Staff+ Software Engineer, Auth & Identity

Anthropic · San Francisco, CA | New York City, NY · Engineering

Posted 2026-08-21

Apply for this role →

About the role

The Auth & Identity team builds the authentication, authorization, and identity platform that underpins every Anthropic product: the API, Claude Code, Claude.ai, and our Enterprise offerings. Every login, API key, OAuth token, access decision, and organization record flows through the systems we own. As Claude moves from a chat product to an agentic platform, we are defining what identity and access look like when the actor is a human, a service account, or an autonomous agent acting on someone's behalf.

We are a platform team with a product surface. The horizontal is the set of services every product consumes: credential minting and exchange, authorization controls, and the canonical record of users, service accounts, agents, and the organizations they belong to. The vertical is the experience where admins author that policy: SSO and SCIM setup, roles and permissions, IP allowlisting, and API key policies.

Our work falls into four pillars:

Authentication – Who you are. Credential minting, exchange, and lifecycle; sessions; workload identity federation; auth for async and agentic workloads.

Authorization – What you can do. The policy framework for model, membership, role, and resource access.

Identity – Who belongs to what. The tenant and organization model, and first-class identity for humans, service accounts, and agents, portable across surfaces and cloud environments.

Enterprise – How enterprises connect. SSO, SCIM, login policies, and the admin controls that let customers provision and govern users from their own identity provider.

What you'll do

You will own critical, high-traffic systems end to end, from design through rollout, operations, and iteration, and help shape the technical strategy for how identity and access work across Anthropic. Representative problems we are working on right now:

Designing credentials for agents and long-running autonomous workloads.

Routing every access decision through a unified authorization system, with low latency, security guarantees, and multi-region resilience.

Building a first-class identity model for service accounts and agents, and linking those identities to other identity and auth systems.

Global distribution and multi-region failover for some of the company’s most mission-critical services.

Deepening enterprise integration: login policies and recovery methods, self-service allowlisting, and tighter integrations with providers.

You will work closely with product, security, infrastructure, and the product teams that consume our primitives, and you will be expected to set technical direction, not just execute on it. Many of the problems are 0-to-1 with no established pattern to copy; others are careful migrations of systems that every Anthropic customer depends on in the hot path.

You might be a good fit if you:

Have 8+ years of experience building and operating backend or platform systems at scale, ideally including identity, authentication, authorization, or security-adjacent infrastructure.

Have worked with some of: OAuth 2.0 and OIDC, SAML, SCIM, JWTs and token exchange, workload identity federation, policy engines such as Cedar or OPA, or RBAC and resource-level access control models.

Care deeply about reliability and security. You design for on-call, failure modes, revocation, and the engineer who inherits your system, and you treat availability of auth as table stakes for every product built on it.

Are comfortable owning large migrations in live, high-traffic systems: shadow modes, incremental rollouts, and clean retirement of legacy paths.

Take a product-focused approach to platform work and build primitives that are easy for other engineers to adopt correctly, with documentation and self-service as part of the deliverable.

Can navigate ambiguity and make sound technical decisions independently, and communicate clearly with cross-functional partners and stakeholders.

Are familiar with using AI tools as part of your software development workflow.

Strong candidates may also have

Experience with globally distributed databases and multi-region service architecture.

Experience working in Go, Python, Rust, or TypeScript across a rapidly changing codebase.

Prior work on enterprise identity integrations with major identity providers and cloud IAM systems.

Deadline to apply: None. Applications will be reviewed on a rolling basis.

Location Preference: Preference will be given to candidates based in NY, SEA, SF or the Bay Area given the current location of team.

The annual compensation range for this role is listed below.

For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonuses target and annual base salary for the role.

Annual Salary:

$405,000—$485,000 USD

Apply for this role →

← Back to all jobs