claude "/claude-api help me configure a customer-managed encryption key with AWS KMS"This guide walks through configuring an AWS KMS key as a customer-managed encryption key (CMEK) for your Anthropic organization.
Enabling CMEK is permanent. If your KMS key is deleted or disabled, Anthropic cannot recover the data encrypted under it. Review the warnings and limitations before you begin.
kms:CreateKey and kms:PutKeyPolicy).To have Anthropic use your encryption key, you must give Anthropic's IAM role a KMS key it can use for encrypting data. The ARN for Anthropic CMEK is:
arn:aws:iam::915198916910:role/anthropic-cmek-client-usUse only this published ARN. Never trust an identifier provided over email, chat, or any onboarding channel.
Create the KMS key with a cross-account key policy
The key policy grants Anthropic's IAM role cross-account access. Three statements are required:
kms:Encrypt and kms:Decrypt actions, which Anthropic uses to encrypt and decrypt the data keys that protect your workspace data (envelope encryption).DescribeKey has no EncryptionContext parameter, so an EncryptionContext condition on this action would always deny.export YOUR_ACCOUNT=$(aws sts get-caller-identity --query Account --output text)
aws kms create-key \
--region <region> \
--description "Anthropic CMEK" \
--key-usage ENCRYPT_DECRYPT \
--policy "{
\"Version\": \"2012-10-17\",
\"Statement\": [
{
\"Sid\": \"AccountRootAdmin\",
\"Effect\": \"Allow\",
\"Principal\": {\"AWS\": \"arn:aws:iam::${YOUR_ACCOUNT}:root\"},
\"Action\": \"kms:*\",
\"Resource\": \"*\"
},
{
\"Sid\": \"AllowAnthropicCMEKCrypto\",
\"Effect\": \"Allow\",
\"Principal\": {\"AWS\": \"arn:aws:iam::915198916910:role/anthropic-cmek-client-us\"},
\"Action\": [\"kms:Encrypt\", \"kms:Decrypt\"],
\"Resource\": \"*\",
\"Condition\": {
\"StringEquals\": {
\"kms:EncryptionContext:anthropic:compartment_uuid\": [
\"00000000-0000-0000-0000-000000000000\",
\"<compartment-uuid>\"
]
}
}
},
{
\"Sid\": \"AllowAnthropicCMEKDescribe\",
\"Effect\": \"Allow\",
\"Principal\": {\"AWS\": \"arn:aws:iam::915198916910:role/anthropic-cmek-client-us\"},
\"Action\": \"kms:DescribeKey\",
\"Resource\": \"*\"
}
]
}"Capture KeyMetadata.Arn from the output. You need it when you register the key in the next step.
The EncryptionContext condition is recommended but optional. Anthropic always includes your workspace's compartment ID in the encryption context, so ciphertext is cryptographically bound to that compartment regardless. Adding the condition provides defense-in-depth at the IAM layer. To start without it, omit the Condition block from the AllowAnthropicCMEKCrypto statement and add it later with kms:PutKeyPolicy.
Finding your compartment ID: Where to find your compartment ID differs between Claude Platform and Claude Enterprise. See the Claude Platform and Claude Enterprise tabs under Register the key with Anthropic.
You can also create the key from the AWS Console. Choose a symmetric key with the encrypt and decrypt key usage, a single-region key, and KMS key material origin. The Create-key wizard commits a key policy at its Review step: If you add Anthropic's account ID 915198916910 under key usage permissions there, the generated policy grants the whole Anthropic account broader actions (such as kms:ReEncrypt* and kms:GenerateDataKey*) with no EncryptionContext condition, and validation would still succeed against it. To avoid leaving an over-permissive key, finish the wizard with administrative permissions only, then open the key's Key policy tab and replace the JSON with the role-scoped policy shown earlier (the three statements scoped to the anthropic-cmek-client-us role, with the EncryptionContext condition).




How you register the key depends on which product you use.
Finding your compartment ID: Each workspace has a compartment ID that scopes its CMEK data. Find it in the Claude Console under Workspace > Security > Encryption keys (the Compartment ID field), or read the compartment_id field returned by the Get Workspace endpoint. Substitute that value for <compartment-uuid> in the preceding key policy.
Key validation always sends the all-zeros compartment UUID (00000000-0000-0000-0000-000000000000) as the encryption context, because validation runs before the key is attached to any workspace. Live traffic sends the compartment ID of each attached workspace.
Any EncryptionContext condition must allow the all-zeros value plus the compartment ID of every workspace the key is attached to. Validation also runs again whenever key setup is re-run, so keep the all-zeros entry in place permanently.
To attach the key to an additional workspace, add that workspace's compartment ID to the condition with kms:PutKeyPolicy before attaching.
Register the key with Anthropic
Create an external key configuration through the Admin API.
For organizations on Claude Platform on AWS, the external key endpoints are not yet available. Register, validate, and attach your key in the Claude Console instead.
curl -sS https://api.anthropic.com/v1/organizations/external_keys \
-H "x-api-key: <anthropic-admin-api-key>" \
-H "anthropic-version: 2023-06-01" \
-H "content-type: application/json" \
-d '{
"display_name": "<friendly-name>",
"geo": "us",
"provider_config": {
"type": "aws",
"kms_arn": "<key-arn-from-create-key-step>",
"role_arn": "arn:aws:iam::915198916910:role/anthropic-cmek-client-us"
}
}'The response contains the external key ID:
{
"type": "external_key",
"id": "ekey_<id>",
"display_name": "<friendly-name>"
}Validate the key
Trigger an encrypt and decrypt round-trip against your key.
curl -sS -X POST https://api.anthropic.com/v1/organizations/external_keys/ekey_<id>/validate \
-H "x-api-key: <anthropic-admin-api-key>" \
-H "anthropic-version: 2023-06-01" \
-H "content-type: application/json" \
-d '{}'A successful response looks like this:
{ "type": "external_key_validation", "status": "success", "error": null }If validation fails, common causes are:
AccessDeniedException when a kms:EncryptionContext:anthropic:compartment_uuid condition allows only one of the two values Anthropic sends. Validation sends the all-zeros UUID (00000000-0000-0000-0000-000000000000); live traffic sends the attached workspace's compartment ID. Confirm the condition lists both. To rule the condition out entirely, temporarily remove the Condition block from the AllowAnthropicCMEKCrypto statement and re-validate.aws:PrincipalOrgID does not match your org, it blocks Anthropic's cross-account role. The RCP needs a carve-out for this key or for Anthropic's role ARN. Service control policies do not apply here, because they do not evaluate for external principals calling through resource-based policies.aws kms get-key-policy --key-id <id> --policy-name default.Attach the key to a workspace
curl -sS -X POST https://api.anthropic.com/v1/organizations/workspaces/<workspace-id> \
-H "x-api-key: <anthropic-admin-api-key>" \
-H "anthropic-version: 2023-06-01" \
-H "content-type: application/json" \
-d '{
"external_key_id": "ekey_<id>"
}'For infrastructure-as-code deployments, the same steps map to the aws provider with the aws_kms_key and aws_kms_alias resources.
Was this page helpful?