Connecting to Anthropic (NHI)
Last updated: September 28, 2026
What You're Setting Up
You're giving Lumos read-only access to a Claude Console organization through Anthropic's Admin API, so it can surface non-human identity inventory and risk: managed agents and service accounts, the API keys that authenticate as them, keys with no expiry, keys bound to a person, and the workspaces and roles that scope what each of them can reach. There's nothing to deploy on your side. Lumos generates the signing key used for Workload Identity Federation, so you never handle a private key.
Connect the organization where your API workloads run, at platform.claude.com. That holds whether it stands alone or is linked to a Claude Enterprise parent. A claude.ai organization doesn't run API workloads, so it has no agents, service accounts or Claude API keys for this integration to read. On Claude Enterprise, connect each linked Console organization.
Setup takes up to three credentials:
Credential | What it adds | When you need it |
|---|---|---|
Organization API key | Agents, API keys, workspaces, members and roles | Always |
Workload Identity Federation | Service accounts and their workspace memberships | Recommended. Without it, Lumos can't see service accounts. |
Compliance Access Key | Compliance groups and roles | Optional. Only for organizations linked to a Claude Enterprise parent, and it requires federation. |
What Lumos does NOT do:
No writes. Only read capabilities are registered. Lumos can't create, modify, archive or delete a member, service account, agent, API key, workspace or role.
No conversations, files or sessions. Lumos never calls the Messages API, and from the Compliance API it reads only groups, group members and organization roles.
No key secrets. Anthropic shows a key's full value once, at creation, and never returns it from the API. Lumos receives metadata and a redacted hint.
No usage, spend or billing data. The Usage and Cost, Analytics and Spend Limits APIs are never called.
Prerequisites
You'll need an organization admin on the Claude Console organization, and its Organization ID. The ID is a UUID shown in Settings > Organization in the Claude Console. Paste it without an org_ prefix.
For compliance data, you'll also need the Claude Enterprise parent's primary owner, who creates the Compliance Access Key in claude.ai. The Compliance API has to be enabled first. The primary owner turns it on in claude.ai organization settings, and it applies to every linked organization.
Step 1: Create the Organization API key
An Admin key (sk-ant-admin01-...) won't work, and neither will a workspace-scoped key. Lumos rejects an Admin key in the setup form before you can save it.
Sign in to the Claude Console as an organization admin.
Go to Settings > API keys and select Create key.
Set Linked account to a service account. Use yourself or another admin only if no service account exists. A key linked to a person stops working when that person leaves the organization, and the connection stops with it.
Set Scope to Organization.
Copy the key.
Step 2: Start the connection in Lumos
In the Lumos app, go to Integrations > Add Integration and search for "Anthropic (NHI)". The Connect to Anthropic (NHI) dialog opens with three sections.
Under Authentication Method, pick:
Organization API Key + Workload Identity Federation, without compliance data
Organization API Key + Workload Identity Federation + Compliance Access Key, if you'll add compliance data in Step 4
Under Capabilities and Integration Settings:
Set Scope to Read. The field defaults to Read + Write, which grants nothing here, because the connector registers no write capability.
Organization ID is required. Paste the UUID from Prerequisites.
Leave Enterprise Plan off, even if you're on a Claude Enterprise plan. Turning it on stops Lumos from reading agents, service accounts and API keys.
Federation Rule ID, Service Account ID and Default Workspace ID come from Step 3. Leave them for now.
Under Authentication Credentials:
Paste the key from Step 1 into Organization API Key.
Under Workload Identity Federation, enter a Key Identifier using letters, numbers and hyphens, such as
lumos-anthropic-nhi. Select Get Key and copy the JWK it shows. Lumos generates the key pair and keeps the private half. The JWK is the public half, which you register with Anthropic in the next step.
Keep the dialog open if you plan to setup Workload Identity Federation. Otherwise, you can skip to Step 5.
Step 3: Set up Workload Identity Federation in Anthropic
Service accounts are the one thing Anthropic won't return to an API key. They need an OAuth token carrying the org:admin scope, and federation is how Lumos gets one: it signs a short-lived assertion with the key from Step 2 and exchanges it for a token.
In the Claude Console, signed in as an organization admin, go to Settings > Workload Identity Federation and select Connect workload.
Create the issuer:
Under Issuer, select Connect a new provider, then Custom OIDC.
Fill in Name.
Set Issuer URL (iss claim) to
https://lumos.com.Set JWKS source to Inline keys.
Paste the JWK from Step 2 into JWK set (JSON).
Leave Maximum token lifetime (hours) at 1.
Create the federation rule:
Fill in Rule name using lowercase letters, numbers and hyphens.
Set Subject (sub) claim to exactly
lumos:anthropic-nhi, with no trailing*.Under Enable in workspaces, turn on All workspaces (including future ones).
Expand Advanced rule options.
Set OAuth scope to
org:admin.Set Token lifetime to 1 hour.
Pick the target:
Select Create a new one and name the service account, such as
lumos-anthropic-nhi, or pick an existing service account used only by this connector.The target's organization role must be admin. Anthropic won't grant
org:adminthrough a rule that targets a developer.
Copy the Federation Rule ID (starts with fdrl_) and the Service Account ID (starts with svac_).
Step 4: Create the Compliance Access Key (optional)
Skip this step unless your Console organization is linked to a Claude Enterprise parent and you want compliance groups and roles in Lumos. The Lumos dialog can stay open while you do it.
The parent organization's primary owner signs in to claude.ai, goes to Organization settings > API, and creates a key under Keys.
Grant
read:compliance_org_dataandread:compliance_user_data.Copy the key. It starts with
sk-ant-api01-.
Scopes are fixed when the key is created, so a key missing one has to be replaced. Don't grant read:compliance_activities: Lumos doesn't read the activity feed.
Step 5: Finish the connection in Lumos
Back in the dialog:
Paste the Federation Rule ID and Service Account ID into their fields.
If you created one in Step 4, paste it into Compliance Access Key.
Leave Default Workspace ID at
default.
Select Validate, then Complete.
Validate checks each credential against Anthropic with live calls. It confirms the Organization API Key belongs to the Organization ID you entered, that federation returns a token carrying org:admin, and that the Compliance Access Key can read compliance groups, members and roles. A failed check names what's wrong. Complete runs the same checks again before saving the connection.
Connecting several organizations
One connection covers one organization, and a key created in one organization can't read another. If you have several Console organizations, including several linked to the same Claude Enterprise parent, repeat these steps for each one.
What Lumos reads
Every call goes to https://api.anthropic.com/v1. All of them are reads except the federation token exchange.
Endpoint | Credential | What it's for |
|---|---|---|
| Organization API key | Connection check and tenant ID |
| Organization API key | Members and their organization roles |
| Organization API key | API keys as credentials, with status, creation and expiry, and the principal each acts as |
| Organization API key | Workspaces as resources |
| Organization API key | Workspace role assignments |
| Organization API key | Managed agents as non-human accounts |
| Federation | Exchanges a signed assertion for a short-lived token |
| Federation | Service accounts as non-human accounts, with their organization roles |
| Federation | Workspace service-account membership |
| Compliance Access Key | Compliance groups as resources |
| Compliance Access Key | Compliance group membership |
| Compliance Access Key | Compliance roles as entitlements |
API Limitations
These are limits in what Anthropic's API exposes, or in what the integration reads today:
Service accounts need federation. Anthropic serves them only to an
org:adminOAuth token. Without federation, an API key bound to a service account points at an account Lumos hasn't read.There's no last-used signal. Lumos reports when a key was created, when it expires and its status, but not when it was last used. An agent's updated timestamp is its last configuration change, not its last run.
Archived agents and service accounts appear as suspended, so they stay visible in the inventory.
Compliance data needs Claude Enterprise. Compliance Access Keys exist only in Enterprise tenants, so a standalone Console organization connects without them.
Security FAQ
Can Lumos change anything in our Anthropic organization?
No. Only read capabilities are registered. The federation token exchange is the one POST the connector makes, and it mints a token Lumos uses only for reads. Nothing in the connector creates, updates or deletes anything.
Does Lumos read our conversations, files or projects?
No. It never calls the Messages API, and from the Compliance API it calls three directory endpoints: groups, group members and organization roles. The endpoints that return content are never called. read:compliance_user_data also covers some content endpoints, because that's how Anthropic groups its scopes. Lumos needs it for group members and never calls the rest.
Can Lumos read our API key secrets?
No. Anthropic shows a key's value once, at creation, and never returns it from the API. Lumos receives metadata and a redacted hint.
Why does the key have to be organization-scoped?
A workspace-scoped key sees only its own workspace. Lumos reads every workspace and the members and agents inside each one, so it needs organization scope. An Admin key would also work against the API, but Lumos rejects it so you aren't handing over a credential with write access.
Why does federation need org:admin?
Anthropic doesn't serve service accounts to any narrower scope. org:admin is broad, so here's what limits it: each token lasts at most an hour, can only be minted with the private key Lumos generated, and is used only for reads. You can disable the rule at any time.
What happens when the person who created the key leaves?
A key linked to a person stops working, and the connection breaks with it. That's why Step 1 instructs to link the key to a service account.
How are credentials handled?
Lumos stores the API keys you paste, and the private half of the federation key pair it generated. The private key never leaves Lumos and you never see it. Anthropic holds only the public JWK. Rotating an API key in Anthropic means updating it in Lumos, because the old one stops working when you delete it.
How do we revoke Lumos's access?
Delete the API keys in Console settings or claude.ai organization settings, and delete or disable the federation rule under Settings > Workload Identity Federation. The next sync fails to authenticate and Lumos surfaces a connection error. Nothing needs cleaning up on the Anthropic side, because Lumos created nothing there.
Connection rejected with "This is an Admin API key."
The key starts with sk-ant-admin01-. Create a key with Scope set to Organization, as described in Step 1.
Connection rejected because the key belongs to a different organization.
The key and the Organization ID come from different organizations. Correct the Organization ID, or paste a key from the organization you meant.
"Anthropic did not accept the signed assertion."
Check that the issuer's JWK set holds the JWK from Get Key, that the Issuer URL is exactly https://lumos.com, that the Subject claim is exactly lumos:anthropic-nhi, and that the Federation Rule ID and Service Account ID match the rule.
"Federation rule grants ...; this connector needs org:admin."
The rule's OAuth scope is set to something else. Change it under Advanced rule options, and confirm the target service account still holds the admin organization role.
"The Compliance Access Key cannot read compliance groups" (or roles, or memberships).
The key is missing a scope. Create a new key with the scopes in Step 2 and paste that instead. If a key with the right scopes still fails, the Compliance API probably isn't enabled for your tenant yet. Check with your Anthropic account team.
The connection saved, but there are no agents, service accounts or API keys.
Check that the Enterprise Plan integration setting is off. If it is, confirm you connected a Console organization, not a claude.ai one. If agents appear but service accounts don't, check that federation is set up and the rule is enabled in all workspaces.
Some workspaces have no managed agents.
Managed Agents doesn't cover every workspace yet. Lumos skips a workspace without it, so a gap in the agent inventory is usually a workspace without agents, not a broken connection.
Questions? Contact your Lumos account team or support@lumos.com.