy a link to a shared plugin, click "Copy link" in the Share dialog. The link opens the plugin for people you've already shared it with; anyone else sees a message that it isn't available. + +## Stop sharing a plugin + +1. Click the "..." button next to the plugin, then select "Share." + +2. Click the "x" next to the person or group you want to remove. + +The plugin is removed from their list right away. Deleting a plugin removes it for everyone you shared it with, and anything shared with a member is removed automatically when they leave your organization. + +## Use a plugin shared with you + +When a colleague shares a plugin with you, it appears in the **Shared with you** section of the **Plugins** tab in **Customize**. It's off until you turn it on. Once it's on, its skills work the same way as any other installed plugin. + +You can't edit a plugin that's been shared with you. If you want to change how it works, ask the person who built it, or build your own version. If they stop sharing the plugin or delete it, it's removed from your list automatically. + +**Note:** Review a plugin shared with you before turning it on, the same as you would for any plugin from outside Anthropic. Learn more about **[skill and plugin scanning](https://support.claude.com/en/articles/15927065-get-started-with-skill-and-plugin-scanning)**. + +--- + ## Add or remove plugin marketplaces Anthropic provides built-in marketplaces of plugins, including a Knowledge Work marketplace that's added by default. You can add other Anthropic-built marketplaces, like Financial Services or Legal, or add one from a GitHub repository. @@ -98,7 +158,7 @@ To remove a marketplace, including the default Knowledge Work marketplace: ## Organization-managed plugins -If you're on a Team or Enterprise plan, an owner can distribute plugins across your organization through plugin marketplaces. These work the same as any other plugin, with a couple of differences: +If you're on a Team or Enterprise plan, an owner can distribute plugins across your organization through plugin marketplaces. These are different from plugins a colleague shares with you, which show up under **Shared with you**. Organization-managed plugins work the same as any other plugin, with a couple of differences: - You can't edit organization-managed plugins. This keeps shared tooling consistent across your team. diff --git a/content/support/13854387-schedule-recurring-tasks-in-claude-cowork.md b/content/support/13854387-schedule-recurring-tasks-in-claude-cowork.md index 8ffa930ab..317318263 100644 --- a/content/support/13854387-schedule-recurring-tasks-in-claude-cowork.md +++ b/content/support/13854387-schedule-recurring-tasks-in-claude-cowork.md @@ -52,7 +52,7 @@ There are two ways to create a scheduled task: 6. You can explicitly confirm you want to schedule the task when prompted by Claude by clicking “Schedule": -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2104085399/4dda7e6f76026fd827db0b9323a9/f20635bf-15e7-4978-a213-5b9f67e9fb9a?expires=1788548400&signature=5e0867081c125cbcb97f9a5d22d8dae0e2493ac5d62825598934e4d230960cf1&req=diEnEsl2mIJWUPMW1HO4zeLJBk3h%2B%2BKDPx%2FSrZI7l8zUGM3uWlSCDTWcQNVw%0ANApG%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2104085399/4dda7e6f76026fd827db0b9323a9/f20635bf-15e7-4978-a213-5b9f67e9fb9a?expires=1788586200&signature=539f7d0b6a500c8952b27a2e302f70f2f148abd8f8c39958929a12e3d41c3c72&req=diEnEsl2mIJWUPMW1HO4zeLJBk3h9%2ByFPx%2FSrZI7l8zsd0kAim3M0s%2BmoJ0w%0A5dvT%0A) 7. Claude will create and schedule your task, and it will be added to the **Scheduled tasks** page. diff --git a/content/support/13947068-assign-tasks-from-anywhere-in-claude-cowork.md b/content/support/13947068-assign-tasks-from-anywhere-in-claude-cowork.md index 713e4f919..58ede340e 100644 --- a/content/support/13947068-assign-tasks-from-anywhere-in-claude-cowork.md +++ b/content/support/13947068-assign-tasks-from-anywhere-in-claude-cowork.md @@ -48,11 +48,11 @@ Follow these steps to get started: 5. You’ll land on a page describing the functionality. Click “Get started”: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2169954086/419674f781edb2977b93cce062b4/93b1893c-d79a-4eb6-b2f1-2fe3e043bd90?expires=1788548400&signature=f04923696cf1be69b14f1ce1bacf49731732f9f242c78922074d261d2af44285&req=diEhH8B7mYFXX%2FMW1HO4zSZP0pqOEQb7B32drIe5EDnIUHrD73jMGNWJ8q8K%0AZjVB%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2169954086/419674f781edb2977b93cce062b4/93b1893c-d79a-4eb6-b2f1-2fe3e043bd90?expires=1788586200&signature=33a746a24ceba762e108351c411b54cb29f1779d4609d4593c8dd5656d18eaac&req=diEhH8B7mYFXX%2FMW1HO4zSZP0pqOHQj9B32drIe5EDmckstZ6UsJxc6rlceE%0Aq30%2F%0A) 6. On the next screen, you can give Claude access to your files and keep your computer awake by toggling those on: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2169955082/de4053ee0eab8fcb9263584bb171/d39b77da-1a69-4682-9fdb-7ed488f236b0?expires=1788548400&signature=533a4db814a56c090e6ad61bd7cb24be8905df6049b1330e554fb2f282223df6&req=diEhH8B7mIFXW%2FMW1HO4zaZWs9KdWQkaepuGRb1rD3IgXSKEqWZBsdNtyLjA%0AiFov%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2169955082/de4053ee0eab8fcb9263584bb171/d39b77da-1a69-4682-9fdb-7ed488f236b0?expires=1788586200&signature=117a719c7f46a597e64a05d154f479768e08208927fc5447143044083cf41279&req=diEhH8B7mIFXW%2FMW1HO4zaZWs9KdVQccepuGRb1rD3K4wh6HdoRVHja60XV0%0AGXtw%0A) 7. Click “Finish setup.” diff --git a/content/support/14499648-how-scim-sync-works-for-enterprise-organizations.md b/content/support/14499648-how-scim-sync-works-for-enterprise-organizations.md index 83cd966ae..79f44caa3 100644 --- a/content/support/14499648-how-scim-sync-works-for-enterprise-organizations.md +++ b/content/support/14499648-how-scim-sync-works-for-enterprise-organizations.md @@ -50,7 +50,7 @@ You can trigger a manual sync from two places in your admin settings. 2. Click "Check for updates" under **SCIM sync**: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312613548/44cd5970ee3c3b2c7f8dcd592d71/image+%2824%29.png?expires=1788548400&signature=5e750179e7004d9069d6f9730ed9b65f98d7376e4e30372f4699e2aa4e732ebb&req=diMmFM9%2FnoRbUfMW1HO4zW4gbD2oMcWwrgfl7PnOiumMYLs%2BgUamLggmrgLf%0Awh7q%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312613548/44cd5970ee3c3b2c7f8dcd592d71/image+%2824%29.png?expires=1788586200&signature=45e0ddad6170a93ad39f5bc97ddeb39469a99c6a6b3ee0ed3ac300d02b9f8cdd&req=diMmFM9%2FnoRbUfMW1HO4zW4gbD2oPcu2rgfl7PnOiulo8JmBVtlJ3zUA%2Fan9%0ACLla%0A) 3. Select whether to sync members, groups, or both. @@ -62,7 +62,7 @@ You can trigger a manual sync from two places in your admin settings. 3. Select whether to sync members, groups, or both: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312608119/e4b0ef4f309f3c4eac8311a6ef47/image.png?expires=1788548400&signature=484f4f683ef101ffd619356537c57ec13d76f92c95827fb85554e87f29dfa7bf&req=diMmFM9%2BlYBeUPMW1HO4zX%2F4frL1zzMb43OpyTHzM9SpsyW%2FECQOoTvmpxU3%0AyOAv%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312608119/e4b0ef4f309f3c4eac8311a6ef47/image.png?expires=1788586200&signature=8d2695d7fc6dd402ea66b4e15b6e51fc5c8430bb712fa4b9b368c97377c65a52&req=diMmFM9%2BlYBeUPMW1HO4zX%2F4frL1wz0d43OpyTHzM9SFjynJTVnITID3fmcd%0AnYVZ%0A) **Note:** If you trigger a manual sync while background changes are processing, your organization takes the most recent change for each member or group. If multiple changes are queued for the same member or group, you may need to resync again to make sure everything applies correctly. diff --git a/content/support/14503613-sso-login.md b/content/support/14503613-sso-login.md index cef449724..93dffa229 100644 --- a/content/support/14503613-sso-login.md +++ b/content/support/14503613-sso-login.md @@ -47,9 +47,9 @@ Before configuring your Identity Provider (IdP), you must verify ownership of yo 3. Wait for the DNS propagation. Once the platform detects the record, the domain status will update to “**Verified**.” -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256015862/476131c3139aec4db01b96127544/10c7a165-8b26-4443-b064-9d659659c65e?expires=1788548400&signature=599f3e07c1090fa44c04e11600da1a735f5402fc6fd80780f8f2a904ea30b26c&req=diIiEMl%2FmIlZW%2FMW1HO4zdpfuCKNHluL006zz1SmF9UslYkpa3kGuk0%2FIGyH%0AbXBCuK7Jrl4v1KFZ4ls%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256015862/476131c3139aec4db01b96127544/10c7a165-8b26-4443-b064-9d659659c65e?expires=1788586200&signature=031d51602401afde2d26c75e5898c858f2b918c99060317f6fe479d82ada428d&req=diIiEMl%2FmIlZW%2FMW1HO4zdpfuCKNElWN006zz1SmF9U1KfJLpEIreDGHkQeZ%0A1gpoI6Ddfk4aliokMgw%3D%0A) -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256025910/a82e2de9382824fa9db7666f67c4/CleanShot%2B2026-04-09%2Bat%2B16_25_20-402x.png?expires=1788548400&signature=6c0d13cbeb1cd6895ca10fa6e3eb2dcf01fc81e0620e52f97f9e08bda5771911&req=diIiEMl8mIheWfMW1HO4zV%2BGnRE6R7dDx57dwYq5DdKYiVqnfrad1Ipyda4V%0AWGFptQSvRnM0dhpDmT0%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256025910/a82e2de9382824fa9db7666f67c4/CleanShot%2B2026-04-09%2Bat%2B16_25_20-402x.png?expires=1788586200&signature=d4be9b5b03d5983798be01306fde4949c9e1901284a1abbd07f2c81e50d43a66&req=diIiEMl8mIheWfMW1HO4zV%2BGnRE6S7lFx57dwYq5DdLMbXTb%2F64F6XafCGix%0A7pDs2hU2lZ1YscxVAQE%3D%0A) **Important:** Each domain can only have one identity provider. If multiple organizations share a single login domain, IT administrators from both organizations will be able to modify login settings. Contact **[Anthropic Support](https://claude.fedstart.com/support)** for assistance with multi-organization setups. For more details about multi-organization setups, see our **[SCIM provisioning guide](https://support.claude.com/en/articles/14503643-set-up-scim-in-claude-for-government)**. @@ -77,7 +77,7 @@ Once your SAML application is set up in your IdP, provide Anthropic with the det - Claims Information — Attribute mappings for user name and email. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256004522/a97b91092b393e93b2d7779f63e6/2db86a6d-1582-419e-925e-cbc914468fa1?expires=1788548400&signature=a7c57bad990d3b911e1b8dc27da6b0d50e1ff6a9a70df13735861eee31e68b49&req=diIiEMl%2BmYRdW%2FMW1HO4zQE9Jr%2Bz%2Fhz%2FbfNHh%2Fvd8OHvBN0OoFqhoSWq7NZ4%0Aha5RPAuXtp4BdEILY0A%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256004522/a97b91092b393e93b2d7779f63e6/2db86a6d-1582-419e-925e-cbc914468fa1?expires=1788586200&signature=eb9dd1d4f05aaff4f54dc817d7db3989702214481ed42f0e4be740f0852bcb60&req=diIiEMl%2BmYRdW%2FMW1HO4zQE9Jr%2Bz8hL5bfNHh%2Fvd8OHvd%2BXmyvUEZiRa3RIt%0A0MUgZkaK2iW1W4%2F%2BsLU%3D%0A) **Tip:** Using a metadata XML file: Most IdPs let you download a metadata.xml file. Upload it on the identity settings page to auto-fill the Signing Certificate, IdP Entity ID, and SSO URL. Some IdPs (like Entra ID) also include claims information in the metadata file; if present, the system will suggest field mappings automatically. diff --git a/content/support/14503643-set-up-scim-in-claude-for-government.md b/content/support/14503643-set-up-scim-in-claude-for-government.md index 47045b4f0..57af3754e 100644 --- a/content/support/14503643-set-up-scim-in-claude-for-government.md +++ b/content/support/14503643-set-up-scim-in-claude-for-government.md @@ -41,7 +41,7 @@ With SCIM, login and provisioning are separate. Your IdP tells Anthropic who sho **Important**: Store this key securely. It cannot be retrieved after you leave the page. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256040196/c3b045028c4c2edef9172b6fb424/9a71258e-ae73-41e3-83a2-d24a240ac0ae?expires=1788548400&signature=c395b4ef788bfae88bd9788cf4d1175c65123134fea67bde233612918169bd75&req=diIiEMl6nYBWX%2FMW1HO4zSrRlaQabT4QyIvvU1hav7OHlCqYDWR2atAEdQyI%0AaXaqZGMvGvxQSCBIL4A%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256040196/c3b045028c4c2edef9172b6fb424/9a71258e-ae73-41e3-83a2-d24a240ac0ae?expires=1788586200&signature=2e6e8f90b693c46cb4a89dce4d29f281743ee4ee92af39ef26f0f877a603f1cf&req=diIiEMl6nYBWX%2FMW1HO4zSrRlaQaYTAWyIvvU1hav7Oodetd5POBDZijjlrW%0Am6v%2FbXykW24%2BWNoOxPY%3D%0A) ### Step 2: Configure SCIM in your Identity Provider @@ -67,7 +67,7 @@ After enabling the integration in your IdP: **Warning**: When you fully enable SCIM provisioning, any users who were **not** synced via SCIM will be removed from the organization. Confirm that all expected users appear in the sync before proceeding. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256040198/da9188b8b968d5f900cc08e9ceb2/3814ab37-c3fa-4256-8d16-49c1e1b4c654?expires=1788548400&signature=57b89553e8d67fbf34a1397e32c146370074d13aee12c31b0facebea3601108d&req=diIiEMl6nYBWUfMW1HO4zeLvMlBqTkT%2BoWupW8zJgMpfUh2imxSzDZMnqSue%0ALJTUWYH5iFQdAp44x2A%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256040198/da9188b8b968d5f900cc08e9ceb2/3814ab37-c3fa-4256-8d16-49c1e1b4c654?expires=1788586200&signature=9f2cde4d7654d1ce771bb3e32d034ecdfbba45da34f05ab54c12ae9f8811991d&req=diIiEMl6nYBWUfMW1HO4zeLvMlBqQkr4oWupW8zJgMrnscm7RrV3rTVAg7%2Fn%0APFx11KIu9PtrlMA7kSc%3D%0A) ### Step 4: Map groups to roles and seat tiers @@ -83,7 +83,7 @@ SCIM provisioning uses IdP groups to assign roles and seat tiers within Claude f 3. Save your mappings. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256056441/f7eb09bba549e9861fc81b961cc7/2760fa5b-87bb-491f-9354-ca3cd2bc4475?expires=1788548400&signature=b07e6da63a5b32f1a173a470caa860066c7c8741ec2047b761ba070ab3820e45&req=diIiEMl7m4VbWPMW1HO4zaWhsXsntk8fh340B79BYGaTaS26QIXfmaftvLPl%0AtYnod4%2FjifIzdgM5Wpk%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256056441/f7eb09bba549e9861fc81b961cc7/2760fa5b-87bb-491f-9354-ca3cd2bc4475?expires=1788586200&signature=b2ae2efe2452d4fc6b7be26997476bc46b75706d554019b9d6f62a502e667544&req=diIiEMl7m4VbWPMW1HO4zaWhsXsnukEZh340B79BYGZcwr9QsYaWUs0J0p1E%0AVisdV9%2BGxcjcXdvl7qg%3D%0A) If you manage multiple organizations under a single parent (see below), each organization maintains its own role and seat tier mappings. Switch between organizations using the organization selector in the bottom-left corner of the page. diff --git a/content/support/14503775-mcp-web-search.md b/content/support/14503775-mcp-web-search.md index da5438642..1ea745e31 100644 --- a/content/support/14503775-mcp-web-search.md +++ b/content/support/14503775-mcp-web-search.md @@ -4,7 +4,7 @@ The Web Search connector gives Claude the ability to search the public internet For questions about web search in commercial Claude, see **[Enabling and using web search](https://support.claude.com/en/articles/10684626-enabling-and-using-web-search)**. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256120763/7652c6c669446113eae75f3c5977/9c74d57e-aaa2-4f1c-bfe4-2b9b87fd41ab?expires=1788548400&signature=0a8ab0a37de524fa4ce4d2429d36cc33a99e6b3e3adc52e5e47177f06c55ee7a&req=diIiEMh8nYZZWvMW1HO4zQvFLLpWicz8M%2Fw5SJgC29FGU%2BYS%2FlTOODGQYJiY%0Av2LhXv5kgMNVCxJYv7s%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2256120763/7652c6c669446113eae75f3c5977/9c74d57e-aaa2-4f1c-bfe4-2b9b87fd41ab?expires=1788586200&signature=0746fbe2017cb09cbb8ec4719fbad8324a3ed5f8dd016285baa5ae0f8eb9e630&req=diIiEMh8nYZZWvMW1HO4zQvFLLpWhcL6M%2Fw5SJgC29Hc18QM2uqSjzT%2FfP5H%0AGhIONBjAicInLUQKzUg%3D%0A) ## How Web Search differs for Claude for Government diff --git a/content/support/14604397-set-up-your-design-system-in-claude-design.md b/content/support/14604397-set-up-your-design-system-in-claude-design.md index edfa64247..ddcabd338 100644 --- a/content/support/14604397-set-up-your-design-system-in-claude-design.md +++ b/content/support/14604397-set-up-your-design-system-in-claude-design.md @@ -72,7 +72,7 @@ To validate your design system, create a test project and see if the output matc Once you’re satisfied with the design system quality, make sure the “Published” toggle is switched on. After publishing, any projects created from the Claude Design homescreen while in your organization will use your design system instead of the default. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2287527007/b1c46cb8dba4cd7e8bbea85fb0c3/2819c6cf-9ce1-4df5-84c8-feae0164bf2e?expires=1788548400&signature=b49f17f5c8d81d8b64cdfeb77d41780c0ef89cc1ccc6fd5df9c65ce5aae92074&req=diIvEcx8moFfXvMW1HO4zWNHF%2FqOCjMTIQKNMXlu0T98rYExZvX9B7LkL65n%0A7%2F4xY8h%2FHsUexYr%2FwTM%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2287527007/b1c46cb8dba4cd7e8bbea85fb0c3/2819c6cf-9ce1-4df5-84c8-feae0164bf2e?expires=1788586200&signature=a85f851c09f3e65adfb44e77ffbc0e0af50c811959a422891ea4842e3d93b421&req=diIvEcx8moFfXvMW1HO4zWNHF%2FqOBj0VIQKNMXlu0T%2FH3sSxGXkTujp5NbtT%0AdXZVyjeMQRrgUczTtZM%3D%0A) --- diff --git a/content/support/14604406-claude-design-admin-guide-for-team-and-enterprise-plans.md b/content/support/14604406-claude-design-admin-guide-for-team-and-enterprise-plans.md index 7d091fe23..233e84dc0 100644 --- a/content/support/14604406-claude-design-admin-guide-for-team-and-enterprise-plans.md +++ b/content/support/14604406-claude-design-admin-guide-for-team-and-enterprise-plans.md @@ -18,7 +18,7 @@ Team and Enterprise plan admins can enable this organization-wide by following t 2. Find the **Claude Design** toggle under **Anthropic Labs** and switch it on. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2289240025/8a528b6cccc3ea1001c25953cb14/image.png?expires=1788548400&signature=a970f71115a6736ff389c5f218d40fa31cb4eb0c7215d52de0197b416f8f86a0&req=diIvH8t6nYFdXPMW1HO4zahp3eoNHe4hDIPtKBLQ9H8ZZUH8ZCaN6v7fOyXh%0AjHHhprXcoaJotavc5bQ%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2289240025/8a528b6cccc3ea1001c25953cb14/image.png?expires=1788586200&signature=0c68ea6f6851e282dcca6dfdf328308f84117002709c1a43c1dff6bf757c3adc&req=diIvH8t6nYFdXPMW1HO4zahp3eoNEeAnDIPtKBLQ9H%2ForFReV8f%2BGiEjiQiM%0AgtgKIJXr5UdqJ9zH1cQ%3D%0A) --- diff --git a/content/support/14604416-get-started-with-claude-design.md b/content/support/14604416-get-started-with-claude-design.md index e8f0e8a4a..60e1424b2 100644 --- a/content/support/14604416-get-started-with-claude-design.md +++ b/content/support/14604416-get-started-with-claude-design.md @@ -153,7 +153,7 @@ Use the “Export” button in the upper right corner when viewing your project - Send to Claude Code Web -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2287510952/553a03eec5cea7b9eff53b473552/6dc33363-38b1-444e-96bb-f8218b588173?expires=1788548400&signature=ce4961818e26a8c1234648446d60048b45eadbc99c4323f146f1ee1f307447b3&req=diIvEcx%2FnYhaW%2FMW1HO4zQFD4SRfn2Vwnfz9ljnuyXQ4Io74mrDEsTTqF%2FXf%0A7sWy6Cc3JWF40sfkj3w%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2287510952/553a03eec5cea7b9eff53b473552/6dc33363-38b1-444e-96bb-f8218b588173?expires=1788586200&signature=e97b532b0c03ab9ebc8d2f78bbd54ffb53f55caf4aa3de64ec980b9ac0da56a6&req=diIvEcx%2FnYhaW%2FMW1HO4zQFD4SRfk2t2nfz9ljnuyXREKF5SnW6q2N5xi3Zy%0A7%2FUUl7aWVcFfDYsvzO0%3D%0A) You can also share projects within your organization using a shareable link. Sharing options include view-only, comment, and edit access. diff --git a/content/support/15330088-set-a-default-model-for-your-organization.md b/content/support/15330088-set-a-default-model-for-your-organization.md index d67e01a9b..0debf5a40 100644 --- a/content/support/15330088-set-a-default-model-for-your-organization.md +++ b/content/support/15330088-set-a-default-model-for-your-organization.md @@ -50,7 +50,7 @@ The organization default applies to every member. To set it: 4. Click “Save changes.” -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2514722139/d05c94072a41ea9090ecf386c53e/c32ee31d-954a-4551-a2da-91677fbd0b6f?expires=1788548400&signature=fac827bbc1376e280c14219ed3337c435187eeea9258f8e44c5ca08032194f03&req=diUmEs58n4BcUPMW1HO4zelOdzpFKUBDfdGVZ664dGGzuRyNG0FFnA%2BBG2dp%0AQYIwR7Bw1kEpT%2Ftv0bI%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2514722139/d05c94072a41ea9090ecf386c53e/c32ee31d-954a-4551-a2da-91677fbd0b6f?expires=1788586200&signature=a54024b39ca656252e608c7d5fe81fa58a4ab175e0f4f790f33bb6ce845c9aaf&req=diUmEs58n4BcUPMW1HO4zelOdzpFJU5FfdGVZ664dGEMFogCeoQ1nJOby4zY%0AUG0H3CDcdvf1I9hryG0%3D%0A) --- diff --git a/content/support/15425996-data-retention-practices-for-covered-models.md b/content/support/15425996-data-retention-practices-for-covered-models.md index d00efd2d1..dce6f7e3b 100644 --- a/content/support/15425996-data-retention-practices-for-covered-models.md +++ b/content/support/15425996-data-retention-practices-for-covered-models.md @@ -28,7 +28,7 @@ This change only applies to organizations that have set up workspaces with zero ### If your developers use the Claude API -- **Directly from Anthropic through Claude Platform:** Turn on retention for the workspaces where you want to use covered models in the developer console (**Workspace > Manage > Privacy Controls**). Your other ZDR-enabled workspaces keep ZDR. Refer to the **[Anthropic Trust Center for documentation](https://trust.anthropic.com/)**. +- **Directly from Anthropic through Claude Platform:** Turn on retention for the workspaces where you want to use covered models in the developer console (**Workspace > Manage > Privacy Controls**). Your other ZDR-enabled workspaces keep ZDR. Learn how to **[turn on data retention for a Workspace in a zero data retention organization](https://support.claude.com/en/articles/16824617-turn-on-data-retention-for-a-workspace-in-a-zero-data-retention-organization)**, or refer to the **[Anthropic Trust Center for additional documentation](https://trust.anthropic.com/)**. - **Through Claude Platform on AWS:** Retention works the same way as the direct Claude API. It's configured at the workspace level, and retained data is handled by Anthropic under the same controls. diff --git a/content/support/15694740-manage-model-access-for-your-organization.md b/content/support/15694740-manage-model-access-for-your-organization.md index b0dd7cef0..163f82749 100644 --- a/content/support/15694740-manage-model-access-for-your-organization.md +++ b/content/support/15694740-manage-model-access-for-your-organization.md @@ -42,9 +42,9 @@ The organization setting is the ceiling. A role can't grant access to a model th If any custom role uses the model you’re disabling as its default, you’ll be prompted to change that role’s default before the change can be saved. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2514693921/02ea72756f5163f14e5d158516dc/69102088-cd86-498e-97aa-c8a6e0004419?expires=1788548400&signature=6b6aeb52d10bb61c5d343f826d68183dba03f8a8ff08f61e3492e43c5a1fc660&req=diUmEs93nohdWPMW1HO4zXlxEu%2B8U9lTQf5Pb7M2Q0u8YSeGwoSz74BYy525%0A7Cc1sRfCKKOFo831svE%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2514693921/02ea72756f5163f14e5d158516dc/69102088-cd86-498e-97aa-c8a6e0004419?expires=1788586200&signature=32a61e1d80088e3cc655323ac7f42fadca0085458f9730116b7125f2c9e94eb3&req=diUmEs93nohdWPMW1HO4zXlxEu%2B8X9dVQf5Pb7M2Q0vuBHEZS%2BO01e8oHBe9%0AeFSIZBhDK69N0eoU1dU%3D%0A) -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2514693922/bfc5de6626eb19dca1d7caf818ca/c3cd8bb6-f86c-4d01-92da-6ae4ca966662?expires=1788548400&signature=82eae516dbe4a3f7c2c49dac5bd5b7d78b8e74cc93d134730531eced61d70c52&req=diUmEs93nohdW%2FMW1HO4zTqNsYHAQlBTAod9uc510lwh5xKX%2FryswHOCoWQI%0AwigagDucnaEedutm9QY%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2514693922/bfc5de6626eb19dca1d7caf818ca/c3cd8bb6-f86c-4d01-92da-6ae4ca966662?expires=1788586200&signature=b84d6e7fab75eda12fed296ceffbdc1a28bb4bf761e87470736b8b5d5b2a86eb&req=diUmEs93nohdW%2FMW1HO4zTqNsYHATl5VAod9uc510lyxbyAtcg0UzrViBLYd%0AOEXnTI2%2Bs1dd%2BBn9wZw%3D%0A) --- @@ -78,7 +78,7 @@ If any custom role has an effort cap higher than the new organization cap for th Only models the role grants access to can be selected as that role’s default model. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2514693923/880665a87dbd4776cf19d6063a37/29d30c6d-f9fc-408c-8c72-4320c6d88d14?expires=1788548400&signature=49e5209f9ef518265eacc357c4b13fa42902754440da002718e1f6db54d73457&req=diUmEs93nohdWvMW1HO4zYj9Sf0G6Ym5XsqpNqvyFRL2%2B4fYS4KhhcZJR9Si%0ABpfu4OH4UvaDf1TJ1uM%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2514693923/880665a87dbd4776cf19d6063a37/29d30c6d-f9fc-408c-8c72-4320c6d88d14?expires=1788586200&signature=22589e696b196d9d735a8f65e21417506b8a636cd10116eb38f74c4c15d180e2&req=diUmEs93nohdWvMW1HO4zYj9Sf0G5Ye%2FXsqpNqvyFRKblUffJ%2FQK6zKxSebp%0AhH3CYTWPJb%2FccUv3tRg%3D%0A) --- @@ -96,7 +96,7 @@ Effort limits determine how much computation members on a role can apply per res 5. Click "Save" to save your changes. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2514693927/7a25673b3b075d72adb3cdc371e3/d2d7cd8d-a713-4e91-a706-f589ac46a9fe?expires=1788548400&signature=e58d7d496f80f1a15b51bf7ce9c2d348867ee29a6b81334d9973503753350d19&req=diUmEs93nohdXvMW1HO4ze1xBju5d7EdDeA1RkowXUGhKvtlHE3cGFJQmD0s%0A8nt6cmdVWyohE6oor4o%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2514693927/7a25673b3b075d72adb3cdc371e3/d2d7cd8d-a713-4e91-a706-f589ac46a9fe?expires=1788586200&signature=8780b0571bad30985108305a87289a51d41e9cd30ff7441b32bc8f1155c914c9&req=diUmEs93nohdXvMW1HO4ze1xBju5e78bDeA1RkowXUGC7ECpLq6RQuIsTcRk%0AsDGp8wDVp%2B8BPRDpI20%3D%0A) Members on the role see only effort levels at or below the cap in their model menu. Note that available effort levels differ depending on the model, and some models don’t support effort level settings at all. For an explanation of each level, see **[Change the model, effort, and thinking settings](https://support.claude.com/en/articles/8664678)**. diff --git a/content/support/15936181-get-started-with-1password-for-claude.md b/content/support/15936181-get-started-with-1password-for-claude.md index c826c39b7..d9e67ab61 100644 --- a/content/support/15936181-get-started-with-1password-for-claude.md +++ b/content/support/15936181-get-started-with-1password-for-claude.md @@ -52,7 +52,7 @@ Once the requirements are in place, you can set up 1Password from a few places i 4. Toggle on **Password managers**: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2546126596/ba71ca47e2df21cec62c243831f8/5b1c67e1-607d-4c73-8f61-d1ceb081082a?expires=1788548400&signature=d7b641d4b7dcee92cacaa9fd9bf8bce09ac34c21669dd4581999a55f804dab23&req=diUjEMh8m4RWX%2FMW1HO4zU5lnmNrqc1nGkiu4hEpcPVHKWeJAveklQ9cSZi%2B%0AJTWZZOCRCmC8YDeJ3ZA%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2546126596/ba71ca47e2df21cec62c243831f8/5b1c67e1-607d-4c73-8f61-d1ceb081082a?expires=1788586200&signature=5f8230dd5f8e8e3066814363da8dea3d6457f0a809cf7246814ae90e0e694549&req=diUjEMh8m4RWX%2FMW1HO4zU5lnmNrpcNhGkiu4hEpcPWoSbjOgxfah3aL1J13%0AGezSX0AI0TMdiQ4opMc%3D%0A) Once enabled, eligible users will see the discovery options above. Users still need to install and set up the required apps and extensions themselves. diff --git a/content/support/16607638-understanding-your-pro-or-max-plan-invoices.md b/content/support/16607638-understanding-your-pro-or-max-plan-invoices.md index 559b6d882..2f1f22bc7 100644 --- a/content/support/16607638-understanding-your-pro-or-max-plan-invoices.md +++ b/content/support/16607638-understanding-your-pro-or-max-plan-invoices.md @@ -40,7 +40,7 @@ You can also open any invoice from your account: **Amount due.** The invoice total minus any applied balance. This is what your payment method was charged. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2629072970/c514f489b65072ccad08e803864f/e8c7a7de-905f-4a40-815f-c9c66edcdbf6?expires=1788548400&signature=7068c8a08a2ad168fa2c1918162d89620ea71dab25792af4d3870daccba034a9&req=diYlH8l5n4hYWfMW1HO4zdWraBk66lwaPZYKVlMiWEVkVBYurCu%2BgKP%2Brje%2F%0AVfpKURTRROkyalC%2FjBM%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2629072970/c514f489b65072ccad08e803864f/e8c7a7de-905f-4a40-815f-c9c66edcdbf6?expires=1788586200&signature=ce99a9dfd333736c31a3433cd6c04991b82162413e09f890f8da4eac32445c38&req=diYlH8l5n4hYWfMW1HO4zdWraBk65lIcPZYKVlMiWEWVmSQ2Epla%2BNPfIHNP%0AId8GBO52FdtMR6dfLZk%3D%0A) ## Billing details on your invoice diff --git a/content/support/16764810-assign-a-program-to-workspaces-in-claude-console.md b/content/support/16764810-assign-a-program-to-workspaces-in-claude-console.md index 93ad64740..e15335eaf 100644 --- a/content/support/16764810-assign-a-program-to-workspaces-in-claude-console.md +++ b/content/support/16764810-assign-a-program-to-workspaces-in-claude-console.md @@ -20,27 +20,27 @@ In the Console, programs are issued to your organization and apply to workspaces 1. **[Sign in to the Console](https://platform.claude.com/)** as an organization Admin. Go to **[Organization settings > Programs](https://platform.claude.com/settings/organization/programs)**. The program card shows whether it applies automatically or needs workspaces assigned. - ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2642744587/d4584e035604f3b7c08afa53a1c6/ee1183ff-e591-4484-a989-1f754245d39c?expires=1788548400&signature=25c51c4afe9883f0eb348366c68142598949e94d86f45f570de9a156a0885994&req=diYjFM56mYRXXvMW1HO4zT%2FymEGCEAGjktHcEoeKC4fQ1IlG4hfIERM3kLI3%0AiaID%0A) + ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2642744587/d4584e035604f3b7c08afa53a1c6/ee1183ff-e591-4484-a989-1f754245d39c?expires=1788586200&signature=7efa6403b5bb3ce9aa22a35e603450486d32d3fa2bcd2cf60ac109b3184a0af1&req=diYjFM56mYRXXvMW1HO4zT%2FymEGCHA%2BlktHcEoeKC4cD3ZMyJClIHp5VECOn%0Acwd2%0A) 2. Select the program to open its page. The **Workspaces** table shows each workspace's status. A workspace marked with an issue does not meet a requirement yet. - ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2642745562/253e55a3292b35f728fb5dc89fb2/0878a8a9-dce5-4df2-9826-3796605b52a0?expires=1788548400&signature=f2f002bd70ea176fa67a8ff7d9175da71661dcc942cdcd5e72f63fbc33ae0a2a&req=diYjFM56mIRZW%2FMW1HO4zc116gZtRFi1MCr%2B42fbmkZdziEJZ8zVw9RcT%2FCa%0ALk3e%0A) + ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2642745562/253e55a3292b35f728fb5dc89fb2/0878a8a9-dce5-4df2-9826-3796605b52a0?expires=1788586200&signature=800003ad6ef17457a3b38f0b9609f3bd3b5c60102562f5de15326d7e94efde7a&req=diYjFM56mIRZW%2FMW1HO4zc116gZtSFazMCr%2B42fbmkYtIByZVgzgdDB6gKL3%0Ad%2FEy%0A) Hover over the issue to see which requirement is not met. - ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2642746466/c49291119729e99f4dba8ec924e4/3f802c0e-7fbc-4e80-935a-05da58f65bde?expires=1788548400&signature=6afa4698d1243c00e498c8c805668d127b02597719196126a7612e466bdeaf59&req=diYjFM56m4VZX%2FMW1HO4zaveae5nknXEVPpeIJbmktTeG1eVNXrkUNT%2FCKL3%0ANZU7%0A) + ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2642746466/c49291119729e99f4dba8ec924e4/3f802c0e-7fbc-4e80-935a-05da58f65bde?expires=1788586200&signature=32466b1a967e05024a25febb4b153e2904a7f6e806344c2f7c51087ba855add9&req=diYjFM56m4VZX%2FMW1HO4zaveae5nnnvCVPpeIJbmktQW4twE646TmO2lxCPl%0AsluL%0A) 3. To give a workspace access, make it meet the requirements. Open the workspace, select "Manage," then "Programs," and check the **Qualifications** panel. - ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2642768117/1304e6b1350fc9bd88c4238a00e3/db606eb5-39d5-4309-a5a9-ee33847fc233?expires=1788548400&signature=50c9a7c1c2ae4ec6563db91e246c0430c27b517bb27e19d310e4acf891f77edd&req=diYjFM54lYBeXvMW1HO4zTU0lNOVL05D9BWcjfiNKI0tyzS87y0Ad%2FovwjJv%0AWQxU%0A) + ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2642768117/1304e6b1350fc9bd88c4238a00e3/db606eb5-39d5-4309-a5a9-ee33847fc233?expires=1788586200&signature=93159f7301fe75f48dce584a0b5c3de6982ed3460f0d68938438489b65467923&req=diYjFM54lYBeXvMW1HO4zTU0lNOVI0BF9BWcjfiNKI3kPJNNtLzOjOwVA24u%0AAEzv%0A) 4. Fix the requirement. For the Cyber Verification Program, turn on data retention under Manage, then Privacy controls. Then select "Rerun." - ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2642746995/87151a11687a9c631b7a9d681390/d40a6c12-283d-4b3b-b6d6-9f631a73e7c0?expires=1788548400&signature=fee4705d972952f0cfa0388aa27d0bba06ede9ae36fbf900c4ab13c2d91d0feb&req=diYjFM56m4hWXPMW1HO4zQfcHTOr63Yv9apHi%2BiM8ogYthMNCs1jn%2F3u%2BUcc%0AEBED%0A) + ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2642746995/87151a11687a9c631b7a9d681390/d40a6c12-283d-4b3b-b6d6-9f631a73e7c0?expires=1788586200&signature=ff47fc8a707a1c8b0d9934bdb45a9cc2d0f7f112ef457830f21e7de829d229eb&req=diYjFM56m4hWXPMW1HO4zQfcHTOr53gp9apHi%2BiM8ohbX95W%2Bs0LmOai7rCT%0A7KGE%0A) 5. The program shows **Active** for the workspace. - ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2642747200/a18bdccde474c9f4eba371cf6050/b0e9d5e3-1e5f-4f27-b682-5684084f92e8?expires=1788548400&signature=253b9a513f573f217f6f278542bf3135c54fd853e3f16126876de4262abc488d&req=diYjFM56moNfWfMW1HO4zaUR8q5i8vY8fTukdAE3MWsYsxYylvZ6A5oJvohA%0A7ZC9%0A) + ![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2642747200/a18bdccde474c9f4eba371cf6050/b0e9d5e3-1e5f-4f27-b682-5684084f92e8?expires=1788586200&signature=9502924f668a803e79e88eabdcc1b72fbe65c2ed9042cb57c8d5a81d02cd6d3d&req=diYjFM56moNfWfMW1HO4zaUR8q5i%2Fvg6fTukdAE3MWs6sPhhrYSSNAKYg%2Bc5%0AQeRf%0A) ## Troubleshooting diff --git a/content/support/8114491-get-started-with-claude.md b/content/support/8114491-get-started-with-claude.md index a56c478c2..b8f12dc36 100644 --- a/content/support/8114491-get-started-with-claude.md +++ b/content/support/8114491-get-started-with-claude.md @@ -36,7 +36,7 @@ You use **prompts** to communicate with Claude. The best approach is to speak to Type your prompt into the chat interface and click the submit button to start a conversation with Claude. You can click the "+" button in the lower left or type "/" to view additional options and commands: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1916208578/2cf2ea52f1f884084b57983a8805/image.png?expires=1788548400&signature=a7bc9692c6065db298c61c7b8aeaa441757541bb635f9a5ae28c1144df09067c&req=dSkmEMt%2BlYRYUfMW1HO4zV2J7SfPsI%2BF9crMELaMZPwjeZkPWm6wFYr4rAQy%0AiJLO48fN0uuCTPn3KX0%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1916208578/2cf2ea52f1f884084b57983a8805/image.png?expires=1788586200&signature=0402de52a13cff176f355bd155598ac9b9af54b784058887cedc557e89fb2c0c&req=dSkmEMt%2BlYRYUfMW1HO4zV2J7SfPvIGD9crMELaMZPy%2BafZP9hq4pUoGnzix%0A%2FWcG6nyh38K5o7aiYJ0%3D%0A) --- diff --git a/content/support/8230524-delete-or-rename-a-conversation.md b/content/support/8230524-delete-or-rename-a-conversation.md index 0b9e99710..a4972ef77 100644 --- a/content/support/8230524-delete-or-rename-a-conversation.md +++ b/content/support/8230524-delete-or-rename-a-conversation.md @@ -44,15 +44,15 @@ These steps apply to Claude for iOS, listed on the App Store as Claude by Anthro 4. If deleting, tap "Delete" again in the confirmation prompt. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599501318/75c28edc693efbe8befd21e4da64/d18a921a-df4b-4788-833c-12c966a32527?expires=1788548400&signature=936926f11d3f2996b389c73d70edffaff93e25ec210116fd58c9c13624bdc078&req=diUuH8x%2BnIJeUfMW1HO4zSc12aZfjGiv1DBI29QsIlEdp2N2fgu4F0aUcLB3%0Ag6TB7lRtmDkRlebfy8U%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599501318/75c28edc693efbe8befd21e4da64/d18a921a-df4b-4788-833c-12c966a32527?expires=1788586200&signature=68b5277b26ca60e98032620d2854cf222efc770e2669954b83a28394ff4cec04&req=diUuH8x%2BnIJeUfMW1HO4zSc12aZfgGap1DBI29QsIlGx1504IsDDeaswEOnB%0AK9Yo6zy1Mt5ZsXn9Jm8%3D%0A) -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493852/2e58b92d18f307bb79ae30650f26/1bbe52f3-202b-4d5d-9f9a-eeda4d6952c3?expires=1788548400&signature=7ccd73176becbb4ffb531bc106fb4551f30364571bca1f0f4d78646dfef371bd&req=diUuH813nolaW%2FMW1HO4zTjXMu%2BJKsjhj7blKEDtUI2KTatoYj1XIyZY4Zrk%0AZX4z27yVFzuyWFNkQaU%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493852/2e58b92d18f307bb79ae30650f26/1bbe52f3-202b-4d5d-9f9a-eeda4d6952c3?expires=1788586200&signature=64b5e45c37e4480de5d0d3d7d703093a7fed2ecb20033a90e23ee6f8d149277b&req=diUuH813nolaW%2FMW1HO4zTjXMu%2BJJsbnj7blKEDtUI2kZNn%2FL1U3Q8pjcbk3%0AY1ph%2BlZ9ZJmPkvRGsD0%3D%0A) You can also delete the conversation you have open: tap the "⋯" button in the top right corner, tap "Delete," then confirm. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493848/997184c386d0e6fb0bd2d7c1f2b6/5d2bc394-25fc-4814-8c2a-2f54d004f83f?expires=1788548400&signature=cfb580d4fdc913b8d9f8516dba5a719aacb5a9ab73513b38fe20a2434739f88a&req=diUuH813nolbUfMW1HO4zVCIqpLKz9RCzQl%2BKgU984yoc%2BdSEYNXzbuv%2BfRr%0AALvNkEukSXxYk6WrxZ0%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493848/997184c386d0e6fb0bd2d7c1f2b6/5d2bc394-25fc-4814-8c2a-2f54d004f83f?expires=1788586200&signature=15d102ab13f1b881097d10bca73727e1ca5008b97c306ca43f7b66d44847b88d&req=diUuH813nolbUfMW1HO4zVCIqpLKw9pEzQl%2BKgU984w0yTaz4Kd5%2F4xD0Frc%0AcbJ1porw%2F0QaQccFblw%3D%0A) -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493856/799041da9fa918e90068c5ebf5bd/2e8d5cee-c45a-41d7-a14b-486e50a37f88?expires=1788548400&signature=50013ee438d2030f4210ac14cc14d89180c1fdab6342eba44e1810d64b80fc40&req=diUuH813nolaX%2FMW1HO4zVCl4AD31W1JEDIU8RT6jk3H9wWzCuRj8243WRpz%0AJ65gjHum7OuRprZ2Mwc%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493856/799041da9fa918e90068c5ebf5bd/2e8d5cee-c45a-41d7-a14b-486e50a37f88?expires=1788586200&signature=8062cf539a204d42764fa4146bfdf542832422fb15e878b282b6d8f1557ef0b4&req=diUuH813nolaX%2FMW1HO4zVCl4AD32WNPEDIU8RT6jk1hltkFcbNOca9EL4ek%0AWEaSJbH7RZUbl91WMQE%3D%0A) ## Delete or rename a conversation on Claude for Android @@ -66,9 +66,9 @@ These steps apply to the Claude for Android, listed on Google Play as Claude by 3. If deleting, tap "Delete" again in the confirmation prompt. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493850/a64e6561222d535f2f5bd03e71f0/5de429c2-d8ed-4e8a-89e8-a13ccaa49767?expires=1788548400&signature=b980ee7f8d266108551c5586a813817d9986c6c4dc808e692fe1e6e58fab9af3&req=diUuH813nolaWfMW1HO4zVTdd9opxlhxrqtc0YNNUtKFlL9T%2Bj5Fdu9%2FCa%2FK%0A4CR8DdGkHzpI1FcWlvg%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493850/a64e6561222d535f2f5bd03e71f0/5de429c2-d8ed-4e8a-89e8-a13ccaa49767?expires=1788586200&signature=2dfde2988c28d1905f158b6e253399cc9884c5e191ad88e1330060c22d2a241c&req=diUuH813nolaWfMW1HO4zVTdd9opylZ3rqtc0YNNUtKiLzLzJDe6uQB9itrl%0Ak7u0b4Ia9GkCYIPR6fc%3D%0A) -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493851/f21b39c60e88050d4b0745325f0d/0a8c0d08-dc53-4ef1-8d9f-2b995242c1f9?expires=1788548400&signature=700e662fc9a4c40bed05c52dc30f8350a84c7e101b6972dada9d7429ab894a3f&req=diUuH813nolaWPMW1HO4zUYvw10OpjZY%2FjekULCQNzU3R6g3aPvXc3nAXJJN%0AmNzuuHSPDdriqFiM6YU%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493851/f21b39c60e88050d4b0745325f0d/0a8c0d08-dc53-4ef1-8d9f-2b995242c1f9?expires=1788586200&signature=ddf441924aaadfaef0d953f151b0745a0b7b8f4c98249a295089b1ffe179121d&req=diUuH813nolaWPMW1HO4zUYvw10Oqjhe%2FjekULCQNzVirX6jSw0%2Br5%2BmsgVx%0ADFnvXydoCWOXwKvugyo%3D%0A) **To delete multiple conversations at once:** @@ -78,9 +78,9 @@ These steps apply to the Claude for Android, listed on Google Play as Claude by 3. Tap the trash icon, then tap "Delete" in the confirmation prompt. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493849/3013a0ab921337b4544f7ffeffa6/e828ec14-fb52-4205-a840-707b6f2a848d?expires=1788548400&signature=f868b4aa087c3a2fcf9745ee31722e154c7f515c8edbfcdaf235b00d34207d53&req=diUuH813nolbUPMW1HO4zWGamM9xfoXb4AqhTnZa84UyfErgxBEEFQ8bSK0r%0AJtLX9xRMWXIz92MYH3I%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493849/3013a0ab921337b4544f7ffeffa6/e828ec14-fb52-4205-a840-707b6f2a848d?expires=1788586200&signature=72224060ac1c8a2ec7495dc09e777d10326f80d2430f708d59b34294b1dafeee&req=diUuH813nolbUPMW1HO4zWGamM9xcovd4AqhTnZa84UZSlZzhZECY14CAakr%0ADXepZ7tStz2d6jVeTN8%3D%0A) -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493853/e2507f53cce8a26776a22a457b1a/bd79bb8a-b078-420f-a4e1-75590367aa80?expires=1788548400&signature=3f74bae75c20efafcca02cc05454cf3a4a2f4cd4dd8ec449b9a5c48bfed96df2&req=diUuH813nolaWvMW1HO4zQTtEx30wEg8SBGfF3I2bRjaEe3Pr%2Fa6e2dc7Rgt%0A%2FnBvUyFl9vXXQzyUusY%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2599493853/e2507f53cce8a26776a22a457b1a/bd79bb8a-b078-420f-a4e1-75590367aa80?expires=1788586200&signature=43447fc1d553308a9baa9e0e2cdcf5781b330aaf877c228f8f986d40490950e1&req=diUuH813nolaWvMW1HO4zQTtEx30zEY6SBGfF3I2bRgxmDE4oa5G5jL%2BovvW%0AejpEFi7LCM3j4%2BHzg9M%3D%0A) ## What happens when you delete a conversation diff --git a/content/support/8325618-paid-plan-billing-faqs.md b/content/support/8325618-paid-plan-billing-faqs.md index 198c8ffe6..9fb244a74 100644 --- a/content/support/8325618-paid-plan-billing-faqs.md +++ b/content/support/8325618-paid-plan-billing-faqs.md @@ -50,7 +50,7 @@ There's no separate option to remove a card, and updating to a new card replaces If you want to use a name other than the one tied to your payment method, check the "Use a different name on invoices" box when adding or updating your payment method in **[Settings > Billing](https://claude.ai/settings/billing)**. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1922141785/666191101c11030b05f03a668a74/image.png?expires=1788548400&signature=50962bb8bc54e67bee811b6c4cec8e4df5c7c6013ed3a343cd8213303bb87ff7&req=dSklFMh6nIZXXPMW1HO4zVXW8GWubzvIQoNvNFTb5cfDO2l8jvI8gOO52a2v%0AJhVIqSjOGD0Sp3%2BHN1g%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1922141785/666191101c11030b05f03a668a74/image.png?expires=1788586200&signature=ab261e1c3e223e2fe2a658d2bbc4ca2141e58657add1bbb4f0a9c1a0dd2986a7&req=dSklFMh6nIZXXPMW1HO4zVXW8GWuYzXOQoNvNFTb5cc%2FwOj43M2bAfr5hJ08%0ArAmGoTIoii%2Fy1ycw0SY%3D%0A) ## How can I edit a paid invoice? diff --git a/content/support/8887527-customizing-your-appearance-settings.md b/content/support/8887527-customizing-your-appearance-settings.md index 472b3f253..0fed25dfe 100644 --- a/content/support/8887527-customizing-your-appearance-settings.md +++ b/content/support/8887527-customizing-your-appearance-settings.md @@ -8,7 +8,7 @@ 3. Select from Light, Match System, and Dark under **Color mode**. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1648260417/d478c757c7115ad58a12026d4caf/AD_4nXc__Qop4X9hknWGfGj_y_DCpLutLruhxIclJIfir0ilsgNMg7X8ksIVnqk1Oce5FKlGIOYu9CKbVsu8DqD7iIY2aC0ZfXMyFTeAdNq-Cao2mXcj_WUpNF0kM2HoYR_dEx6N_cuJow?expires=1788548400&signature=8b09fa1bc344536a6b0ba14d2586bfa8136b4b85c0de30e0cd58dbc2fc7cfc40&req=dSYjHst4nYVeXvMW1HO4zc2jJ6o4hIPgSBkgeTglJrr1QGYP1FQCsNMDy6Sw%0ACfZPuPuy4%2Bl%2BUWUAb%2FA%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1648260417/d478c757c7115ad58a12026d4caf/AD_4nXc__Qop4X9hknWGfGj_y_DCpLutLruhxIclJIfir0ilsgNMg7X8ksIVnqk1Oce5FKlGIOYu9CKbVsu8DqD7iIY2aC0ZfXMyFTeAdNq-Cao2mXcj_WUpNF0kM2HoYR_dEx6N_cuJow?expires=1788586200&signature=fba319229fa6f65571110349d40becd59617533ebea0dc35d9212b8a4a5bdafe&req=dSYjHst4nYVeXvMW1HO4zc2jJ6o4iI3mSBkgeTglJroE5AfEo42%2FS6exySBa%0AAJF8f5pKF1EuCs%2B0k3A%3D%0A) ## How to change your font @@ -16,10 +16,10 @@ 2. Select from Default, Match System, and Dyslexic Friendly. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1648260416/7fc0803d44d8de40f8e6636b2eb6/AD_4nXf0UEDa1i2QmqlQtoB5BgpQ-FfZVzss_7wMVQdvkmEDSfoTxixnG0GSxC6qrOs21HdkXH-I2Yn_GHDAf8yjd6FJtoh9FadALozvIErFp9r8LychDGLPb7OpN1CN4PRcgVAYNCre?expires=1788548400&signature=534568096814105de11a8e0aa2338713880c457f8eec58a87ca62b736231e8b8&req=dSYjHst4nYVeX%2FMW1HO4zc8962jgWXk4QtNFlF5%2FHEfnES9me1S1YW%2F6NSRX%0APqSdFrUpWRt8IVZ4nfg%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1648260416/7fc0803d44d8de40f8e6636b2eb6/AD_4nXf0UEDa1i2QmqlQtoB5BgpQ-FfZVzss_7wMVQdvkmEDSfoTxixnG0GSxC6qrOs21HdkXH-I2Yn_GHDAf8yjd6FJtoh9FadALozvIErFp9r8LychDGLPb7OpN1CN4PRcgVAYNCre?expires=1788586200&signature=c700ab1ee97af309408801621427081b1a8381fd37b8ff21d98c6a89a49c32ae&req=dSYjHst4nYVeX%2FMW1HO4zc8962jgVXc%2BQtNFlF5%2FHEcsc3pbbdP8TmlVS%2FMt%0Aq%2FY6m2l5IrvWCuoT8A8%3D%0A) ## Can I disable the sidebar? It's not currently possible to completely disable the sidebar. You can click the button on the top right of the sidebar to open or close it. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1941108004/5217903737ddd9bb62fe5d7a904c/CleanShot+2026-01-14+at+09_12_58.png?expires=1788548400&signature=564a4d64c0e04e2d2467fb0534cf4ff5d39a5575d1e55e6034b929302e9d8efe&req=dSkjF8h%2BlYFfXfMW1HO4zUS%2BB1fzXXPrylfYa7uDb9lvkTK4yaHFCXzYDyHp%0A86o8mHeZ7jD3lH0Fhgo%3D%0A) \ No newline at end of file +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1941108004/5217903737ddd9bb62fe5d7a904c/CleanShot+2026-01-14+at+09_12_58.png?expires=1788586200&signature=5bcc890159d2fc9adf93e2a2c0db07b4a910054f0500f9bf4f44d3a42ca92492&req=dSkjF8h%2BlYFfXfMW1HO4zUS%2BB1fzUX3tylfYa7uDb9mnWbdi%2BZ2%2FokrU9OOm%0AxZNBvmNEJTxXxF1x6Uk%3D%0A) \ No newline at end of file diff --git a/content/support/9267400-move-your-personal-claude-account-to-a-team-or-enterprise-organization.md b/content/support/9267400-move-your-personal-claude-account-to-a-team-or-enterprise-organization.md index 79e3b14e6..676cd2567 100644 --- a/content/support/9267400-move-your-personal-claude-account-to-a-team-or-enterprise-organization.md +++ b/content/support/9267400-move-your-personal-claude-account-to-a-team-or-enterprise-organization.md @@ -126,7 +126,7 @@ For the full walkthrough of your options, deadlines, and what happens to your su You may have both a personal account and an organization account tied to the same email address. You can switch between them by clicking your initials or name in the lower left corner of the screen. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312193347/712f763fc290b2488c103849f20c/0c135a6f-3442-4ee1-9ab7-98673f03ef6e?expires=1788548400&signature=9fc768498f38989a73d073d0be3424f8c91c24c23cd9a737998f438a1e1b97fd&req=diMmFMh3noJbXvMW1HO4zXhPndgzzBdlufhmlOXMdYZv3X%2FhWXm2U68vx%2Fum%0ApE0YLM4RdGSOruuuTAQ%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2312193347/712f763fc290b2488c103849f20c/0c135a6f-3442-4ee1-9ab7-98673f03ef6e?expires=1788586200&signature=474c2b8554f9d76e23f56c406b4ecf83c86039e635fd2d3eaa34c05fa86748f9&req=diMmFMh3noJbXvMW1HO4zXhPndgzwBljufhmlOXMdYaRAb7TN%2FA5rxx5%2BArA%0AArfBqq7kn%2B9ThKl4jyU%3D%0A) A blue checkmark shows which account you're currently using. Click the other account to switch to it and access its separate conversations and projects. diff --git a/content/support/9519189-manage-project-visibility-and-sharing.md b/content/support/9519189-manage-project-visibility-and-sharing.md index 4f7b079b3..a48614baa 100644 --- a/content/support/9519189-manage-project-visibility-and-sharing.md +++ b/content/support/9519189-manage-project-visibility-and-sharing.md @@ -12,7 +12,7 @@ When creating a project on a Team or Enterprise plan, you can choose between two - **Private:** Only invited members can view and use the project. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1740370991/2b6b16e5deff094e073a5b4bb0ea/63197103-24c0-41e5-aebd-9b8f431837bb?expires=1788548400&signature=a7af8c8ed3c44dbed7efb09c5430eabea5fbaa2050b989e717222555bdee726d&req=dScjFsp5nYhWWPMW1HO4zd3a2VQhIIajHK95%2FTFaPyl21qWrCRTZCGo3dSiO%0ALjzWIJEafXdqYz7%2FbAc%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1740370991/2b6b16e5deff094e073a5b4bb0ea/63197103-24c0-41e5-aebd-9b8f431837bb?expires=1788586200&signature=8b54913eb0ee6dbd4dad3dc2d58876740b49787560b72cd8e36718216f996de7&req=dScjFsp5nYhWWPMW1HO4zd3a2VQhLIilHK95%2FTFaPymdPQAPowEGYKSs4Zfb%0AuRmt3SXxCeGyidn2BMI%3D%0A) ## What are public projects? @@ -22,11 +22,11 @@ If you choose to share a project with the rest of your organization upon creatio Yes, you can switch the visibility of a project you created as public to private at any time by opening the project and clicking the “Share” button to the right of the project name: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1740370987/5d5db997e6b42e627ffa62fddf75/4823906b-9535-4a19-b89e-a1003f1e6e68?expires=1788548400&signature=97db7ee4f52e778c33e68197dfcba58f6f23d4812509c8f66f4eee4654ec8c08&req=dScjFsp5nYhXXvMW1HO4zUiDoiHyhQ4tE8Kp5wh0MSBOlagwiTuqk1FnyjzQ%0Axm1NFrsUUyZxO5CdWJQ%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1740370987/5d5db997e6b42e627ffa62fddf75/4823906b-9535-4a19-b89e-a1003f1e6e68?expires=1788586200&signature=4de0dea060381162669e761c74db2df3a0b08648f9fa4e0e262b38974102e03d&req=dScjFsp5nYhXXvMW1HO4zUiDoiHyiQArE8Kp5wh0MSBnR7179Y%2BCNcMAbfii%0AEslTyZsk7%2FpYAe3wVp8%3D%0A) Click “Everyone at [your organization]” under **General access** and select “Only people invited” to change the project from public to private: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1740370988/386407facbf3e73d2f5538623a18/69d8ffcd-e1ca-470f-a219-5b88704e41f2?expires=1788548400&signature=06a40e6d83b8332aabf5605434f54bc37f8a257b73ef6a619d33a04d7219de30&req=dScjFsp5nYhXUfMW1HO4zckCIfpnZiqgl3XeGelDRW0RMBptnrTK42%2Fmb%2FeC%0Amjl6Df4h%2FZvd62agl4E%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1740370988/386407facbf3e73d2f5538623a18/69d8ffcd-e1ca-470f-a219-5b88704e41f2?expires=1788586200&signature=643bfb4cf8d0af2cdcaa3b30f6004b146712d04167cb07d3b441a1f10354caff&req=dScjFsp5nYhXUfMW1HO4zckCIfpnaiSml3XeGelDRW0EERJm4iFRSRUEbDxj%0AAhyrgKuCqRoFuQW46Rw%3D%0A) ## What are private projects? @@ -36,11 +36,11 @@ Choosing “Only people invited” keeps your project private so that you are th Yes, you can switch the visibility of a project you created as private to public at any time by opening the project and clicking the “Share” button to the right of the project name: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1740370989/f829dcd8bdd88e944322f678323f/9d25eff1-6df3-40be-82eb-ba7fe09187e8?expires=1788548400&signature=b5a9a29a06ff5cadc1b646a57d2d09bcddb97ecff76c49140b1aa850530f3784&req=dScjFsp5nYhXUPMW1HO4zaSEGluZTrAJ2JrJefVtywnVMHF%2F7PdgejF7SDAJ%0Aohd1gZCbVIW02vK%2FmK8%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1740370989/f829dcd8bdd88e944322f678323f/9d25eff1-6df3-40be-82eb-ba7fe09187e8?expires=1788586200&signature=b52637291afb11bb6e729d704c09622ff49489baeee037586d237766da60a956&req=dScjFsp5nYhXUPMW1HO4zaSEGluZQr4P2JrJefVtywncK7CxXmOYnovBTVLU%0A18ZkWhiqmC3iBlucfwg%3D%0A) Click “Only people invited” under General access and select “Everyone at [your organization]” to change the project from private to public: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1740370990/d173fbc6f030780d30c6d7b8e204/7e47b9d1-89fe-4607-8b5b-f7b06e7ad0d6?expires=1788548400&signature=14b54442cdc093ef15d62979cb309373a5a7b72a425145046b522235ee66a016&req=dScjFsp5nYhWWfMW1HO4zT7Q08C%2BuQQSAmYRPrgMBZlk%2Fet5MGpHNbR%2BOOKV%0AXE1sTWbfAv7ASMH4QC8%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1740370990/d173fbc6f030780d30c6d7b8e204/7e47b9d1-89fe-4607-8b5b-f7b06e7ad0d6?expires=1788586200&signature=92a8872becbb3cae8735cd78c57b7b1ddc4cf97e96bccc7a59c2c3b21f790fcd&req=dScjFsp5nYhWWfMW1HO4zT7Q08C%2BtQoUAmYRPrgMBZlbLRcC2Kb8XVd610eJ%0AI7dnoCrkAgQFE2GAqDM%3D%0A) ## Add and remove access to private projects diff --git a/content/support/9534590-cost-and-usage-reporting-in-the-claude-console.md b/content/support/9534590-cost-and-usage-reporting-in-the-claude-console.md index 8165c0595..424ede782 100644 --- a/content/support/9534590-cost-and-usage-reporting-in-the-claude-console.md +++ b/content/support/9534590-cost-and-usage-reporting-in-the-claude-console.md @@ -8,7 +8,7 @@ The Claude Console provides detailed cost and usage reporting to help you effect Users with access to these reports can click into them on the left navigation menu on the Console: -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1584654217/db0a977417e38e43639f060d96e0/image.png?expires=1788548400&signature=2862067ca547a05a52f6de379fff1d475ad526a3dff2579c7331d5d00e6ae018&req=dSUvEs97mYNeXvMW1HO4zYCWiSwdhc6euqqBX2puyxT5PmgLW9mHic20LBTm%0AOHnkyWuNqisaC8vIp2U%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1584654217/db0a977417e38e43639f060d96e0/image.png?expires=1788586200&signature=43810dd0fa273c8c35bb047ae572dbb13ab0dba210fc3fb8cfda1581354ad9db&req=dSUvEs97mYNeXvMW1HO4zYCWiSwdicCYuqqBX2puyxQYdoodA6A%2BptmEdG6%2F%0AXieRHzdfKb6TyL5CXQs%3D%0A) --- @@ -46,9 +46,9 @@ The [Usage page](https://platform.claude.com/usage) offers a detailed breakdown 6. Use the export button to download a CSV of the displayed data. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1584664321/59b50eba0b61e0789f7055fcf9f4/image+%285%29.png?expires=1788548400&signature=6e89961e5759f3da13ce3b5cf4661dca03e00576a9c5a4afc32d9496556b905c&req=dSUvEs94mYJdWPMW1HO4zQwER3svJYdiqMITUZbanFDx82UKeMqjgeu44Q9f%0AtWanhwJjSwDk0vnWtF4%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1584664321/59b50eba0b61e0789f7055fcf9f4/image+%285%29.png?expires=1788586200&signature=72755c25312dd470afb496a2dd2490ce74852c09abc5ce16464fc4c5bf5895a1&req=dSUvEs94mYJdWPMW1HO4zQwER3svKYlkqMITUZbanFB4wkRSNBuptUOoMthy%0A%2By9BjDpXJ2xp0PANN4k%3D%0A) -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1584693386/aed472efe163abcbc14fa32f3699/rate+limited+requests.png?expires=1788548400&signature=fa5e47a0c1c3ce6cbd6b1befe0572c0cdd52f727f2e0082b1834630a6ff53ee7&req=dSUvEs93noJXX%2FMW1HO4zRxEwWNI4llo21D6pckxWMaONmoqz7p2QYnatBKu%0AUgEPNDkcSDubvjNsbD8%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1584693386/aed472efe163abcbc14fa32f3699/rate+limited+requests.png?expires=1788586200&signature=1ca7c6b4fb6a5cfb5599ecd9f028a66fba468d7ae7ae0f260af9391911606c3a&req=dSUvEs93noJXX%2FMW1HO4zRxEwWNI7ldu21D6pckxWMaNagCC0N3u3OFQCnW8%0AEMsTzQDeDi3IOost5ck%3D%0A) ### Rate Limit Use @@ -88,6 +88,6 @@ The [Cost page](https://platform.claude.com/cost) helps you understand your spen 5. Use the export button to download a CSV of the cost data. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1584679401/4d0bc8ed08625e1adee414e77030/CleanShot+2025-06-23+at+08_54_40%402x.png?expires=1788548400&signature=432271d49f5bbd3bd08b5c03f33a7466576923162a0908562d0dc6efe3b5e427&req=dSUvEs95lIVfWPMW1HO4zUR%2Bh5TGV9hlCyIF5nuUsbxC1caIOlpT5GGz6jhy%0AaLnXarD70G5vUSQ6zpc%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1584679401/4d0bc8ed08625e1adee414e77030/CleanShot+2025-06-23+at+08_54_40%402x.png?expires=1788586200&signature=90b00a3c008ad79844e28012d315cc6c792f0a73a1976c314801995c2e0a14ee&req=dSUvEs95lIVfWPMW1HO4zUR%2Bh5TGW9ZjCyIF5nuUsbyfIbtq7sCFsKQ1bn6u%0A2mFA2bpvp88Pp0uwJBc%3D%0A) **Note**: Currently, it's not possible to break down usage or cost by individual users. \ No newline at end of file diff --git a/content/support/9547008-publish-and-share-artifacts.md b/content/support/9547008-publish-and-share-artifacts.md index 9c5d21844..994e6e23f 100644 --- a/content/support/9547008-publish-and-share-artifacts.md +++ b/content/support/9547008-publish-and-share-artifacts.md @@ -56,11 +56,11 @@ Publishing also adds the artifact to the **[Artifacts](https://claude.ai/artifac After publishing, you'll see a “Get embed code” button. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1951684960/0cd917c4455b31e86b70a97f8234/image.png?expires=1788548400&signature=a8e3dba524462dddfc43fe197ddd1f95efe307db8663a7bf4acabd6949a87e60&req=dSkiF892mYhZWfMW1HO4zdcpD15X4QuFR8xgMH3ra8isK50k5ELipwTshzgN%0ANcd4re0g%2Bq%2BXNVe1Qpc%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1951684960/0cd917c4455b31e86b70a97f8234/image.png?expires=1788586200&signature=0a386e9538d21798e2b68b736eafb62058fed5bc7a77e20d899361addb6fe258&req=dSkiF892mYhZWfMW1HO4zdcpD15X7QWDR8xgMH3ra8hrUh14lQIp4mXip33z%0AMo9F8ShUC1X5Z2w4%2F3s%3D%0A) Click it to open a modal with automatically generated code you can copy and paste to embed your artifact on another website. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1951685860/6bf1aa2c57d6ff95804797779e9c/image.png?expires=1788548400&signature=b21cbbe753dafd53cbbc480266a9805a35661137aa89363e8c4564f5677015ff&req=dSkiF892mIlZWfMW1HO4zcqH79GGzYxpf3CUbx4Ru6Uy1iXHyKQVNP2h3U%2F4%0AYTvM8U80XGS1cyitpSo%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1951685860/6bf1aa2c57d6ff95804797779e9c/image.png?expires=1788586200&signature=21dc6c07145703f30670cc129512b677968c846a41b3dd3028e56d82488b9ffa&req=dSkiF892mIlZWfMW1HO4zcqH79GGwYJvf3CUbx4Ru6Vfug%2FBhHRmVlcDvwo%2F%0ADUalWnwd3sZ80Y0Uxms%3D%0A) You must specify which websites can embed your artifact by entering URLs in the **Allowed domains** field, separated by commas. @@ -116,7 +116,7 @@ Artifacts created on Team or Enterprise accounts can only be shared within your 4. Click “Share & copy link” to make this version shareable. -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1951680160/d5a38784df4c6d0cc55eda339279/Screenshot%2B2025-10-28%2Bat%2B2_00_15-E2-80-AFPM.png?expires=1788548400&signature=22865f44de7a77f771757f3dc3c29cbd3f997ec429f51eafb9fe4aa48bb34fe6&req=dSkiF892nYBZWfMW1HO4zbvYOlngKXGXK6hAzMpXfmPpJe4qO1%2B8mFC58VWQ%0AVTqznIFgxXV4O4AbcCk%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1951680160/d5a38784df4c6d0cc55eda339279/Screenshot%2B2025-10-28%2Bat%2B2_00_15-E2-80-AFPM.png?expires=1788586200&signature=6375495341e2d31196cb4580df02119750002cf1ac00c434e8b15e9159fbc602&req=dSkiF892nYBZWfMW1HO4zbvYOlngJX%2BRK6hAzMpXfmNFIZ%2B%2BWtwPaM1Kj4Py%0ANh3ZaZ6tEJsM6fZNl1c%3D%0A) ### Who can access shared artifacts @@ -138,7 +138,7 @@ When you share an artifact, viewers also gain access to any attachments and file 2. In the **Artifact shared** modal, click “Unshare.” -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1951676927/c66153a2c075c6a64404306aefd0/Screenshot%2B2025-10-28%2Bat%2B1_58_24-E2-80-AFPM.png?expires=1788548400&signature=7e8cfdb7453c60b57399ceb29b97599130e173690c235d5b67f16f6747d90a20&req=dSkiF895m4hdXvMW1HO4zW9EwgG4%2FXy3gj8mTHivCKY0efzcHO0%2FMiYi4eSQ%0ASBzcKiXbZ86g7NrCLmM%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/1951676927/c66153a2c075c6a64404306aefd0/Screenshot%2B2025-10-28%2Bat%2B1_58_24-E2-80-AFPM.png?expires=1788586200&signature=fc9f4a76e6290e970c0c7ad78b3450d3a7461c6f94e8a4cb679b307f84bbbf75&req=dSkiF895m4hdXvMW1HO4zW9EwgG48XKxgj8mTHivCKYqsT%2FkT1mOznxhKqqQ%0Ao%2FT0IV7tBf21mxi%2FWz4%3D%0A) --- diff --git a/content/support/9927533-disable-public-projects-for-your-organization.md b/content/support/9927533-disable-public-projects-for-your-organization.md index 55b517982..94ca028f7 100644 --- a/content/support/9927533-disable-public-projects-for-your-organization.md +++ b/content/support/9927533-disable-public-projects-for-your-organization.md @@ -10,7 +10,7 @@ Follow these steps: 2. Find **Public projects** and toggle it off -![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2053902291/8c39d1a79dedc97411eed54dec5c/CleanShot+2026-02-11+at+11_25_34%402x.png?expires=1788548400&signature=91d34bd5d18a517337060ca5bcee56ea463a67d0f98389396645ed5493c3e5c2&req=diAiFcB%2Bn4NWWPMW1HO4zfGib2%2BhbwhbYabJlVJ9VPwgE2j8bBYQZfRSCoVE%0AMSSAHyGhJfjYXfXio5U%3D%0A) +![](https://downloads.intercomcdn.com/i/o/lupk8zyo/2053902291/8c39d1a79dedc97411eed54dec5c/CleanShot+2026-02-11+at+11_25_34%402x.png?expires=1788586200&signature=49f559df71f91e981fa1759548938979d8665ba32c9acb6187399af0172c3a4c&req=diAiFcB%2Bn4NWWPMW1HO4zfGib2%2BhYwZdYabJlVJ9VPx%2FdAKzwJwxY7CDU0dc%0A2BaPc9D8S4CHTjxGrwU%3D%0A) ## How does disabling public projects work? diff --git a/discovery.json b/discovery.json index 1101f541e..d9c9e2877 100644 --- a/discovery.json +++ b/discovery.json @@ -1,7 +1,7 @@ { "version": 1, "note": "What the last full run could see outside sources.json. Written by the fetcher so a new source arrives as a diff a human reviews, not as a line in an Actions log nobody reads. Stable facts only: a change here is always news. `review` is the actionable list \u2014 domains we could archive today and do not.", - "updated": "2026-09-04", + "updated": "2026-09-05", "domains": { "anthropic.com": { "status": "frozen", diff --git a/tombstones.json b/tombstones.json index 433e6fbb3..ba9f3373e 100644 --- a/tombstones.json +++ b/tombstones.json @@ -1,7 +1,7 @@ { "version": 1, "note": "URLs confirmed gone upstream. Kept so a page that died once does not report as a fresh failure on every later run, which would bury the failure that is actually new. An entry clears itself if the URL answers again -- but only while something still probes it. Entries whose local file was removed are no longer fetched, so they stay as a record of the restructure rather than a live check.", - "updated": "2026-09-04", + "updated": "2026-09-05", "urls": { "https://claude.com/docs/claude-science/annotations": { "since": "2026-09-01", @@ -663,6 +663,10 @@ "since": "2026-08-25", "reason": "HTTP 404" }, + "https://support.claude.com/en/articles/13163666-holiday-2025-usage-promotion": { + "since": "2026-09-05", + "reason": "HTTP 404" + }, "https://support.claude.com/en/articles/13371040-logging-in-to-your-console-account": { "since": "2026-08-25", "reason": "moved -> https://support.claude.com/en/articles/13371040-log-in-to-your-console-account"