Full ARN of the AWS KMS key. On Claude Platform on AWS the key must be a single-Region key in your organization's own AWS account; cross-account keys, multi-Region keys, and alias ARNs are rejected.
AWS region. Derived from kms_arn if omitted.
IAM role ARN. Deprecated — Anthropic reaches the KMS key through its own intermediate role (or, on Claude Platform on AWS, with credentials AWS issues for the Workspace); this field is ignored.
Name of the key within the vault.
Azure AD tenant ID.
Key Vault data-plane URI — https://{vault-name}.vault.azure.net or https://{hsm-name}.managedhsm.azure.net.
Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.
Azure Key Vault provider configuration.
Name of the key within the vault.
Azure AD tenant ID.
Key Vault data-plane URI — https://{vault-name}.vault.azure.net or https://{hsm-name}.managedhsm.azure.net.
Azure AD application (client) ID. Omit to use Anthropic's multitenant app. Provide only if using a single-tenant app registration in the customer's directory.
CMEK external key config belonging to the caller's organization.
Configs are organization-scoped. Workspaces attach to a config; once any workspace references it, the provider fields become effectively immutable (existing encrypted data needs the config for decrypt).
Full resource name of the Cloud KMS key.
ID of the deleted External Key.
Result of a validation roundtrip against the customer's KMS.
HTTP 200 for both outcomes — the operation completed; status says
whether the key works.
Error message when status is failure. Null otherwise.
success — encrypt/decrypt roundtrip succeeded. failure — the roundtrip failed or timed out; see error.