Access required: Claude allocation must be enabled for your PAIR organisation. Contact help@pairnow.ai if you would like access and we will enable it for your organisation.
Claude allocation is available only for Claude Enterprise organisations.
Before you begin
You need:
- a Claude Enterprise organisation with usage credits enabled
- access to the Claude Enterprise Primary Owner account
- PAIR organisation admin access
Create one dedicated key
- Sign in to Claude Enterprise as the Primary Owner.
- Go to Organisation settings > API.
- Enable public API access if it is currently disabled.
- Create one key named PAIR.
- Select the four scopes below.
- Create the key and copy the full secret. Anthropic displays it once.
PAIR needs these scopes:
-
read:analytics- reads per-user cost and token usage -
read:members- reads the Claude members that PAIR matches to learners -
read:spend_limits- reads each member’s effective monthly limit and current spend -
write:spend_limits- applies the monthly allowance configured in PAIR
Add the key to PAIR
- Open the Claude allocation page in your organisation dashboard.
- Select 'Claude API Key' under the Configure button to the right of Manage default allowances.
- Paste the full Claude Admin API key and save. The API key should start with 'sk-' prefix.
Only a PAIR organisation admin can complete this step. Keep the key out of email, Teams messages and support tickets.
How PAIR protects the key
PAIR stores one Claude API key per PAIR organisation. The key is encrypted before storage and is only decrypted by PAIR’s backend when making an authorised request to Anthropic on behalf of that organisation.
PAIR does not expose the stored key in the application UI, API responses, logs, traces, analytics events, or support tooling. Anthropic authentication headers are redacted from operational telemetry.
Access to systems handling encrypted credentials is restricted to authorised PAIR operational roles and application runtime infrastructure. Regular developers cannot retrieve customer Claude keys.
When a key is replaced, PAIR overwrites the stored encrypted credential for that organisation and does not retain the previous key value. Customers can revoke the key directly from Claude Enterprise at any time.
PAIR operates under SOC 2 and ISO 27001-aligned security controls, with data processing governed by PAIR’s DPA where applicable. These controls support PAIR’s approach to access management, operational security, incident response, and protection of customer credentials.
Choose which users the feature applies to
Share the work email addresses of the users to be included with your PAIR contact. PAIR will configure an allowlist so the feature applies only to those users. Each email address should match the address used in both Claude and PAIR.
To add or remove users later, contact PAIR with the changes you need.
What to expect after connecting
PAIR primarily matches users by work email, so the email address should be the same in Claude and PAIR.
Cost and token usage can take up to 24 hours to appear (although it's usually much faster). Allowance changes are processed straight away.