Documentation Index

Fetch the complete documentation index at: https://help.grip.security/llms.txt

Use this file to discover all available pages before exploring further.

Claude (Anthropic) Integration with Grip Security

Prev

Overview

This guide explains how to connect Anthropic's Claude Console to Grip.

A single connection process enables access to various Grip features:

  • Grip's SSPM - Enables you to evaluate essential security settings in your Claude environment, including access controls, authentication policies, data protection, and network security.

  • ITDR - Helps identify identity threats from Claude in the ITDR center.

  • Viewing NHI - Provides visibility into non-human identities (NHI) in Claude.

  • Identity and Access Management (IAM) - Allows you to view Claude accounts when you access the Claude app page

  • Prompt monitoring -  Provides visibility into how AI is actually being used - tracking inputs, monitoring for misuse, and identifying corporate data leakage

Credentials

The integration offers three types of credentials, each serving distinct use cases:

Note

  • A single credential is sufficient to establish the connection, since SSPM uses a single key for all three posture checks.

  • Adding more credentials expands coverage to additional use cases such as NHI, ITDR, IAM, and Prompt monitoring, and unlocks more posture checks. Policies lacking a matching key will display a Review status instead of Pass or Fail.

Additional info

Claude has two separate administrative surfaces, and credentials are not interchangeable between them:

  • Claude Console (platform.claude.com) - where the Claude API Key and Admin API Key are created. Billed by prepaid credits; it has no Team or Enterprise seat tiers.

  • Claude.ai - where the Compliance Access Token is created. Requires a Claude Enterprise plan.

A key created in one organization cannot manage a different organization. You will also need your Organization ID to complete the connection.

Grip use cases

Anthropic Product

Credential

Key prefix

Created in

Who can create it

Claude plan

SSPM

Claude Console (platform.claude.com)

API Key

sk-ant-api03-

Claude Console > API keys

Developer role or above

-Individual - Free

-Claude Teams

-Enterprise

SSPM, NHI, ITDR

Claude console

(platform.claude.com)

Admin Key

sk-ant-admin01-

Claude Console > Settings > Admin keys

Admin role (or Owner / Primary Owner)

-Claude Teams

-Enterprise

SSPM, IAM, Prompt Monitoring

Claude Chat

(Claude.ai)

Compliance Access Token

sk-ant-api01-

claude.ai > Organization settings > API

* Primary Owner of the parent organization

-Enterprise

* Note 1

To generate a Compliance API key, the organization must use its sole Primary Owner account.
If a user with Owner permissions encounters a "no permissions" message, they should request that the Primary Owner create the key.

Integration process - Get Claud's required credentials

1. Copy the Organization ID

  • Sign in to platform.claude.com. This is the developer dashboard, separate from claude.ai.

  • Click your admin user (1) and go to Organization settings (2).

  • Copy the Organization ID (3) to your clipboard.

2. Create & Copy the API key

From the organization settings section, navigate to API keys (8)

  • Click on + Create Key (9)

  • In the Create API key window (10), select the workspace and name your key

  • Copy the key to your clipboard - you will need it when connecting to Grip

3. Create & Copy the Admin Key

  • In Organization settings, navigate to Admin Keys (4) in the side menu.

  • Click Create Admin Key (5).

  • Name the key and click Add (6).

  • Copy the Admin Key to your clipboard (7).

4. Enable the Compliance API and create a Compliance key

Enable the Compliance API - availability

  • Enable the Compliance API - Navigate to claude.ai/admin-settings/data-privacy-controls » Organization settings » Data and privacy

  • Claude Console organizations can request access. See Anthropic's Get access to the Compliance API guide for details.

  • Once access is granted, the Compliance API is enabled at the parent organization level and cascades to all linked organizations. Note that only Admin API keys created after enablement can call the Activity Feed.
    If your Admin API Key was created earlier, it will continue to work for other purposes but will return a 403 error on Activity Feed requests - create a new Admin API Key to pick up the scope.

Required role: Primary Owner in claude.ai.

Create the Compliance Access Token

  • In Claude. ai, go to Organization settings,» API » Keys section.

  • Click + Create key

  • Name the key

  • Select the scopes below and click Create.

Note: Scopes are fixed when the key is created and cannot be changed afterward. To use a different set of scopes, create a new key, update the connection in Grip, and delete the old key.

Scope

Grants

read:compliance_activities

Read the Activity Feed for the parent organization and all linked organizations

read:compliance_user_data

Read user chats, messages, files, projects, organization users, and group members

read:compliance_org_data

Read organization metadata (names, types, roles, groups). User listings and group membership require read:compliance_user_data.

  • Copy the key immediately; it is shown only once.

Connect Anthropic to Grip

  1. From the Grip portal, go to Integrations, search for Claude (1), and click Connect » Connect to Posture Management (2).

  2. In the Add a New Claude Tenant window (3), enter:

    • Display Name - A name to identify this tenant in Grip

    • Organization ID - Copied in step 1 - mandatory

    • Admin key and API keys - Copied in steps 2 & 3

    • Compliance Access Token - Copied in step 4

  • Click on Add Tenant.

Once connected, you will be redirected to the Posture Checks tab filtered to your tenant's policies. The status will initially show Retrieving until synchronization is complete. Afterward, each check will display Pass, Fail, or Review.

Checks that show Review indicate that the corresponding API key was not provided during connection setup.

The Connected tag will display on the Claud tile in the Integrations Catalog, and the connected service will be highlighted in green to confirm the connection.

Get the AI Platforms IAM

Grip pulls users directly from Claude, giving you a full user inventory for these platforms from day one.

This means immediate, complete identity coverage for your AI platforms.