| title | Legal and compliance |
|---|---|
| source | https://code.claude.com/docs/en/legal-and-compliance |
| category | code |
| generated | true |
Fetch the complete documentation index at: https://code.claude.com/docs/llms.txt Use this file to discover all available pages before exploring further.
Legal agreements, compliance certifications, and security information for Claude Code.
Your use of Claude Code is subject to:
- Commercial Terms - for Team, Enterprise, and Claude API users
- Consumer Terms of Service - for Free, Pro, and Max users
Whether you're using the Claude API directly (1P) or accessing it through Amazon Bedrock or Google Cloud's Agent Platform (3P), your existing commercial agreement will apply to Claude Code usage, unless we've mutually agreed otherwise.
If a customer has a Business Associate Agreement (BAA) with us, and wants to use Claude Code, the BAA will automatically extend to cover Claude Code if the customer has executed a BAA and has Zero Data Retention (ZDR) activated. The BAA will be applicable to that customer's API traffic flowing through Claude Code. ZDR is enabled on a per-organization basis, so each organization must have ZDR enabled separately to be covered under the BAA.
Claude Code usage is subject to the Anthropic Usage Policy. Advertised usage limits for Pro and Max plans assume ordinary, individual usage of Claude Code and the Agent SDK.
Claude Code authenticates with Anthropic's servers using OAuth tokens or API keys. These authentication methods serve different purposes:
- OAuth authentication is intended exclusively for purchasers of Claude Free, Pro, Max, Team, and Enterprise subscription plans and is designed to support ordinary use of Claude Code and other native Anthropic applications. For the sign-in steps, see Logging in to your Claude account; for how Claude Code performs OAuth authentication, see Authentication.
- Developers building products or services that interact with Claude's capabilities, including those using the Agent SDK, should use API key authentication through Claude Console or a supported cloud provider. Anthropic does not permit third-party developers to offer Claude.ai login or to route requests through Free, Pro, or Max plan credentials on behalf of their users.
Anthropic reserves the right to take measures to enforce these restrictions and may do so without prior notice.
For questions about permitted authentication methods for your use case, please contact sales.
You can find more information in the Anthropic Trust Center and Transparency Hub.
Anthropic manages our security program through HackerOne. Use this form to report vulnerabilities.
© Anthropic PBC. All rights reserved. Use is subject to applicable Anthropic Terms of Service.