Claude Platform Docs

API 金鑰

列出 API 金鑰
$client->beta->organization->apiKeys->list(?string afterID, ?string beforeID, ?string createdByUserID, ?int limit, ?Status status, ?string workspaceID): Page<APIKey>
GET/v1/organizations/api_keys
擷取 API 金鑰(Admin API)
$client->beta->organization->apiKeys->retrieve(string apiKeyID): APIKey
GET/v1/organizations/api_keys/{api_key_id}

依 ID 查詢並擷取您組織中單一 API 金鑰的資訊。此 Admin API 端點需要 Admin API 金鑰,專為程式化金鑰管理而設計,且絕不會回傳金鑰的祕密值。若要檢視或建立您自己的 API 金鑰,請前往 Claude Console 中的 API 金鑰

更新 API 金鑰
$client->beta->organization->apiKeys->update(string apiKeyID, ?string name, ?Status status): APIKey
POST/v1/organizations/api_keys/{api_key_id}
Models
class APIKey { $type = 'api_key'; $id; $createdAt; /* 8 more */ }
"api_key" type

Object type.

For API Keys, this is always "api_key".

string id

ID of the API key.

\Datetime createdAt

RFC 3339 datetime string indicating when the API Key was created.

?APIKeyCreatedBy createdBy

The ID and type of the actor that created the API key, or null when the creator is not recorded (legacy, workload-identity-federated, or system-created keys).

?\Datetime expiresAt

RFC 3339 datetime string indicating when the API Key expires, or null if it never expires.

string name

Name of the API key.

?string partialKeyHint

Partially redacted hint for the API key.

?Principal principal

The principal the API key acts as (a User or a Service Account), or null if the API key is not bound to a principal.

Scope scope

Where the API key belongs: its Workspace ({"type": "workspace", "workspace_id": "wrkspc_..."}, with the Workspace's real ID even when it is the organization's default Workspace), or the organization ({"type": "organization"}) for a principal-bound API key that has no Workspace.

Status status

Status of the API key.

?string workspaceIDDeprecated

Deprecated: use scope instead. ID of the Workspace associated with the API key, or null if the API key belongs to the default Workspace. Also null for a principal-bound API key that has no Workspace; scope tells the two apart.

Use `scope` instead. `workspace_id` is `null` both for an API key in the default Workspace and for a principal-bound API key that has no Workspace.
class APIKeyCreatedBy { $type; $id; }
Type type

Type of the actor that created the object.

string id

ID of the actor that created the object.

class APIKeyOrganizationScope { $type = 'organization'; }
"organization" type

Scope type. Always "organization": the API key has no Workspace. Only a principal-bound API key can have this scope.

class APIKeyServiceAccountActor { $type = 'service_account_actor'; $serviceAccountID; }
"service_account_actor" type

Principal type. Always "service_account_actor" for a Service Account.

string serviceAccountID

ID of the Service Account the API key acts as.

class APIKeyUserActor { $type = 'user_actor'; $userID; }
"user_actor" type

Principal type. Always "user_actor" for a User.

string userID

ID of the User the API key acts as.

class APIKeyWorkspaceScope { $type = 'workspace'; $workspaceID; }
"workspace" type

Scope type. Always "workspace": the API key belongs to one Workspace.

string workspaceID

ID of the Workspace the API key belongs to. Unlike the deprecated top-level workspace_id, this is the Workspace's real ID even for the organization's default Workspace.