Integrations
Anthropic
Configuring Anthropic integration
Tidal Control's Anthropic integration monitors your Claude Console organisation for AI governance and access control purposes. All access is read-only — Tidal Control never creates, modifies, or deletes anything in your Anthropic organisation.
Anthropic or Claude Enterprise? Anthropic offers two separate products with two separate keys. Use this integration if your company builds with the Anthropic API through the Claude Console (platform.claude.com). If your employees use Claude for chat and projects on claude.ai, use the Claude Enterprise integration instead. The keys are not interchangeable. If you use both products, connect both integrations.
What this integration monitors:
- Organisation members: Email, name, organisation role (admin, developer, billing, user), and when they were added
- Workspaces: Name, creation date, archival state, data residency, and default inference region
- Workspace members: Who can act in each workspace and at what workspace role
- API keys: Name, status, workspace scope, expiry date, and the user who created the key
- Invites: Pending invites with their invited role and expiry date
Requirements:
- Super User role in Tidal Control
- A Claude Console organisation — the Admin API is not available for individual accounts
- The admin organisation role in the Claude Console, since only admins can create Admin API keys
Configuration step-by-step plan
What we're going to do: We'll create an Admin API key in the Claude Console, then add the connection in Tidal Control.
Configuration steps:
- Create an Admin API key in the Claude Console
- Configure the integration in Tidal Control
Step 1: Create an Admin API key in the Claude Console
- Sign in to the Claude Console as an organisation admin
- Go to Settings → Admin keys
- Click Create key
- Enter a name (e.g.
Tidal Control) and optionally set an expiration - Click Create key
- Copy the key — it starts with
sk-ant-admin01-and is only shown once
Save the Admin API key immediately. Anthropic only shows the full key value once at creation. If you close the dialog without copying it, you will need to create a new key.
Admin keys have no scopes. A Console Admin key carries full Admin API access, so there is nothing to select during creation. Tidal Control only reads organisation members, workspaces, API key metadata, and invites — it never reads or sends messages, and never retrieves secret key values.
Step 2: Configure the integration in Tidal Control
- Go to Settings → Integrations in Tidal Control
- Click the plus icon next to Anthropic
- Fill in the configuration:
- Name: A descriptive name, e.g.
Anthropic - Admin API Key: The key from step 1
- Name: A descriptive name, e.g.
- Click "Create" to save the integration
Configuration fields explained
Name:
- A descriptive name for this connection
- For example:
Anthropic,Anthropic Console
Admin API Key:
- The Claude Console Admin API key, starting with
sk-ant-admin01- - Created in step 1
- A regular Anthropic API key (
sk-ant-api03-) will not work — it cannot call the Admin API - Keep this value secure
Available checks
AI governance (ISO/IEC 42001):
- Who has access to the AI provider organisation and at what role
- Which workspaces exist, which are archived, and where their data resides
- Which credentials are live, as evidence of governance over your AI supply chain
Access control (ISO 27001 A.5.15, A.5.18, SOC 2 CC6.1):
- Organisation and workspace role assignments for least-privilege reviews
- Privileged access — organisation admins and workspace admins
- API key inventory, including keys without an expiry date and who created them
Identity management (ISO 27001 A.5.16, SOC 2 CC6.2, CC6.3):
- Member roster with joining dates
- Pending invites that were never accepted or have expired
- Archived workspaces and inactive API keys as de-provisioning evidence
Verification
Check integration status:
- Settings → Integrations shows "Connected" status for Anthropic
- Anthropic tests are available in the Tests section
- Test refresh delivers results without authentication errors
Frequently asked questions
Does Tidal Control read our Claude conversations? No. The integration only reads organisation governance data: members, workspaces, API key metadata, and invites.
Does this integration cover usage and cost reporting? No. It covers identity, access, and credential governance only. Usage and cost reports are not retrieved.
Can I use a regular Anthropic API key? No. Only an Admin API key can call the Admin API. A regular API key returns an authentication error.
Are MFA and SSO settings included? No. The Admin API does not expose organisation MFA or SSO enforcement settings, so verify those manually in the Console.
Common problems
Authentication fails with a 401 error
- Confirm the key starts with
sk-ant-admin01-— a regular API key cannot call the Admin API - Check that the key was copied in full and has not expired or been revoked
- Confirm the account that created the key still has the admin organisation role
No workspaces or members are returned
- Confirm the key belongs to the organisation you want to monitor
- Individual accounts without an organisation have no Admin API data to read
Test refresh is slow for large organisations
- Workspace membership is read per workspace, so organisations with many workspaces take longer to refresh
Still can't figure it out?
Send an email to support@tidalcontrol.com, and we'll get back to you as soon as possible.
Gather support info: Note which browser you're using, exact error messages, and which steps you've already tried. This speeds up the solution considerably.