# Claude Platform
Everything [[Anthropic]] gives you to build with [[Claude]], in one place: an API, a web console, docs, a cookbook of examples, and official SDKs. If you're writing software that talks to Claude, this is home base. It lives at platform.claude.com (the address that used to be console.anthropic.com).
The name covers a few distinct things people tend to blur together.
| Piece | What it is |
|---|---|
| [[Claude API]] | The RESTful API at `api.anthropic.com`: Messages, Batches, Files, Managed Agents |
| [[Claude Console]] | The web UI for keys, billing, usage, workspaces, and the Workbench |
| Docs | Guides, references, quickstarts |
| Cookbook | Copy-paste recipes and working example code |
| SDKs | Official client libraries — Python, TypeScript, Java, Go, C#, Ruby, PHP |
## How it fits together
You sign up, land in the [[Claude Console]], and create an API key. That key authenticates your calls to the [[Claude API]]. The docs tell you what's possible; the cookbook shows you code that already works; the SDKs save you from hand-rolling HTTP requests. [[Claude Managed Agents]] is the newest layer on top; managed agent infrastructure running on the same platform.
## Keyless authentication
Leaked API keys are one of the top security concerns developers have. GitGuardian found 1.27 million AI-service credentials exposed on public GitHub in 2025, up 81% from the year before. So in May 2026, Anthropic introduced **keyless auth** for the Claude Platform, and it became generally available on June 17, 2026.
There are two paths, and with both you never handle a static `sk-ant-...` key:
- **Interactive (humans)**: authenticate through the browser with the CLI, using `ant auth login` (see [[Anthropic CLI (ant)]])
- **Workloads (machines)**: **Workload Identity Federation (WIF)**. Your workload uses the cloud identity it already has (AWS IAM, Google Cloud, Azure / Microsoft Entra ID, or any OIDC provider such as GitHub Actions, Kubernetes, SPIFFE, or Okta)
How WIF works:
1. The workload presents a signed OIDC token (a JWT) from its identity provider
2. Anthropic validates it against trust rules you configured in the [[Claude Console]]
3. Anthropic returns a short-lived access token (via `POST /v1/oauth/token`), bound to a service account in your organization. The SDKs refresh it automatically
It relies on three resources, configured under Settings > Workload identity: a **service account** (with roles), a **federation issuer**, and a **federation rule** that binds an external identity to the service account. Every exchange and request is logged against that service account.
Setup takes a few minutes. You set four environment variables (federation rule ID, organization ID, service account ID, workspace ID) and remove the API key. Those IDs aren't secrets, so they're safe to commit. It covers all [[Claude API]] endpoints, including the first-party SDKs and [[Claude Code]].
Keep in mind that federated auth is only as strong as the identity provider that signs the token. And the audit trail covers what happens in Claude, not the rest of your AI stack.
## The Cookbook
The cookbook deserves more attention than it gets. It's a library of working, copy-paste recipes organized by category: tool use, agent patterns, RAG and retrieval, prompting, vision, skills, evals, observability, extended thinking, and even cybersecurity. The recipes worth knowing about:
- **Programmatic Tool Calling** — Claude writes code that calls your tools directly instead of round-tripping through the model for each call. Big latency win for multi-tool workflows.
- **Tool Search with embeddings** — scale to thousands of tools by letting the model discover them semantically instead of stuffing every schema in context.
- **Automatic context compaction** — compress conversation history in long-running agents without losing the thread. The platform-side answer to [[Context Engineering]].
- **Contextual Retrieval** — add context to chunks BEFORE embedding them; one of the highest-impact RAG improvements for the effort.
- **Prompt caching, including speculative caching** — cache stable prompt prefixes; speculative caching warms the cache while the user is still typing.
- **Batch processing** — 50% cost reduction for anything async.
- **Citations** — first-class source citations instead of prompt hacks.
- **Multi-agent orchestration** — evaluator-optimizer and orchestrator-workers patterns, plus async agent teams with dynamically spawned subagents.
When building anything on the [[Claude API]], check the cookbook FIRST. Odds are good someone already wrote the recipe.
## Direct vs cloud platforms
You can reach Claude two ways. Straight through Anthropic gives you direct billing and the latest features first. Going through a cloud provider — AWS, Google Cloud, Azure — folds billing and auth into that provider's IAM instead.
Pick direct for new projects and full feature access. Pick a cloud platform if you already have a commitment there, or specific compliance needs that make consolidated cloud billing worth it.
## References
- Platform home: https://platform.claude.com/
- Docs: https://platform.claude.com/docs/en/home
- Cookbook: https://platform.claude.com/cookbook/
- API overview: https://platform.claude.com/docs/en/api/overview
- Keyless auth announcement: https://x.com/ClaudeDevs/status/2051393709619732758
- Workload Identity Federation GA: https://claude.com/blog/workload-identity-federation
- Workload Identity Federation docs: https://platform.claude.com/docs/en/manage-claude/workload-identity-federation
- Authentication docs: https://platform.claude.com/docs/en/manage-claude/authentication
## Related
- [[Claude]]
- [[Claude Console]]
- [[Claude API]]
- [[Anthropic]]
- [[Anthropic SDK]]
- [[Anthropic CLI (ant)]]
- [[Claude Code]]
- [[Claude Managed Agents]]