Federation changedapi/organization/federation
Nearest release: v2.1.286, published 6 hours before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
# Federation ## Federation › Issuers ### Create Federation Issuer #### Body parameters #### Returns #### Example ##### Response (200) ### List Federation Issuers #### Query parameters #### Returns #### Example ##### Response (200) ### Get Federation Issuer #### Path parameters #### Returns #### Example ##### Response (200) ### Update Federation Issuer #### Path parameters #### Body parameters #### Returns #### Example ##### Response (200) ### Archive Federation Issuer #### Path parameters #### Returns #### Example ##### Response (200) ## Federation › Rules ### Create Federation Rule #### Body parameters #### Returns #### Example ##### Response (200) ### List Federation Rules #### Query parameters #### Returns #### Example ##### Response (200) ### Get Federation Rule #### Path parameters #### Returns #### Example ##### Response (200) ### Update Federation Rule #### Path parameters #### Body parameters #### Returns #### Example ##### Response (200) ### Archive Federation Rule #### Path parameters #### Returns #### Example ##### Response (200) ## Federation › Rules › Workspaces ### Add Federation Rule Workspace #### Path parameters #### Body parameters #### Returns #### Example ##### Response (200) ### List Federation Rule Workspaces #### Path parameters #### Query parameters #### Returns #### Example ##### Response (200) ### Remove Federation Rule Workspace #### Path parameters #### Returns #### Example ##### Response (200)
The whole hunk
2601 lines, new pageA whole new page. There's nothing to diff it against, so here is what it says.
---
title: Federation
url: https://platform.claude.com/docs/en/api/organization/federation
---
# Federation
## Federation › Issuers
### Create Federation Issuer
**POST** `/v1/organizations/federation_issuers`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
Register an OIDC issuer that Anthropic will trust for workload identity
federation in your organization.
The `jwks` field controls how the issuer's signing keys are obtained and
takes one of three shapes selected by `type`: `discovery` (resolve keys
through OIDC discovery), `explicit_url` (fetch keys from a fixed JWKS
URL), or `inline` (provide a static key set). When `jwks.type` is
`discovery` and no `discovery_base` is set, the issuer URL must be
publicly reachable over HTTPS so Anthropic can fetch the discovery
document; for `explicit_url` and `inline` modes the issuer URL is only
matched as the JWT's `iss` claim and is not fetched.
#### Body parameters
- `issuer_url: string`
The `iss` claim value to match against.
minLength: 1
- `name: string`
Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.
minLength: 1, maxLength: 255
- `check_jti: optional boolean or null`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Defaults to true. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `jwks: optional JWKSDiscovery or JWKSExplicitURL or JWKSInline`
How signing keys are obtained. Defaults to OIDC discovery.
- `JWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `JWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `JWKSInline object`
JWKS supplied directly; no network fetch.
- `type: "inline"`
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `max_jwt_lifetime_seconds: optional number or null`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Defaults to 3600 (1h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
minimum: 1, maximum: 176400
#### Returns
- `FederationIssuer object`
Registered external OIDC identity provider.
Records an external IdP the organization trusts for the RFC 7523
jwt-bearer grant. The `issuer_url` must match the JWT `iss` claim exactly.
- `type: "federation_issuer"`
default: federation_issuer
- `id: string`
Tagged ID of the federation issuer.
- `archived_at: string or null`
If set, all rules referencing this issuer reject token exchange.
format: date-time
- `archived_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
- `check_jti: boolean`
Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
- `created_at: string`
When this issuer was created.
format: date-time
- `created_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
- `issuer_url: string`
The `iss` claim value. Incoming JWTs must match exactly.
- `jwks: JWKSDiscovery or JWKSExplicitURL or JWKSInline`
How signing keys are obtained for signature verification.
- `JWKSDiscovery object`
JWKS via the issuer's OIDC discovery document.
- `type: "discovery"`
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `discovery_base: optional string or null`
Set when the discovery URL differs from `issuer_url`.
- `JWKSExplicitURL object`
JWKS fetched from a fixed endpoint.
- `type: "explicit_url"`
- `url: string`
JWKS endpoint.
minLength: 1
- `ca_cert_pem: optional string or null`
Optional custom CA (PEM) for TLS verification of the JWKS fetch.
maxLength: 8192
- `JWKSInline object`
JWKS supplied directly; no network fetch.
- `type: "inline"`
- `keys: array of map[unknown]`
Inline JWK objects.
minItems: 1
- `jwks_polling_disabled_at: string or null`
If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session.
format: date-time
- `max_jwt_lifetime_seconds: number`
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
- `name: string`
Admin-chosen slug identifier.
- `poll_status: FederationIssuerPollStatus or null`
Live state of Anthropic's JWKS polling for this issuer. Populated on both single-issuer retrieval and list responses, including archived issuers. Typically null for inline-key issuers (no polling), or when poll status is temporarily unavailable or polling has not started yet.
- `consecutive_failures: number`
Consecutive fetch failures since the last success.
- `last_fetched_at: string or null`
When the last successful fetch completed.
format: date-time
- `next_poll_at: string or null`
When the next fetch is scheduled. Null if paused.
format: date-time
- `updated_at: string`
When this issuer was last updated.
format: date-time
- `updated_by_actor_id: string or null`
Tagged ID (`user_`/`svac_`) of the actor that last updated this issuer.
#### Example
```bash
curl https://api.anthropic.com/v1/organizations/federation_issuers \
-H 'Content-Type: application/json' \
-H 'anthropic-version: 2023-06-01' \
-H "X-Api-Key: $ANTHROPIC_API_KEY" \
-d '{
"issuer_url": "x",
"name": "x"
}'
```
##### Response (200)
```json
{
"id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"check_jti": true,
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"issuer_url": "https://token.actions.githubusercontent.com",
"jwks": {
"type": "discovery",
"ca_cert_pem": "ca_cert_pem",
"discovery_base": "discovery_base"
},
"jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
"max_jwt_lifetime_seconds": 0,
"name": "github-actions",
"poll_status": {
"consecutive_failures": 0,
"last_fetched_at": "2019-12-27T18:11:19.117Z",
"next_poll_at": "2019-12-27T18:11:19.117Z"
},
"type": "federation_issuer",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id"
}
```
### List Federation Issuers
**GET** `/v1/organizations/federation_issuers`
**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).
List federation issuers in your organization.
Archived issuers are excluded unless `include_archived=true`.
#### Query parameters
- `include_archived: optional boolean`
Include archived resources. Defaults to false.
default: false
Cut at 300 lines. The page has the rest.
No line in this hunk matches that.