Article

Claude Compliance API Adds Unified Chats: Enterprise Export Guide

Export unified Claude chats with cloud tool records. Check Enterprise beta access, endpoint routing, parser limits and archive coverage.

Editorial illustration for Claude Compliance API Adds Unified Chats: Enterprise Export Guide: a geometric block represents a model release. Not documentary evidence.

Anthropic announced on October 8, 2026 that the Claude Compliance API now includes unified-experience chats in beta for Claude Enterprise. Existing Compliance Access Keys work with the expanded coverage. For teams maintaining audit, eDiscovery or data-loss-prevention exports, this is a reason to requalify their collectors. Anthropic’s release note.

Unified chats retain their identity when work moves to the cloud: the export remains one chat, with tool calls and results in its messages. The content documentation describes that representation. The implementation question is whether your archive preserves those records, not just whether authentication succeeds.

Confirm Enterprise access and organization scope

If the API is not enabled, the Enterprise Primary Owner enables it in claude.ai under Organization settings → API. A content collector needs a Compliance Access Key with read:compliance_user_data; export-only work does not need delete permission. A parent-scoped key can cover linked organizations, while an organization owner’s key covers only that organization. Keep the credential in a secrets manager. Setup and scopes.

An Admin API key can query the Activity Feed but cannot retrieve chat content; ordinary model API keys and Analytics keys are not substitutes. Key-type comparison. The Help Center’s eligibility guidance excludes Public Sector organizations. Confirm the intended tenant’s eligibility before treating this beta as available there.

Route each record to the right endpoint family

Cloud execution does not automatically mean a remote-session export. The following routes are relative to /v1/compliance.

Record needed

Retrieval route

Boundary to preserve

Ordinary and unified chats

/apps/chats → per-chat messages

Unified cloud work stays here. Chat content guide.

Enterprise-signed-in sessions on users’ machines

/apps/sessions/local → per-session messages

Separate session records, including eligible Claude Code and Cowork use. Local-session guide.

Cowork sessions running in the cloud

/apps/sessions/remote → per-session messages

Not unified chats or Claude Code cloud sessions. Remote-session guide.

Who acted, on what and when

/activities

Events, not prompt or response bodies. Coverage FAQ.

Session readers use page / next_page and stop at a null next token. Chat readers use cursors and has_more. Keep separate adapters even if they feed one archive. Pagination reference. Claude Code authenticated by a Console API key or through a third-party cloud, and local sessions under zero data retention, are outside the documented session coverage. Session exclusions.

Poll chat updates without losing your place

For organization-wide discovery, omit user_ids[] and set order_by=updated_at. The list is ascending, with ID tie-breaking; the default page size is 100 and the maximum is 1,000. Choose your export start time in this request outline. List-chats reference:

GET /v1/compliance/apps/chats
Query parameters:
  order_by = updated_at
  updated_at.gte = <RFC3339 export start time>
  limit = 1000
  # Omit user_ids[]; add after_id when continuing a saved cursor.

Send requests to api.anthropic.com using the documented x-api-key authentication and anthropic-version header; the guide uses version 2023-06-01. Request contract.

  1. Upsert by chat ID, treating deletion markers separately from content updates. New messages, project moves and deletion can make chats reappear; renames may not. Update semantics.

  2. Use last_id as the next after_id until has_more is false. Keep the cursor opaque and its sort mode unchanged. Cursor contract. Recommended design: commit the checkpoint only after the covered records or retrieval jobs are durably stored, then resume from it on the next run.

  3. On HTTP 429, honor retry-after and retry without advancing the cursor. If the header is absent, Anthropic documents exponential backoff starting at one second and doubling to 60 seconds. Error-handling guidance.

Do not combine user_ids[] with updated_at filters: the documented rejection cutoff was September 22, 2026. This is an existing constraint to check during migration, not another change introduced by the October 8 beta. Filter restrictions.

Preserve tool records, not just readable text

Fetch each chat through GET /v1/compliance/apps/chats/{chat_id}/messages and read chat_messages. Omitting limit returns all messages; an explicit limit is capped at 1,000. If paginating, continue with last_id as after_id until has_more is false. Message endpoint.

In your downstream mapping, preserve tool_use and tool_result blocks, their tool_use_id relationship, nullable identifiers, error indicators and truncated flags. Tool input is JSON-encoded text. Chat parameters tool_use_input_max_chars and tool_result_max_chars default to 10,000 characters; -1 removes the requested cap, not necessarily every server-side limit. Message schema and limits.

Session endpoints instead use tool_use_input_max_bytes and tool_result_max_bytes, with 10,000-byte defaults. There, -1 requests a server maximum of roughly 1 MiB per string. A truncated input may not parse as JSON. Do not copy session limits into the chat adapter. Session transcript limits.

Retrieve uploads, generated files and artifact versions through their matching content endpoints. A message listing is not a binary archive: exported uploads can be processed images or extracted text rather than original file bytes. File and artifact retrieval. Recommended design: retain access-controlled structured records, with explicit unavailable-content status, before building a searchable text view.

Anthropic’s integration directory lists DLP, SIEM and eDiscovery partners. That listing alone does not establish a connector’s handling of the new beta. Ask for acceptance evidence from the stored export, including tool records and attachment handling, rather than a successful HTTP response alone.

Plan for retention and shared request capacity

Chat content follows organization retention and can disappear earlier through user deletion. A user-deleted chat exposes deleted_at but no message content; hard-deleted chats are unavailable. Content-retention rules. By contrast, Activity Feed events have six-year retention beginning at API enablement, without earlier backfill. Its one-minute queryability statement is about events, not chat-export latency. Activity Feed contract.

The Compliance API shares a 600-requests-per-minute budget across a parent organization’s keys and linked organizations; remote-session endpoints have an additional budget. Rate-limit overview.

Illustrative sizing, not a benchmark: assume 10,000 chats, list pages of 1,000, one message request per chat, no downloads or retries, and the whole shared budget available. That is 10 list requests + 10,000 message requests = 10,010 requests, or approximately 16.7 budget-minutes at 600 requests per minute. This is not a completion-time promise: response size, extra pages, downloads and competing collectors add work.

Join records by stable user_id, not email, and monitor compliance_api_accessed events for the collector itself. Integration design guidance. Define who may receive exported content and how long the archive retains it; the data-flow mapping approach in RohitAI’s agentic-privacy guide is useful for that decision.

Qualify the archive before declaring coverage

The following is a proposed acceptance plan, not a test performed for this article. Use synthetic or explicitly authorized fixtures in an Enterprise sandbox; a standalone Console test organization exercises the Activity Feed, not Enterprise chat content. Sandbox guidance.

  • Conversation identity: compare an ordinary chat with a unified chat containing cloud tool work. Check the source records and the final archive for the expected conversation identity and tool-call/result associations.

  • Content fidelity: include long tool input/output, a generated file and an artifact revision. Confirm truncation flags, version tracking and unavailable-object handling survive ingestion.

  • Recovery: exercise multiple pages, repeated delivery and interrupted storage. Simulate 429 and malformed-filter responses; failed retrievals must not move checkpoints forward.

  • Deletion state: start with mocked deletion markers. Any real deletion exercise belongs on a separately authorized disposable fixture, never production evidence.

The practical release criterion is a documented coverage matrix and reproducible archived fixtures. This beta does not, by itself, establish historical unified-chat backfill, tenant-level rollout, export latency or a general-availability date. The reviewed sources leave those questions open.

Finally, collection is retrospective. The Compliance API overview distinguishes it from inline inference controls. An archive can support review of an unwanted disclosure; it does not prevent that disclosure from happening.

Methodology: AI-assisted reporting and implementation analysis based on Anthropic’s published release notes and documentation, rechecked on October 8, 2026. No authenticated API requests, connector tests or tenant-level rollout checks were performed. The capacity example is arithmetic under stated assumptions.