Tool
Anthropic API
Anthropic’s own model endpoint for applications you build. The same models are also sold through three cloud platforms, so the API is one contract among several for identical weights.
- Source
- Registry entry — nothing fetched yet
- Verified
- Evidence not verified
- Confidence
- Unknown
01What this is
- Delivery
- Cloud platforms
- Vendor
- Anthropic
- Categories
- model-api, llm-gateway
- Use cases
- model-selection, private-company-chatgpt, contract-review, ai-coding-assistant, agent-workflow
- Open source
- not recorded as open source
The rows above are the registry entry — who this is and where to find it. They are not claims about the vendor’s behaviour; those live under “Verified facts”, with the document each one came from.
02Repository
No source repository is linked to this tool. That is expected for a closed-source product and a gap for anything else.
03Verified facts
Data processing agreement
Not yet researched for this entity.
Pricing
Not yet researched for this entity.
Personal data
Not yet researched for this entity.
Security
Not yet researched for this entity.
Subprocessors
Not yet researched for this entity.
Vendor jurisdiction
Not yet researched for this entity.
Terms-of-service restrictions
Not yet researched for this entity.
04Vendor documents
| Document | Last fetched |
|---|---|
| Data processing agreement | not yet fetched |
| Pricing | not yet fetched |
| Pricing | not yet fetched |
| Privacy policy | not yet fetched |
| Security page | not yet fetched |
| Security page | not yet fetched |
| Subprocessor list | not yet fetched |
| Supported countries | not yet fetched |
| Terms of service | not yet fetched |
05Hosting options
- Vendor api
- No description recorded.
06Deployment stacks
- vendor_apiAgent workflow on a model vendor’s APILangGraph as the orchestration graph mixing deterministic and model-driven steps, a closed model (GPT-5, Claude or Gemini) for the reasoning, your own tools for the actions, Langfuse for tracing and evaluation, and human approval gates on the steps that change something.
- vendor_apiAssistant on a model vendor’s APIOpen WebUI as the interface, a LiteLLM gateway holding the vendor key and the spend log, a closed model (GPT-5, Claude Sonnet or Gemini) reached over its API, and pgvector for retrieval over your own documents. The application is identical to a self-hosted one; only the model moves to a vendor endpoint.
07Alternatives
Tools that serve at least one of the same use cases. Open-source alternatives, with the repository facts behind them, have their own page.
Self-hosted alternatives to Anthropic API
- Cloud platformsAlibaba Cloud Model StudioAlibaba Cloud’s model platform and the primary managed route to the Qwen family. International and mainland China consoles are separate deployments under separate agreements.
- Cloud platformsAmazon BedrockAWS service offering models from several providers behind one API in a chosen region, with VPC endpoints, IAM control, guardrails and knowledge bases for retrieval.
- Cloud platformsAmazon Bedrock AgentCoreAWS runtime for agents: session isolation, tool invocation, memory and an identity boundary, with the model served from Bedrock in the same account.
- Cloud platformsAmazon Bedrock Knowledge BasesManaged retrieval-augmented generation on Bedrock: ingestion, chunking, embedding and a vector store, wired to a model in the same account and region.
- Cloud platformsAmazon SageMaker AIAWS’s machine-learning platform. JumpStart deploys open-weight models into your own VPC, which is the route to self-managed weights without leaving the AWS account.
- Hybrid — hosted or self-hostedAnythingLLMDesktop and server application that turns a document set into a chat workspace, with per-workspace embeddings, multiple model back ends and a built-in vector store.
- Hybrid — hosted or self-hostedauthentikIdentity provider with OpenID Connect, SAML and proxy-based authentication, application-level policies and a forward-auth outpost for services that have no login of their own.
- Cloud platformsAzure AI SearchManaged search index with vector, keyword and hybrid retrieval, private endpoints and Entra ID security filters. The retrieval half of most Azure-hosted assistants.
- Cloud platformsBasetenDeploys open-weight and custom models as autoscaling endpoints, including into a customer’s own cloud account. Publishes a subprocessor list, which most inference providers do not.
- Cloud platformsCerebras InferenceOpen-weight model endpoints served from the vendor’s wafer-scale accelerators. A narrower catalogue than the general providers, aimed at latency-sensitive interactive work.
- SaaS productsChatGPT EnterpriseOpenAI’s administered ChatGPT tier with SSO, workspace controls, retention settings, connectors to company systems and business terms that differ from the consumer product.
- SaaS productsClaudeAnthropic’s assistant, available as a team and enterprise product with SSO, audit logs, project workspaces and commercial terms, and as an API for building applications.
08By jurisdiction
Issue-spotting for this tool under each published jurisdiction, built from the same rules an answer uses. A page with nothing researched says so rather than filling the gap.
- europeAnthropic API in European UnionRegulation (EU) 2016/679 (GDPR). Directly applicable in every Member State and unamended as of the review date. An AI deployment engages Articles 5 and 6 on principles and lawful basis, 9 on special categories, 13 and 14 on information, 22 on decisions based solely on automated processing, 28 on processors, 32 on security, 35 on impact assessments and Chapter V on transfers out of the EEA. Member States retain room to legislate on employment, which is where Germany’s BDSG § 26 comes in.
- europeAnthropic API in SwitzerlandThe revised Federal Act on Data Protection (nFADP/revDSG), SR 235.1, in force since 1 September 2023, with the Data Protection Ordinance and the Ordinance on Data Protection Certification. The AI-relevant provisions are article 21 on automated individual decisions — a duty to inform, a right to state a point of view and a right to review by a natural person on request — article 22 on impact assessments, article 23 on prior consultation of the Commissioner where residual risk stays high, articles 16 and 17 on cross-border disclosure, article 24 on breach notification, article 9 on processors and article 7 on data protection by design. Sanctions are criminal fines of up to CHF 250,000 imposed on responsible private individuals, not administrative fines on companies, which changes who in an organisation has to have read the assessment.
- europeAnthropic API in United KingdomUK GDPR, as retained and amended, together with the Data Protection Act 2018. The core duties are unchanged in shape — lawful basis, transparency, purpose limitation, security, processor contracts, international transfers — but the automated decision-making regime now sits in Articles 22A to 22D rather than Article 22. Article 22A defines a decision as based solely on automated processing where there is no meaningful human involvement, and a significant decision as one producing a legal or similarly significant effect. Whether human involvement is meaningful must be considered in light of the extent to which the decision is reached by profiling.
- middle-eastAnthropic API in United Arab EmiratesOnshore: Federal Decree-Law No. 45 of 2021, in force since 2 January 2022, supervised by the Emirates Data Office. Its scope provision carves out government data, health data with its own legislation, banking and credit data with its own legislation, and free-zone companies with special personal-data legislation — which is why the DIFC and ADGM sit outside it entirely. The DIFC applies Data Protection Law No. 5 of 2020 together with the DIFC Data Protection Regulations, including Regulation 10 on autonomous and semi-autonomous systems. ADGM applies the Data Protection Regulations 2021 and designates adequate jurisdictions on the European Commission’s model. Onshore, automated decisions engage a right to object and a right to have the human element included in the review, and an impact assessment is mandatory for systematic comprehensive automated evaluation with legal or serious effects.
- north-americaAnthropic API in CanadaPIPEDA (S.C. 2000, c. 5) governs commercial handling of personal information federally, through ten fair-information principles and an accountability model for transfers — the organisation stays responsible for information handed to a processor, wherever that processor sits. The Privacy Commissioner lists Alberta, British Columbia and Quebec as having general private-sector laws declared substantially similar, and Ontario, New Brunswick, Newfoundland and Labrador and Nova Scotia as substantially similar for health information. Quebec’s regime, as amended by Law 25, is the strictest and has been fully in force since September 2024: it carries a duty to inform a person subject to a decision based exclusively on automated processing, a privacy impact assessment before communicating personal information outside Quebec, and data portability, all enforced by the Commission d’accès à l’information with monetary penalties.
- north-americaAnthropic API in United StatesSectoral, not omnibus. FTC Act §5 (15 U.S.C. 45) is the general backstop for unfair or deceptive AI and data practices. HIPAA (45 CFR Part 164) covers protected health information; the GLBA Safeguards Rule (16 CFR Part 314) covers financial institutions; FCRA (15 U.S.C. 1681) governs consumer reports and adverse-action notices, which is the statute AI credit, tenant and employment screening most often engages; the COPPA Rule (16 CFR Part 312) covers under-13 data, and the 2025 amendments’ compliance deadline has passed. There is no federal cross-border transfer regime for ordinary personal data. State law supplies what the federal layer does not: California’s CCPA and the CPPA’s ADMT regulations, Colorado’s automated decision-making statute from 2027, Illinois BIPA and the Illinois Human Rights Act AI amendment, Texas TRAIGA, Connecticut Public Act 26-15 and New York City Local Law 144.
- north-asiaAnthropic API in China (mainland)Personal Information Protection Law (PIPL), in force since 1 November 2021. Requires a lawful basis, notice, and separate consent for defined activities including providing personal information to a third party, publicising it, processing sensitive personal information and sending it abroad. Sensitive personal information needs a specific purpose, sufficient necessity and strict protective measures. A personal information protection impact assessment is required before high-risk processing, including any outbound transfer. Article 38 sets the outbound routes. Entrusted processing must be governed by a contract that fixes purpose, period, method and protective measures.
- north-asiaAnthropic API in Hong KongPersonal Data (Privacy) Ordinance (Cap. 486). The Ordinance applies to any person who controls the collection, holding, processing or use of personal data, and works through six Data Protection Principles in Schedule 1 covering collection, accuracy and retention, use, security, openness and access. Data processors are not directly regulated: the data user stays responsible and must impose the requirements on its processors by contract or other means. Contravening a Data Protection Principle is not itself an offence, but the Commissioner may issue an enforcement notice and contravening that notice is.
- north-asiaAnthropic API in JapanAct on the Protection of Personal Information (個人情報の保護に関する法律, Act No. 57 of 2003). Requires the purpose of use to be specified and adhered to, restricts acquisition and third-party provision, sets security control measures, and imposes duties when personal data is entrusted to a contractor — which is what using a model provider usually is. Transfers to a third party in a foreign country are subject to their own regime, with an information duty to the individual. The e-Gov entry currently shows unenforced provisions pending, so check which version applies before relying on an article number.
- north-asiaAnthropic API in South KoreaPersonal Information Protection Act (개인정보 보호법). The version in force is Act No. 20897, effective 2 October 2025. It sets consent and alternative bases, purpose limitation, retention limits, security duties, breach notification and cross-border rules, and since March 2023 has carried Article 37-2, the right of a data subject to object to or refuse a decision made by a completely automated system — expressly including systems applying artificial intelligence — where that decision significantly affects their rights or duties. An amendment promulgated on 10 March 2026 takes effect on 11 September 2026.
- north-asiaAnthropic API in TaiwanPersonal Data Protection Act (個人資料保護法). Applies to public and non-public agencies, with separate collection and use rules for each. Notice at collection, purpose limitation, and a set of statutory bases are the core; special categories including medical records, genetic data, sexual life, health examination and criminal records are subject to a narrower regime. Article 21 lets the competent authority restrict international transfer in defined circumstances — under the text in force, that is the central sector regulator, and restrictions are issued sector by sector rather than as a general adequacy list.
- oceaniaAnthropic API in AustraliaPrivacy Act 1988, through the thirteen Australian Privacy Principles. They govern open handling, anonymity, collection, notification, use and disclosure, direct marketing, cross-border disclosure, government identifiers, quality, security, access and correction, and they apply to an AI pipeline the same way they apply to a filing cabinet. The Privacy and Other Legislation Amendment Act 2024 added a statutory tort for serious invasion of privacy, doxxing offences, a Children’s Online Privacy Code still in development, a mechanism to prescribe countries with substantially similar laws that has never been used, and an automated decision-making transparency duty that commences twenty-four months after Royal Assent — that is, in December 2026. The OAIC has published two AI-specific guidance documents, one for organisations buying commercially available AI products and one for developing and training generative AI models.
- south-americaAnthropic API in BrazilLei nº 13.709/2018 (LGPD) is the general data protection statute. The AI-relevant provisions are article 20 on review of decisions taken solely on automated processing, articles 33 to 36 on international transfer bases and adequacy criteria, article 38 letting the authority demand a data protection impact report at any time, and article 46 requiring security measures applied from the design phase of the product through to its execution. Commencement was staged: the authority’s own provisions from December 2018 and administrative sanctions from August 2021. Resolution 15/2024 sets incident notification at three business days to both the regulator and the affected data subjects, and there is still no regulation specific to impact reports — the authority points controllers at the high-risk definition in its small-processing-agent regulation instead.
- south-asiaAnthropic API in IndiaThe Digital Personal Data Protection Act, 2023 received assent in August 2023 and comes into force provision by provision, on dates the Central Government appoints. It is consent-based, with notice, security safeguards, breach notification, additional duties for Significant Data Fiduciaries, extraterritorial reach over processing connected with offering goods or services to people in India, and penalties up to 250 crore rupees. The DPDP Rules, 2025 supply the operative detail on a phased timetable: rules 1, 2 and 17 to 21 from publication in November 2025, the consent-manager rule one year later, and rules 3 and 5 to 16 — notice content, security safeguards, breach reporting, children’s verifiable consent, retention, Significant Data Fiduciary duties and cross-border transfer — eighteen months after publication. Until then the 2011 SPDI Rules and sectoral regimes remain the operative privacy law.
- southeast-asiaAnthropic API in SingaporePersonal Data Protection Act 2012 (Act 26 of 2012), supported by the Personal Data Protection Regulations 2021 (S 63/2021, in operation 1 February 2021). Consent, notification, purpose limitation, accuracy, protection, retention, transfer limitation and accountability obligations apply to any organisation processing personal data, including data used to train or run an AI system. The PDPC issues advisory guidelines that explain how those obligations land on AI — one set for AI recommendation and decision systems from March 2024, and one for generative AI published in July 2026. Sectoral layers sit above: the Cybersecurity Act for critical information infrastructure, HSA guidance for software medical devices, and the Health Information Act 2026 once it is brought into operation.
09Evidence
No sources were recorded for this answer. Nothing on this page should be treated as verified.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.