Anthropic Multi-Environment Setup
Overview
Configure isolated Claude API environments with per-env API keys, model selection, and spend controls using Anthropic Workspaces.
Environment Configuration
# config.py
import os
from dataclasses import dataclass
@dataclass
class ClaudeConfig:
api_key: str
model: str
max_tokens: int
max_retries: int
timeout: float
monthly_budget_usd: float
CONFIGS = {
"development": ClaudeConfig(
api_key=os.environ["ANTHROPIC_API_KEY_DEV"],
model="claude-haiku-4-20250514", # Cheap for dev
max_tokens=256,
max_retries=1,
timeout=15.0,
monthly_budget_usd=10.0,
),
"staging": ClaudeConfig(
api_key=os.environ["ANTHROPIC_API_KEY_STAGING"],
model="claude-sonnet-4-20250514",
max_tokens=1024,
max_retries=2,
timeout=30.0,
monthly_budget_usd=50.0,
),
"production": ClaudeConfig(
api_key=os.environ["ANTHROPIC_API_KEY_PROD"],
model="claude-sonnet-4-20250514",
max_tokens=4096,
max_retries=5,
timeout=120.0,
monthly_budget_usd=5000.0,
),
}
def get_config() -> ClaudeConfig:
env = os.getenv("APP_ENV", "development")
return CONFIGS[env]
Anthropic Workspaces (Key Isolation)
Create separate Workspaces in console.anthropic.com:
| Workspace |
Purpose |
Rate Limit Tier |
dev |
Development & testing |
Tier 1 |
staging |
Pre-production validation |
Tier 2 |
production |
Live traffic |
Tier 3+ |
Each workspace has independent API keys, usage tracking, and rate limits.
Environment Files
# .env.development
ANTHROPIC_API_KEY_DEV=sk-ant-api03-dev-...
APP_ENV=development
# .env.staging
ANTHROPIC_API_KEY_STAGING=sk-ant-api03-stg-...
APP_ENV=staging
# .env.production (stored in secret manager, not files)
ANTHROPIC_API_KEY_PROD=sk-ant-api03-prd-...
APP_ENV=production
Client Factory
import anthropic
def create_client() -> anthropic.Anthropic:
config = get_config()
return anthropic.Anthropic(
api_key=config.api_key,
max_retries=config.max_retries,
timeout=config.timeout,
)
Per-Environment Model Override
# Development: always use Haiku (cheapest)
# Staging: use production model for accuracy testing
# Production: use configured model
def get_model(override: str | None = None) -> str:
if override:
return override
return get_config().model
Error Handling
| Issue |
Cause |
Fix |
| Dev key used in prod |
Wrong env loaded |
Validate key prefix matches environment |
| Staging rate limited |
Low tier workspace |
Upgrade staging workspace tier |
| Cost overrun in dev |
No budget guard |
Add per-env spend limits |
Prerequisites
- Define the environment inventory, workspace/key ownership, model policy, rate and spend budgets, data classification, and promotion approver.
- Provision separate least-privileged credentials through a secret manager; production secrets must not exist in repository files, shell history, examples, or CI logs.
- Prepare synthetic fixtures, environment isolation tests, a canary route, and a rollback configuration before changing any workspace or client factory.
Instructions
- Map each environment to exactly one approved Anthropic workspace and secret-manager reference. Validate environment identity at startup and fail closed on a missing or mismatched key.
- Load configuration through the environment-specific client factory, pin model and API settings, and enforce per-environment token, rate, timeout, retry, data, and destination limits.
- Run authentication, cross-environment isolation, budget, and request-shape tests with synthetic fixtures. Capture only aggregate pass/fail and usage metadata.
- Promote a reviewed artifact from staging to a small internal canary before production. Require owner approval and verify no production traffic or data can reach non-production workspaces.
- On drift, leaked scope, or failed health checks, disable the route, restore the previous environment mapping, rotate affected credentials, and retain a redacted receipt.
Output
Produce an environment receipt containing environment/workspace classes, config and artifact digests, model policy, isolation and synthetic-test results, canary/approval state, secret rotation status, retention, and rollback reference. Exclude API keys, endpoint tokens, prompts, responses, and member identifiers.
Examples
Run a synthetic fixture-request-001 through development and staging with separate keys, assert workspace_crossing=0; production_key_in_nonprod=0; content_logged=0, and record canary=internal; approval=pending. Promotion remains blocked until the owner approves the staging receipt.
Resources
Next Steps
For monitoring, see anth-observability.
1---2name: anth-multi-env-setup3description: Configure Claude API across dev, staging, and production environments with isolated keys, model routing, and spend controls per environment. Trigger with phrases like "anthropic environments", "claude multi-env", "anthropic staging setup", "claude dev vs prod config".4license: MIT5---6# Anthropic Multi-Environment Setup
7
8## Overview
9
10Configure isolated Claude API environments with per-env API keys, model selection, and spend controls using Anthropic Workspaces.
11
12## Environment Configuration
13
14```python
15# config.py
16import os
17from dataclasses import dataclass
18
19@dataclass
20class ClaudeConfig:
21 api_key: str
22 model: str
23 max_tokens: int
24 max_retries: int
25 timeout: float
26 monthly_budget_usd: float
27
28CONFIGS = {
29 "development": ClaudeConfig(
30 api_key=os.environ["ANTHROPIC_API_KEY_DEV"],
31 model="claude-haiku-4-20250514", # Cheap for dev
32 max_tokens=256,
33 max_retries=1,
34 timeout=15.0,
35 monthly_budget_usd=10.0,
36 ),
37 "staging": ClaudeConfig(
38 api_key=os.environ["ANTHROPIC_API_KEY_STAGING"],
39 model="claude-sonnet-4-20250514",
40 max_tokens=1024,
41 max_retries=2,
42 timeout=30.0,
43 monthly_budget_usd=50.0,
44 ),
45 "production": ClaudeConfig(
46 api_key=os.environ["ANTHROPIC_API_KEY_PROD"],
47 model="claude-sonnet-4-20250514",
48 max_tokens=4096,
49 max_retries=5,
50 timeout=120.0,
51 monthly_budget_usd=5000.0,
52 ),
53}
54
55def get_config() -> ClaudeConfig:
56 env = os.getenv("APP_ENV", "development")
57 return CONFIGS[env]
58```
59
60## Anthropic Workspaces (Key Isolation)
61
62Create separate Workspaces in [console.anthropic.com](https://console.anthropic.com/settings/workspaces):
63
64| Workspace | Purpose | Rate Limit Tier |
65|-----------|---------|-----------------|
66| `dev` | Development & testing | Tier 1 |
67| `staging` | Pre-production validation | Tier 2 |
68| `production` | Live traffic | Tier 3+ |
69
70Each workspace has independent API keys, usage tracking, and rate limits.
71
72## Environment Files
73
74```bash
75# .env.development
76ANTHROPIC_API_KEY_DEV=sk-ant-api03-dev-...
77APP_ENV=development
78
79# .env.staging
80ANTHROPIC_API_KEY_STAGING=sk-ant-api03-stg-...
81APP_ENV=staging
82
83# .env.production (stored in secret manager, not files)
84ANTHROPIC_API_KEY_PROD=sk-ant-api03-prd-...
85APP_ENV=production
86```
87
88## Client Factory
89
90```python
91import anthropic
92
93def create_client() -> anthropic.Anthropic:
94 config = get_config()
95 return anthropic.Anthropic(
96 api_key=config.api_key,
97 max_retries=config.max_retries,
98 timeout=config.timeout,
99 )
100```
101
102## Per-Environment Model Override
103
104```python
105# Development: always use Haiku (cheapest)
106# Staging: use production model for accuracy testing
107# Production: use configured model
108
109def get_model(override: str | None = None) -> str:
110 if override:
111 return override
112 return get_config().model
113```
114
115## Error Handling
116
117| Issue | Cause | Fix |
118|-------|-------|-----|
119| Dev key used in prod | Wrong env loaded | Validate key prefix matches environment |
120| Staging rate limited | Low tier workspace | Upgrade staging workspace tier |
121| Cost overrun in dev | No budget guard | Add per-env spend limits |
122
123## Prerequisites
124
125- Define the environment inventory, workspace/key ownership, model policy, rate and spend budgets, data classification, and promotion approver.
126- Provision separate least-privileged credentials through a secret manager; production secrets must not exist in repository files, shell history, examples, or CI logs.
127- Prepare synthetic fixtures, environment isolation tests, a canary route, and a rollback configuration before changing any workspace or client factory.
128
129## Instructions
130
1311. Map each environment to exactly one approved Anthropic workspace and secret-manager reference. Validate environment identity at startup and fail closed on a missing or mismatched key.
1322. Load configuration through the environment-specific client factory, pin model and API settings, and enforce per-environment token, rate, timeout, retry, data, and destination limits.
1333. Run authentication, cross-environment isolation, budget, and request-shape tests with synthetic fixtures. Capture only aggregate pass/fail and usage metadata.
1344. Promote a reviewed artifact from staging to a small internal canary before production. Require owner approval and verify no production traffic or data can reach non-production workspaces.
1355. On drift, leaked scope, or failed health checks, disable the route, restore the previous environment mapping, rotate affected credentials, and retain a redacted receipt.
136
137## Output
138
139Produce an environment receipt containing environment/workspace classes, config and artifact digests, model policy, isolation and synthetic-test results, canary/approval state, secret rotation status, retention, and rollback reference. Exclude API keys, endpoint tokens, prompts, responses, and member identifiers.
140
141## Examples
142
143Run a synthetic `fixture-request-001` through development and staging with separate keys, assert `workspace_crossing=0; production_key_in_nonprod=0; content_logged=0`, and record `canary=internal; approval=pending`. Promotion remains blocked until the owner approves the staging receipt.
144
145## Resources
146
147- [Workspaces](https://docs.anthropic.com/en/docs/administration/workspaces)
148- [Console](https://console.anthropic.com)
149
150## Next Steps
151
152For monitoring, see `anth-observability`.