Claude Platform Docs

Kunci Eksternal

Buat Kunci Eksternal
BetaExternalKey Beta.Organization.ExternalKeys.Create(parameters, cancellationToken = default)
POST/v1/organizations/external_keys

Membuat konfigurasi kunci eksternal yang dimiliki oleh organisasi pemanggil.

Daftar Kunci Eksternal
ExternalKeyListPage Beta.Organization.ExternalKeys.List(parameters, cancellationToken = default)
GET/v1/organizations/external_keys

Menampilkan daftar konfigurasi kunci eksternal di organisasi pemanggil.

Dapatkan Kunci Eksternal
BetaExternalKey Beta.Organization.ExternalKeys.Retrieve(parameters, cancellationToken = default)
GET/v1/organizations/external_keys/{external_key_id}

Mengambil satu konfigurasi kunci eksternal di organisasi pemanggil berdasarkan ID.

Perbarui Kunci Eksternal
BetaExternalKey Beta.Organization.ExternalKeys.Update(parameters, cancellationToken = default)
POST/v1/organizations/external_keys/{external_key_id}

Perbarui sebagian konfigurasi kunci eksternal. Field yang dihilangkan dibiarkan tidak berubah.

Hapus Kunci Eksternal
ExternalKeyDeleteResponse Beta.Organization.ExternalKeys.Delete(parameters, cancellationToken = default)
DELETE/v1/organizations/external_keys/{external_key_id}

Menghapus konfigurasi kunci eksternal.

Validasi Kunci Eksternal
ExternalKeyValidateResponse Beta.Organization.ExternalKeys.Validate(parameters, cancellationToken = default)
POST/v1/organizations/external_keys/{external_key_id}/validate

Validasi konfigurasi kunci eksternal terhadap KMS pelanggan.

Models
class BetaAwsExternalKeyConfig { Type = "aws"; KmsArn; Region; RoleArn; }
JsonElement Type = "aws"
required string KmsArn

Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected.

maxLength2048
string? Region

AWS region. Derived from kms_arn if omitted.

string? RoleArnDeprecated

IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored.

class BetaAzureExternalKeyConfig { Type = "azure"; KeyName; TenantID; /* 2 more */ }
JsonElement Type = "azure"
required string KeyName

Name of the key within the vault.

required string TenantID

Azure AD tenant ID.

required string VaultUri

Key Vault data-plane URI — https://{vault-name}.vault.azure.net or https://{hsm-name}.managedhsm.azure.net.

string? ClientID

Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.

class BetaAzureExternalKeyConfigParam { Type = "azure"; KeyName; TenantID; /* 2 more */ }

Azure Key Vault provider configuration.

JsonElement Type = "azure"
required string KeyName

Name of the key within the vault.

required string TenantID

Azure AD tenant ID.

required string VaultUri

Key Vault data-plane URI — https://{vault-name}.vault.azure.net or https://{hsm-name}.managedhsm.azure.net.

string? ClientID

Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.

class BetaExternalKey { Type = "external_key"; ID; Attachment; /* 5 more */ }

CMEK external key config belonging to the caller's organization.

Configs are organization-scoped. Workspaces attach to a config; once any workspace references it, the provider fields become effectively immutable (existing encrypted data needs the config for decrypt).

class BetaExternalKeyAttachedAttachment { Type = "attached"; }
JsonElement Type = "attached"
class BetaExternalKeyUnattachedAttachment { Type = "unattached"; }
JsonElement Type = "unattached"
class BetaGcpExternalKeyConfig { Type = "gcp"; KeyName; }
JsonElement Type = "gcp"
required string KeyName

Full resource name of the Cloud KMS key.