Skip to main content
Sessions that run Anthropic-backed agents need an Anthropic API key. Runtime stores the key on the caller’s behalf so sessions can boot without a per-run prompt. Two scopes are available:
  • Personal Anthropic keys - saved under the caller’s account and used by default. Scoped per (user, organization) so you can separate keys across contexts.
  • Organization Anthropic keys - set by org owners/admins and shared with every member. Two policies control how they interact with personal keys:
    • individual: every member uses their own personal key. The org key, if set, is ignored.
    • enforced: the org key is used first; per-member personal keys are only used as fallbacks if no org key is configured.
To inspect which key would be used at session creation time, use Resolved Provider Keys.
Values are never returned by any endpoint on this page. Responses include only a masked preview (sk-ant-***...XXXX) and a “connected” / “has_key” flag. Treat keys as opaque, write-only values once stored.

Personal Key

GET /api/user/anthropic-key

Required scope: integrations:read
Read the caller’s stored personal Anthropic key for the current context.

Headers

string
required
Bearer <your_api_key>
string
Optional. Reads the personal key scoped to the given organization.

Response

boolean
true if a personal key is configured.
string
Masked preview of the stored key (e.g. sk-ant-***xxxx), or null when none is set.
string
ISO 8601 timestamp of the last update, or null when never set.

PUT /api/user/anthropic-key

Required scope: integrations:write
Save a personal Anthropic API key. The key is encrypted at rest and never returned by any endpoint after this point.

Headers

string
required
Bearer <your_api_key>
string
Optional. Stores the personal key against the given organization.

Request Body

string
required
Anthropic API key. Must start with sk-ant- or sk-. Minimum 10 characters.

Response

Same shape as GET /api/user/anthropic-key, with connected: true.

DELETE /api/user/anthropic-key

Required scope: integrations:write
Remove the caller’s stored personal Anthropic key for the current context. Subsequent sessions will prompt for a key (or fall back to the org key if configured).

Headers

string
required
Bearer <your_api_key>
string
Optional. Removes the personal key scoped to the given organization.

Response

Same shape as GET /api/user/anthropic-key, always with connected: false.

Organization Key

Setting and deleting the organization Anthropic key requires the caller to be an org owner or admin. Members with integrations:write on their key will still receive 403.
Organization context is required for all org-key endpoints. Set X-Organization-Id to match the path org_id, or use an org-scoped API key whose org ID matches.

GET /api/organizations//anthropic-key

Required scope: integrations:read
All org members can read the key status. Returns whether the org has a key configured and the active policy. The actual key is never returned.

Path Parameters

string
required
Organization ID. Must match X-Organization-Id (or the API key’s org).

Response

string
Echo of the path org_id.
boolean
true when the organization has a stored Anthropic key.
string
Masked preview of the stored key, or null when none is set.
string
"individual" (org key ignored) or "enforced" (org key used first).
string
ISO 8601 timestamp of the last update, or null when never set.

PUT /api/organizations//anthropic-key

Required scope: integrations:write
Org owner or admin role required.
Set the organization Anthropic key, the active policy, or both. To switch a brand-new org to enforced, you must include an api_key.

Path Parameters

string
required
Organization ID. Must match X-Organization-Id (or the API key’s org).

Request Body

string
Anthropic API key. Must start with sk-ant- or sk- when provided. Required when switching to policy="enforced" for the first time.
string
"individual" (default) or "enforced".

Response

Same shape as the GET response, reflecting the updated key and policy.

DELETE /api/organizations//anthropic-key

Required scope: integrations:write
Org owner or admin role required.
Remove the organization’s Anthropic key and reset the policy to "individual". Members fall back to their personal keys (or are prompted) the next time they create a session.

Path Parameters

string
required
Organization ID.

Response

Same shape as the GET response, with has_key: false, key_preview: null, and policy: "individual".