Claude Platform Docs

外部キーを作成

BetaExternalKey Beta.Organization.ExternalKeys.Create(parameters, cancellationToken = default)
POST/v1/organizations/external_keys

呼び出し元の組織が所有する外部キー設定を作成します。

Parameters
ExternalKeyCreateParams parameters
required ProviderConfig providerConfig

KMS provider identity and auth coordinates.

class BetaAwsExternalKeyConfig { Type = "aws"; KmsArn; Region; RoleArn; }
JsonElement Type = "aws"
required string KmsArn

Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected.

maxLength2048
string? Region

AWS region. Derived from kms_arn if omitted.

string? RoleArnDeprecated

IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored.

class BetaGcpExternalKeyConfig { Type = "gcp"; KeyName; }
JsonElement Type = "gcp"
required string KeyName

Full resource name of the Cloud KMS key.

class BetaAzureExternalKeyConfigParam { Type = "azure"; KeyName; TenantID; /* 2 more */ }

Azure Key Vault provider configuration.

JsonElement Type = "azure"
required string KeyName

Name of the key within the vault.

required string TenantID

Azure AD tenant ID.

required string VaultUri

Key Vault data-plane URI — https://{vault-name}.vault.azure.net or https://{hsm-name}.managedhsm.azure.net.

string? ClientID

Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.

string? displayName

Human-friendly display name.

maxLength255
minLength1
Geo geo

Data residency geo. Only us is supported.

Us("us")
Returns
class BetaExternalKey { Type = "external_key"; ID; Attachment; /* 5 more */ }

CMEK external key config belonging to the caller's organization.

Configs are organization-scoped. Workspaces attach to a config; once any workspace references it, the provider fields become effectively immutable (existing encrypted data needs the config for decrypt).

外部キーを作成
ExternalKeyCreateParams parameters = new()
{
    ProviderConfig = new BetaAwsExternalKeyConfig()
    {
        KmsArn = "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
        Region = "us-east-1",
        RoleArn = "arn:aws:iam::111122223333:role/anthropic-cmek",
    },
};

var betaExternalKey = await client.Beta.Organization.ExternalKeys.Create(parameters);

Console.WriteLine(betaExternalKey);
Returns Examples
Response 200
{
  "id": "ekey_01SDCCSbTxrXDpWc1phhtcfK",
  "attachment": {
    "type": "attached"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "display_name": "prod-us-key",
  "geo": "us",
  "provider_config": {
    "kms_arn": "arn:aws:kms:us-east-1:111122223333:key/abcd1234-5678-90ab-cdef-000011112222",
    "type": "aws",
    "region": "us-east-1",
    "role_arn": "arn:aws:iam::111122223333:role/anthropic-cmek"
  },
  "type": "external_key",
  "updated_at": "2024-10-30T23:58:27.427722Z"
}