- The Auth & Identity team builds the authentication, authorization, and identity platform that underpins every Anthropic product: the API, Claude Code, Claude
- Ai, and our Enterprise offerings
- Every login, API key, OAuth token, access decision, and organization record flows through the systems we own
- As Claude moves from a chat product to an agentic platform, we are defining what identity and access look like when the actor is a human, a service account, or an autonomous agent acting on someone’s behalf
- We are a platform team with a product surface
- The horizontal is the set of services every product consumes: credential minting and exchange, authorization controls, and the canonical record of users, service accounts, agents, and the organizations they belong to
- The vertical is the experience where admins author that policy: SSO and SCIM setup, roles and permissions, IP allowlisting, and API key policies
- Our work falls into four pillars:
- Authentication – Who you are. Credential minting, exchange, and lifecycle; sessions; workload identity federation; auth for async and agentic workloads
- Authorization – What you can do. The policy framework for model, membership, role, and resource access
- Identity – Who belongs to what. The tenant and organization model, and first-class identity for humans, service accounts, and agents, portable across surfaces and cloud environments
- Enterprise – How enterprises connect. SSO, SCIM, login policies, and the admin controls that let customers provision and govern users from their own identity provider
- You will own critical, high-traffic systems end to end, from design through rollout, operations, and iteration, and help shape the technical strategy for how identity and access work across Anthropic. Representative problems we are working on right now:
- Designing credentials for agents and long-running autonomous workloads
- Routing every access decision through a unified authorization system, with low latency, security guarantees, and multi-region resilience
- Building a first-class identity model for service accounts and agents, and linking those identities to other identity and auth systems
- Global distribution and multi-region failover for some of the company’s most mission-critical services
- Deepening enterprise integration: login policies and recovery methods, self-service allowlisting, and tighter integrations with providers
- You will work closely with product, security, infrastructure, and the product teams that consume our primitives, and you will be expected to set technical direction, not just execute on it. Many of the problems are 0-to-1 with no established pattern to copy; others are careful migrations of systems that every Anthropic customer depends on in the hot path
Benefits
- Comprehensive health, dental, and vision insurance for you and your dependents
- Inclusive fertility benefits via Carrot Fertility
- 22 weeks of paid parental leave
- Flexible paid time off and absence policies
- Mental health support for you and your dependents
- Competitive salary and equity packages
- Optional equity donation matching at a 1:1 ratio, up to 25% of your equity grant
- Retirement plans with competitive matching
- Life and income protection plans$500/month flexible wellness and time saver stipend
- Commuter benefits
- Annual education stipend
- Home office stipends
- Relocation support for those moving for Anthropic
- Daily meals and snacks in the office
Have 8+ years of experience building and operating backend or platform systems at scale, ideally including identity, authentication, authorization, or security-adjacent infrastructureAre familiar with using AI tools as part of your software development workflowHave worked with some of: OAuth 2.0 and OIDC, SAML, SCIM, JWTs and token exchange, workload identity federation, policy engines such as Cedar or OPA, or RBAC and resource-level access control modelsAre comfortable owning large migrations in live, high-traffic systems: shadow modes, incremental rollouts, and clean retirement of legacy pathsCare deeply about reliability and security. You design for on-call, failure modes, revocation, and the engineer who inherits your system, and you treat availability of auth as table stakes for every product built on itCan navigate ambiguity and make sound technical decisions independently, and communicate clearly with cross-functional partners and stakeholdersTake a product-focused approach to platform work and build primitives that are easy for other engineers to adopt correctly, with documentation and self-service as part of the deliverableMinimum years of experience: Years of experience required will correlate with the internal job level requirements for the positionMinimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experienceRequired field of study: A field relevant to the role as demonstrated through coursework, training, or professional experienceWe encourage you to apply even if you do not believe you meet every single qualificationExperience with globally distributed databases and multi-region service architectureExperience working in Go, Python, Rust, or TypeScript across a rapidly changing codebasePrior work on enterprise identity integrations with major identity providers and cloud IAM systems