Follow Discord
Sweep 09 Oct 2026 · 17:27Z Build v2.1.296 517 read Stable v2.1.287 Latest v2.1.296 Next v2.1.296 Feeds RSS JSON llms.txt llms-full.txt Unofficial
One change · api

wif-admin-api changedmanage-claude/wif-admin-api

Nearest release: v2.1.292, published 11 hours before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.

Recorded here
Lines+107added
Lines−112removed
From line 69 where the diff opens
First seen 14 Aug 2026 this site's first read of the page
Recorded edits4to this page, all time

The whole hunk

from line 69, old and new numbered
/
lines
from line 69
6969 
7070All endpoints live under `https://api.anthropic.com/v1/organizations/`. Every request to the federation and service-account endpoints needs the API version header and the bearer token:
7171 
72In the SDKs these endpoints are `client.beta.organization.service_accounts`, `client.beta.organization.federation.issuers`, and `client.beta.organization.federation.rules` (`ant beta:organization:service-accounts`, `federation:issuers`, and `federation:rules` in the CLI). The SDK and CLI examples construct the default client, which sends the bearer token from `ANTHROPIC_AUTH_TOKEN`, or, in an automated workload, performs the federation exchange itself as described in [Bootstrap a workload to manage WIF](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#bootstrap-a-workload-to-manage-wif). SDK list methods fetch further pages on demand, so `limit` sets the page size; the PHP and Ruby examples read one page.
72In the SDKs these endpoints are `client.organization.service_accounts` (typescript: `client.organization.serviceAccounts`; csharp, go: `client.Organization.ServiceAccounts`; java: `client.organization().serviceAccounts()`; php: `$client->organization->serviceAccounts`), `client.organization.federation.issuers` (csharp, go: `client.Organization.Federation.Issuers`; java: `client.organization().federation().issuers()`; php: `$client->organization->federation->issuers`), and `client.organization.federation.rules` (csharp, go: `client.Organization.Federation.Rules`; java: `client.organization().federation().rules()`; php: `$client->organization->federation->rules`) (`ant organization:service-accounts`, `federation:issuers`, and `federation:rules` in the CLI). The SDK and CLI examples construct the default client, which sends the bearer token from `ANTHROPIC_AUTH_TOKEN`, or, in an automated workload, performs the federation exchange itself as described in [Bootstrap a workload to manage WIF](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#bootstrap-a-workload-to-manage-wif). SDK list methods fetch further pages on demand, so `limit` sets the page size; the PHP and Ruby examples read one page.
7373 
7474<CodeGroup>
7575 ```bash cURL
from line 79
7979 ```
8080 
8181 ```bash CLI
82 ant beta:organization:service-accounts list
82 ant organization:service-accounts list
8383 ```
8484 
8585 ```python Python
8686 client = anthropic.Anthropic()
8787 
88 service_accounts = client.beta.organization.service_accounts.list()
88 service_accounts = client.organization.service_accounts.list()
8989 
9090 for service_account in service_accounts:
9191 print(f"{service_account.id}: {service_account.name}")
from line 94
9494 ```typescript TypeScript
9595 const client = new Anthropic();
9696 
97 for await (const serviceAccount of client.beta.organization.serviceAccounts.list()) {
97 for await (const serviceAccount of client.organization.serviceAccounts.list()) {
9898 console.log(`${serviceAccount.id}: ${serviceAccount.name}`);
9999 }
100100 ```
from line 102
102102 ```csharp C#
103103 AnthropicClient client = new();
104104 
105 var page = await client.Beta.Organization.ServiceAccounts.List();
105 var page = await client.Organization.ServiceAccounts.List();
106106 
107107 await foreach (var serviceAccount in page.Paginate())
108108 {
from line 113
113113 ```go Go
114114 client := anthropic.NewClient()
115115 
116 serviceAccounts := client.Beta.Organization.ServiceAccounts.ListAutoPaging(context.Background(), anthropic.BetaOrganizationServiceAccountListParams{})
116 serviceAccounts := client.Organization.ServiceAccounts.ListAutoPaging(context.Background(), anthropic.OrganizationServiceAccountListParams{})
117117 
118118 for serviceAccounts.Next() {
119119 serviceAccount := serviceAccounts.Current()
from line 127
127127 ```java Java
128128 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
129129 
130 var serviceAccounts = client.beta().organization().serviceAccounts().list();
130 var serviceAccounts = client.organization().serviceAccounts().list();
131131 
132132 for (var serviceAccount : serviceAccounts.autoPager()) {
133133 IO.println(serviceAccount.id() + ": " + serviceAccount.name());
from line 137
137137 ```php PHP
138138 $client = new Client();
139139 
140 $serviceAccounts = $client->beta->organization->serviceAccounts->list();
140 $serviceAccounts = $client->organization->serviceAccounts->list();
141141 
142142 foreach ($serviceAccounts->getItems() as $serviceAccount) {
143143 echo "{$serviceAccount->id}: {$serviceAccount->name}\n";
from line 147
147147 ```ruby Ruby
148148 client = Anthropic::Client.new
149149 
150 service_accounts = client.beta.organization.service_accounts.list
150 service_accounts = client.organization.service_accounts.list
151151 
152152 service_accounts.data.each do |service_account|
153153 puts "#{service_account.id}: #{service_account.name}"
from line 176
176176 ```
177177 
178178 ```bash CLI
179 ant beta:organization:service-accounts create \
179 ant organization:service-accounts create \
180180 --name inference-worker \
181181 --organization-role developer
182182 ```
from line 184
184184 ```python Python
185185 client = anthropic.Anthropic()
186186 
187 service_account = client.beta.organization.service_accounts.create(
187 service_account = client.organization.service_accounts.create(
188188 name="inference-worker", organization_role="developer"
189189 )
190190 
from line 195
195195 ```typescript TypeScript
196196 const client = new Anthropic();
197197 
198 const serviceAccount = await client.beta.organization.serviceAccounts.create({
198 const serviceAccount = await client.organization.serviceAccounts.create({
199199 name: "inference-worker",
200200 organization_role: "developer"
201201 });
from line 205
205205 ```
206206 
207207 ```csharp C#
208 using Anthropic.Models.Beta.Organization.ServiceAccounts;
208 using Anthropic.Models.Organization.ServiceAccounts;
209209 
210210 AnthropicClient client = new();
211211 
212 var serviceAccount = await client.Beta.Organization.ServiceAccounts.Create(new()
212 var serviceAccount = await client.Organization.ServiceAccounts.Create(new()
213213 {
214214 Name = "inference-worker",
215215 OrganizationRole = OrganizationRole.Developer
from line 222
222222 ```go Go
223223 client := anthropic.NewClient()
224224 
225 serviceAccount, err := client.Beta.Organization.ServiceAccounts.New(context.Background(), anthropic.BetaOrganizationServiceAccountNewParams{
225 serviceAccount, err := client.Organization.ServiceAccounts.New(context.Background(), anthropic.OrganizationServiceAccountNewParams{
226226 Name: "inference-worker",
227 OrganizationRole: anthropic.BetaOrganizationServiceAccountNewParamsOrganizationRoleDeveloper,
227 OrganizationRole: anthropic.OrganizationServiceAccountNewParamsOrganizationRoleDeveloper,
228228 })
229229 if err != nil {
230230 log.Fatal(err)
from line 235
235235 ```
236236 
237237 ```java Java
238 import com.anthropic.models.beta.organization.serviceaccounts.ServiceAccountCreateParams;
238 import com.anthropic.models.organization.serviceaccounts.ServiceAccountCreateParams;
239239 
240240 void main() {
241241 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
from line 244
244244 .name("inference-worker")
245245 .organizationRole(ServiceAccountCreateParams.OrganizationRole.DEVELOPER)
246246 .build();
247 var serviceAccount = client.beta().organization().serviceAccounts().create(params);
247 var serviceAccount = client.organization().serviceAccounts().create(params);
248248 
249249 IO.println("id: " + serviceAccount.id());
250250 IO.println("name: " + serviceAccount.name());
from line 252
252252 ```
253253 
254254 ```php PHP
255 use Anthropic\Beta\Organization\ServiceAccounts\ServiceAccountCreateParams\OrganizationRole;
255 use Anthropic\Organization\ServiceAccounts\ServiceAccountCreateParams\OrganizationRole;
256256 // ...
257257 
258258 $client = new Client();
259259 
260 $serviceAccount = $client->beta->organization->serviceAccounts->create(
260 $serviceAccount = $client->organization->serviceAccounts->create(
261261 name: 'inference-worker',
262262 organizationRole: OrganizationRole::DEVELOPER,
263263 );
from line 269
269269 ```ruby Ruby
270270 client = Anthropic::Client.new
271271 
272 service_account = client.beta.organization.service_accounts.create(
272 service_account = client.organization.service_accounts.create(
273273 name: "inference-worker",
274274 organization_role: :developer
275275 )
from line 289
289289 ```
290290 
291291 ```bash CLI
292 ant beta:organization:service-accounts list --limit 20
292 ant organization:service-accounts list --limit 20
293293 ```
294294 
295295 ```python Python
296296 client = anthropic.Anthropic()
297297 
298 service_accounts = client.beta.organization.service_accounts.list(limit=20)
298 service_accounts = client.organization.service_accounts.list(limit=20)
299299 
300300 for service_account in service_accounts:
301301 print(f"{service_account.id}: {service_account.name}")
from line 304
304304 ```typescript TypeScript
305305 const client = new Anthropic();
306306 
307 for await (const serviceAccount of client.beta.organization.serviceAccounts.list({
307 for await (const serviceAccount of client.organization.serviceAccounts.list({
308308 limit: 20
309309 })) {
310310 console.log(`${serviceAccount.id}: ${serviceAccount.name}`);
from line 314
314314 ```csharp C#
315315 AnthropicClient client = new();
316316 
317 var page = await client.Beta.Organization.ServiceAccounts.List(new() { Limit = 20 });
317 var page = await client.Organization.ServiceAccounts.List(new() { Limit = 20 });
318318 
319319 await foreach (var serviceAccount in page.Paginate())
320320 {
from line 325
325325 ```go Go
326326 client := anthropic.NewClient()
327327 
328 serviceAccounts := client.Beta.Organization.ServiceAccounts.ListAutoPaging(context.Background(), anthropic.BetaOrganizationServiceAccountListParams{
328 serviceAccounts := client.Organization.ServiceAccounts.ListAutoPaging(context.Background(), anthropic.OrganizationServiceAccountListParams{
329329 Limit: anthropic.Int(20),
330330 })
331331 
from line 339
339339 ```
340340 
341341 ```java Java
342 import com.anthropic.models.beta.organization.serviceaccounts.ServiceAccountListParams;
342 import com.anthropic.models.organization.serviceaccounts.ServiceAccountListParams;
343343 
344344 void main() {
345345 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
from line 347
347347 var params = ServiceAccountListParams.builder()
348348 .limit(20)
349349 .build();
350 var serviceAccounts = client.beta().organization().serviceAccounts().list(params);
350 var serviceAccounts = client.organization().serviceAccounts().list(params);
351351 
352352 for (var serviceAccount : serviceAccounts.autoPager()) {
353353 IO.println(serviceAccount.id() + ": " + serviceAccount.name());
from line 358
358358 ```php PHP
359359 $client = new Client();
360360 
361 $serviceAccounts = $client->beta->organization->serviceAccounts->list(limit: 20);
361 $serviceAccounts = $client->organization->serviceAccounts->list(limit: 20);
362362 
363363 foreach ($serviceAccounts->getItems() as $serviceAccount) {
364364 echo "{$serviceAccount->id}: {$serviceAccount->name}\n";
from line 368
368368 ```ruby Ruby
369369 client = Anthropic::Client.new
370370 
371 service_accounts = client.beta.organization.service_accounts.list(limit: 20)
371 service_accounts = client.organization.service_accounts.list(limit: 20)
372372 
373373 service_accounts.data.each do |service_account|
374374 puts "#{service_account.id}: #{service_account.name}"
from line 386
386386 ```
387387 
388388 ```bash CLI
389 ant beta:organization:service-accounts archive svac_01ABCDEFabcdef0123456789XY
389 ant organization:service-accounts archive svac_01ABCDEFabcdef0123456789XY
390390 ```
391391 
392392 ```python Python
393393 client = anthropic.Anthropic()
394394 
395 service_account = client.beta.organization.service_accounts.archive(
395 service_account = client.organization.service_accounts.archive(
396396 "svac_01ABCDEFabcdef0123456789XY"
397397 )
398398 
from line 403
403403 ```typescript TypeScript
404404 const client = new Anthropic();
405405 
406 const serviceAccount = await client.beta.organization.serviceAccounts.archive(
406 const serviceAccount = await client.organization.serviceAccounts.archive(
407407 "svac_01ABCDEFabcdef0123456789XY"
408408 );
409409 
from line 414
414414 ```csharp C#
415415 AnthropicClient client = new();
416416 
417 var serviceAccount = await client.Beta.Organization.ServiceAccounts.Archive(
417 var serviceAccount = await client.Organization.ServiceAccounts.Archive(
418418 "svac_01ABCDEFabcdef0123456789XY"
419419 );
420420 
from line 425
425425 ```go Go
426426 client := anthropic.NewClient()
427427 
428 serviceAccount, err := client.Beta.Organization.ServiceAccounts.Archive(
428 serviceAccount, err := client.Organization.ServiceAccounts.Archive(
429429 context.Background(),
430430 "svac_01ABCDEFabcdef0123456789XY",
431 anthropic.BetaOrganizationServiceAccountArchiveParams{},
432431 )
433432 if err != nil {
434433 log.Fatal(err)
from line 440
441440 ```java Java
442441 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
443442 
444 var serviceAccount = client.beta().organization().serviceAccounts()
443 var serviceAccount = client.organization().serviceAccounts()
445444 .archive("svac_01ABCDEFabcdef0123456789XY");
446445 
447446 IO.println("id: " + serviceAccount.id());
from line 450
451450 ```php PHP
452451 $client = new Client();
453452 
454 $serviceAccount = $client->beta->organization->serviceAccounts->archive(
453 $serviceAccount = $client->organization->serviceAccounts->archive(
455454 serviceAccountID: 'svac_01ABCDEFabcdef0123456789XY',
456455 );
457456 
from line 462
463462 client = Anthropic::Client.new
464463 
465464 service_account_id = "svac_01ABCDEFabcdef0123456789XY"
466 service_account = client.beta.organization.service_accounts.archive(service_account_id)
465 service_account = client.organization.service_accounts.archive(service_account_id)
467466 
468467 puts "id: #{service_account.id}"
469468 puts "archived_at: #{service_account.archived_at}"
from line 484
485484 
486485To read or update a single service account, use `GET` and `POST` on `/v1/organizations/service_accounts/{service_account_id}`. A service account must be a member of a workspace before federated tokens can act in it. Every service account has an implicit membership in your organization's default workspace; add explicit memberships for other workspaces with `GET`, `POST`, and `DELETE` on `/v1/organizations/service_accounts/{service_account_id}/workspaces`, where `DELETE` targets `.../workspaces/{workspace_id}`.
487486 
488For complete parameter details and response schemas, see the [Service accounts API reference](https://platform.claude.com/docs/en/api/beta/organization/service_accounts).
487For complete parameter details and response schemas, see the [Service accounts API reference](https://platform.claude.com/docs/en/api/organization/service_accounts).
489488 
490489## Federation issuers
491490 
from line 512
513512 ```
514513 
515514 ```bash CLI
516 ant beta:organization:federation:issuers create \
515 ant organization:federation:issuers create \
517516 --name github-actions \
518517 --issuer-url https://token.actions.githubusercontent.com \
519518 --jwks '{type: discovery}'
from line 521
522521 ```python Python
523522 client = anthropic.Anthropic()
524523 
525 issuer = client.beta.organization.federation.issuers.create(
524 issuer = client.organization.federation.issuers.create(
526525 name="github-actions",
527526 issuer_url="https://token.actions.githubusercontent.com",
528527 jwks={"type": "discovery"},
from line 535
536535 ```typescript TypeScript
537536 const client = new Anthropic();
538537 
539 const issuer = await client.beta.organization.federation.issuers.create({
538 const issuer = await client.organization.federation.issuers.create({
540539 name: "github-actions",
541540 issuer_url: "https://token.actions.githubusercontent.com",
542541 jwks: { type: "discovery" }
from line 547
548547 ```
549548 
550549 ```csharp C#
551 using Anthropic.Models.Beta.Organization.Federation.Issuers;
550 using Anthropic.Models.Organization.Federation.Issuers;
552551 
553552 AnthropicClient client = new();
554553 
555 var issuer = await client.Beta.Organization.Federation.Issuers.Create(new()
554 var issuer = await client.Organization.Federation.Issuers.Create(new()
556555 {
557556 Name = "github-actions",
558557 IssuerUrl = "https://token.actions.githubusercontent.com",
559 Jwks = new BetaJwksDiscovery()
558 Jwks = new JwksDiscovery()
560559 });
561560 
562561 Console.WriteLine($"id: {issuer.ID}");
from line 566
567566 ```go Go
568567 client := anthropic.NewClient()
569568 
570 issuer, err := client.Beta.Organization.Federation.Issuers.New(context.Background(), anthropic.BetaOrganizationFederationIssuerNewParams{
569 issuer, err := client.Organization.Federation.Issuers.New(context.Background(), anthropic.OrganizationFederationIssuerNewParams{
571570 Name: "github-actions",
572571 IssuerURL: "https://token.actions.githubusercontent.com",
573 JWKS: anthropic.BetaOrganizationFederationIssuerNewParamsJWKSUnion{
574 OfDiscovery: &anthropic.BetaJWKSDiscoveryParam{},
572 JWKS: anthropic.OrganizationFederationIssuerNewParamsJWKSUnion{
573 OfDiscovery: &anthropic.JWKSDiscoveryParam{},
575574 },
576575 })
577576 if err != nil {
from line 583
584583 ```
585584 
586585 ```java Java
587 import com.anthropic.models.beta.organization.federation.issuers.BetaJwksDiscovery;
588 import com.anthropic.models.beta.organization.federation.issuers.IssuerCreateParams;
586 import com.anthropic.models.organization.federation.issuers.JwksDiscovery;
587 import com.anthropic.models.organization.federation.issuers.IssuerCreateParams;
589588 
590589 void main() {
591590 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
from line 592
593592 var params = IssuerCreateParams.builder()
594593 .name("github-actions")
595594 .issuerUrl("https://token.actions.githubusercontent.com")
596 .jwks(BetaJwksDiscovery.builder().build())
595 .jwks(JwksDiscovery.builder().build())
597596 .build();
598 var issuer = client.beta().organization().federation().issuers().create(params);
597 var issuer = client.organization().federation().issuers().create(params);
599598 
600599 IO.println("id: " + issuer.id());
601600 IO.println("name: " + issuer.name());
from line 605
606605 ```php PHP
607606 $client = new Client();
608607 
609 $issuer = $client->beta->organization->federation->issuers->create(
608 $issuer = $client->organization->federation->issuers->create(
610609 name: 'github-actions',
611610 issuerURL: 'https://token.actions.githubusercontent.com',
612611 jwks: ['type' => 'discovery'],
from line 619
620619 ```ruby Ruby
621620 client = Anthropic::Client.new
622621 
623 issuer = client.beta.organization.federation.issuers.create(
622 issuer = client.organization.federation.issuers.create(
624623 name: "github-actions",
625624 issuer_url: "https://token.actions.githubusercontent.com",
626625 jwks: {type: :discovery}
from line 641
642641 ```
643642 
644643 ```bash CLI
645 ant beta:organization:federation:issuers list --limit 20
644 ant organization:federation:issuers list --limit 20
646645 ```
647646 
648647 ```python Python
649648 client = anthropic.Anthropic()
650649 
651 issuers = client.beta.organization.federation.issuers.list(limit=20)
650 issuers = client.organization.federation.issuers.list(limit=20)
652651 
653652 for issuer in issuers:
654653 print(f"{issuer.id}: {issuer.name}")
from line 656
657656 ```typescript TypeScript
658657 const client = new Anthropic();
659658 
660 for await (const issuer of client.beta.organization.federation.issuers.list({ limit: 20 })) {
659 for await (const issuer of client.organization.federation.issuers.list({ limit: 20 })) {
661660 console.log(`${issuer.id}: ${issuer.name}`);
662661 }
663662 ```
from line 664
665664 ```csharp C#
666665 AnthropicClient client = new();
667666 
668 var page = await client.Beta.Organization.Federation.Issuers.List(new() { Limit = 20 });
667 var page = await client.Organization.Federation.Issuers.List(new() { Limit = 20 });
669668 
670669 await foreach (var issuer in page.Paginate())
671670 {
from line 675
676675 ```go Go
677676 client := anthropic.NewClient()
678677 
679 issuers := client.Beta.Organization.Federation.Issuers.ListAutoPaging(context.Background(), anthropic.BetaOrganizationFederationIssuerListParams{
678 issuers := client.Organization.Federation.Issuers.ListAutoPaging(context.Background(), anthropic.OrganizationFederationIssuerListParams{
680679 Limit: anthropic.Int(20),
681680 })
682681 
from line 689
690689 ```
691690 
692691 ```java Java
693 import com.anthropic.models.beta.organization.federation.issuers.IssuerListParams;
692 import com.anthropic.models.organization.federation.issuers.IssuerListParams;
694693 
695694 void main() {
696695 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
from line 697
698697 var params = IssuerListParams.builder()
699698 .limit(20)
700699 .build();
701 var issuers = client.beta().organization().federation().issuers().list(params);
700 var issuers = client.organization().federation().issuers().list(params);
702701 
703702 for (var issuer : issuers.autoPager()) {
704703 IO.println(issuer.id() + ": " + issuer.name());
from line 708
709708 ```php PHP
710709 $client = new Client();
711710 
712 $issuers = $client->beta->organization->federation->issuers->list(limit: 20);
711 $issuers = $client->organization->federation->issuers->list(limit: 20);
713712 
714713 foreach ($issuers->getItems() as $issuer) {
715714 echo "{$issuer->id}: {$issuer->name}\n";
from line 718
719718 ```ruby Ruby
720719 client = Anthropic::Client.new
721720 
722 issuers = client.beta.organization.federation.issuers.list(limit: 20)
721 issuers = client.organization.federation.issuers.list(limit: 20)
723722 
724723 issuers.data.each do |issuer|
725724 puts "#{issuer.id}: #{issuer.name}"
from line 736
737736 ```
738737 
739738 ```bash CLI
740 ant beta:organization:federation:issuers archive \
739 ant organization:federation:issuers archive \
741740 --federation-issuer-id fdis_01ABCDEFabcdef0123456789XY
742741 ```
743742 
from line 743
744743 ```python Python
745744 client = anthropic.Anthropic()
746745 
747 issuer = client.beta.organization.federation.issuers.archive(
746 issuer = client.organization.federation.issuers.archive(
748747 "fdis_01ABCDEFabcdef0123456789XY"
749748 )
750749 
from line 754
755754 ```typescript TypeScript
756755 const client = new Anthropic();
757756 
758 const issuer = await client.beta.organization.federation.issuers.archive(
757 const issuer = await client.organization.federation.issuers.archive(
759758 "fdis_01ABCDEFabcdef0123456789XY"
760759 );
761760 
from line 765
766765 ```csharp C#
767766 AnthropicClient client = new();
768767 
769 var issuer = await client.Beta.Organization.Federation.Issuers.Archive(
768 var issuer = await client.Organization.Federation.Issuers.Archive(
770769 "fdis_01ABCDEFabcdef0123456789XY"
771770 );
772771 
from line 776
777776 ```go Go
778777 client := anthropic.NewClient()
779778 
780 issuer, err := client.Beta.Organization.Federation.Issuers.Archive(
779 issuer, err := client.Organization.Federation.Issuers.Archive(
781780 context.Background(),
782781 "fdis_01ABCDEFabcdef0123456789XY",
783 anthropic.BetaOrganizationFederationIssuerArchiveParams{},
784782 )
785783 if err != nil {
786784 log.Fatal(err)
from line 791
793791 ```java Java
794792 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
795793 
796 var issuer = client.beta().organization().federation().issuers()
794 var issuer = client.organization().federation().issuers()
797795 .archive("fdis_01ABCDEFabcdef0123456789XY");
798796 
799797 IO.println("id: " + issuer.id());
from line 801
803801 ```php PHP
804802 $client = new Client();
805803 
806 $issuer = $client->beta->organization->federation->issuers->archive(
804 $issuer = $client->organization->federation->issuers->archive(
807805 federationIssuerID: 'fdis_01ABCDEFabcdef0123456789XY',
808806 );
809807 
from line 813
815813 client = Anthropic::Client.new
816814 
817815 issuer_id = "fdis_01ABCDEFabcdef0123456789XY"
818 issuer = client.beta.organization.federation.issuers.archive(issuer_id)
816 issuer = client.organization.federation.issuers.archive(issuer_id)
819817 
820818 puts "id: #{issuer.id}"
821819 puts "archived_at: #{issuer.archived_at}"
from line 822
824822 
825823To read or update a single issuer, use `GET` and `POST` on `/v1/organizations/federation_issuers/{issuer_id}`. An OAuth caller cannot update an issuer that backs a rule whose `oauth_scope` is anything other than `workspace:developer` or `workspace:inference`; see [Permissions and constraints](https://platform.claude.com/docs/en/manage-claude/wif-admin-api#permissions-and-constraints).
826824 
827For complete parameter details and response schemas, see the [Federation issuers API reference](https://platform.claude.com/docs/en/api/beta/organization/federation/issuers).
825For complete parameter details and response schemas, see the [Federation issuers API reference](https://platform.claude.com/docs/en/api/organization/federation/issuers).
828826 
829827## Federation rules
830828 
from line 854
856854 ```
857855 
858856 ```bash CLI
859 ant beta:organization:federation:rules create <<'YAML'
857 ant organization:federation:rules create <<'YAML'
860858 name: gha-deploy
861859 issuer_id: fdis_01ABCDEFabcdef0123456789XY
862860 match:
from line 873
875873 ```python Python
876874 client = anthropic.Anthropic()
877875 
878 rule = client.beta.organization.federation.rules.create(
876 rule = client.organization.federation.rules.create(
879877 name="gha-deploy",
880878 issuer_id="fdis_01ABCDEFabcdef0123456789XY",
881879 match={
from line 896
898896 ```typescript TypeScript
899897 const client = new Anthropic();
900898 
901 const rule = await client.beta.organization.federation.rules.create({
899 const rule = await client.organization.federation.rules.create({
902900 name: "gha-deploy",
903901 issuer_id: "fdis_01ABCDEFabcdef0123456789XY",
904902 match: {
from line 919
921919 ```csharp C#
922920 AnthropicClient client = new();
923921 
924 var rule = await client.Beta.Organization.Federation.Rules.Create(new()
922 var rule = await client.Organization.Federation.Rules.Create(new()
925923 {
926924 Name = "gha-deploy",
927925 IssuerID = "fdis_01ABCDEFabcdef0123456789XY",
from line 941
943941 ```go Go
944942 client := anthropic.NewClient()
945943 
946 rule, err := client.Beta.Organization.Federation.Rules.New(context.Background(), anthropic.BetaOrganizationFederationRuleNewParams{
944 rule, err := client.Organization.Federation.Rules.New(context.Background(), anthropic.OrganizationFederationRuleNewParams{
947945 Name: "gha-deploy",
948946 IssuerID: "fdis_01ABCDEFabcdef0123456789XY",
949 Match: anthropic.BetaFederationRuleMatchParam{
947 Match: anthropic.FederationRuleMatchParam{
950948 SubjectPrefix: anthropic.String("repo:my-org/my-repo:ref:refs/heads/main"),
951949 Claims: map[string]string{"repository_owner": "my-org"},
952950 },
953 Target: anthropic.BetaServiceAccountTargetParam{
951 Target: anthropic.ServiceAccountTargetParam{
954952 ServiceAccountID: "svac_01ABCDEFabcdef0123456789XY",
955953 },
956954 WorkspaceID: anthropic.String("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ"),
from line 965
967965 
968966 ```java Java
969967 import com.anthropic.core.JsonValue;
970 import com.anthropic.models.beta.organization.federation.rules.BetaFederationRuleMatch;
971 import com.anthropic.models.beta.organization.federation.rules.BetaServiceAccountTarget;
972 import com.anthropic.models.beta.organization.federation.rules.RuleCreateParams;
968 import com.anthropic.models.organization.federation.rules.FederationRuleMatch;
969 import com.anthropic.models.organization.federation.rules.ServiceAccountTarget;
970 import com.anthropic.models.organization.federation.rules.RuleCreateParams;
973971 
974972 void main() {
975973 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
976974 
977 var match = BetaFederationRuleMatch.builder()
975 var match = FederationRuleMatch.builder()
978976 .subjectPrefix("repo:my-org/my-repo:ref:refs/heads/main")
979 .claims(BetaFederationRuleMatch.Claims.builder()
977 .claims(FederationRuleMatch.Claims.builder()
980978 .putAdditionalProperty("repository_owner", JsonValue.from("my-org"))
981979 .build())
982980 .build();
from line 982
984982 .name("gha-deploy")
985983 .issuerId("fdis_01ABCDEFabcdef0123456789XY")
986984 .match(match)
987 .target(BetaServiceAccountTarget.of("svac_01ABCDEFabcdef0123456789XY"))
985 .target(ServiceAccountTarget.of("svac_01ABCDEFabcdef0123456789XY"))
988986 .workspaceId("wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ")
989987 .oauthScope("workspace:developer")
990988 .tokenLifetimeSeconds(600)
991989 .build();
992 var rule = client.beta().organization().federation().rules().create(params);
990 var rule = client.organization().federation().rules().create(params);
993991 
994992 IO.println("id: " + rule.id());
995993 IO.println("name: " + rule.name());
from line 997
999997 ```php PHP
1000998 $client = new Client();
1001999 
1002 $rule = $client->beta->organization->federation->rules->create(
1000 $rule = $client->organization->federation->rules->create(
10031001 name: 'gha-deploy',
10041002 issuerID: 'fdis_01ABCDEFabcdef0123456789XY',
10051003 match: [
from line 1020
10221020 ```ruby Ruby
10231021 client = Anthropic::Client.new
10241022 
1025 rule = client.beta.organization.federation.rules.create(
1023 rule = client.organization.federation.rules.create(
10261024 name: "gha-deploy",
10271025 issuer_id: "fdis_01ABCDEFabcdef0123456789XY",
10281026 match: {
from line 1051
10531051 ```
10541052 
10551053 ```bash CLI
1056 ant beta:organization:federation:rules list \
1054 ant organization:federation:rules list \
10571055 --issuer-id fdis_01ABCDEFabcdef0123456789XY
10581056 ```
10591057 
from line 1058
10601058 ```python Python
10611059 client = anthropic.Anthropic()
10621060 
1063 rules = client.beta.organization.federation.rules.list(
1061 rules = client.organization.federation.rules.list(
10641062 issuer_id="fdis_01ABCDEFabcdef0123456789XY"
10651063 )
10661064 
from line 1069
10711069 ```typescript TypeScript
10721070 const client = new Anthropic();
10731071 
1074 for await (const rule of client.beta.organization.federation.rules.list({
1072 for await (const rule of client.organization.federation.rules.list({
10751073 issuer_id: "fdis_01ABCDEFabcdef0123456789XY"
10761074 })) {
10771075 console.log(`${rule.id}: ${rule.name}`);
from line 1079
10811079 ```csharp C#
10821080 AnthropicClient client = new();
10831081 
1084 var page = await client.Beta.Organization.Federation.Rules.List(new()
1082 var page = await client.Organization.Federation.Rules.List(new()
10851083 {
10861084 IssuerID = "fdis_01ABCDEFabcdef0123456789XY"
10871085 });
from line 1093
10951093 ```go Go
10961094 client := anthropic.NewClient()
10971095 
1098 rules := client.Beta.Organization.Federation.Rules.ListAutoPaging(context.Background(), anthropic.BetaOrganizationFederationRuleListParams{
1096 rules := client.Organization.Federation.Rules.ListAutoPaging(context.Background(), anthropic.OrganizationFederationRuleListParams{
10991097 IssuerID: anthropic.String("fdis_01ABCDEFabcdef0123456789XY"),
11001098 })
11011099 
from line 1107
11091107 ```
11101108 
11111109 ```java Java
1112 import com.anthropic.models.beta.organization.federation.rules.RuleListParams;
1110 import com.anthropic.models.organization.federation.rules.RuleListParams;
11131111 
11141112 void main() {
11151113 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
from line 1115
11171115 var params = RuleListParams.builder()
11181116 .issuerId("fdis_01ABCDEFabcdef0123456789XY")
11191117 .build();
1120 var rules = client.beta().organization().federation().rules().list(params);
1118 var rules = client.organization().federation().rules().list(params);
11211119 
11221120 for (var rule : rules.autoPager()) {
11231121 IO.println(rule.id() + ": " + rule.name());
from line 1126
11281126 ```php PHP
11291127 $client = new Client();
11301128 
1131 $rules = $client->beta->organization->federation->rules->list(
1129 $rules = $client->organization->federation->rules->list(
11321130 issuerID: 'fdis_01ABCDEFabcdef0123456789XY',
11331131 );
11341132 
from line 1138
11401138 ```ruby Ruby
11411139 client = Anthropic::Client.new
11421140 
1143 rules = client.beta.organization.federation.rules.list(
1141 rules = client.organization.federation.rules.list(
11441142 issuer_id: "fdis_01ABCDEFabcdef0123456789XY"
11451143 )
11461144 
from line 1158
11601158 ```
11611159 
11621160 ```bash CLI
1163 ant beta:organization:federation:rules archive \
1161 ant organization:federation:rules archive \
11641162 --federation-rule-id fdrl_01ABCDEFabcdef0123456789XY
11651163 ```
11661164 
from line 1165
11671165 ```python Python
11681166 client = anthropic.Anthropic()
11691167 
1170 rule = client.beta.organization.federation.rules.archive(
1171 "fdrl_01ABCDEFabcdef0123456789XY"
1172 )
1168 rule = client.organization.federation.rules.archive("fdrl_01ABCDEFabcdef0123456789XY")
11731169 
11741170 print(f"id: {rule.id}")
11751171 print(f"archived_at: {rule.archived_at}")
from line 1174
11781174 ```typescript TypeScript
11791175 const client = new Anthropic();
11801176 
1181 const rule = await client.beta.organization.federation.rules.archive(
1177 const rule = await client.organization.federation.rules.archive(
11821178 "fdrl_01ABCDEFabcdef0123456789XY"
11831179 );
11841180 
from line 1185
11891185 ```csharp C#
11901186 AnthropicClient client = new();
11911187 
1192 var rule = await client.Beta.Organization.Federation.Rules.Archive(
1188 var rule = await client.Organization.Federation.Rules.Archive(
11931189 "fdrl_01ABCDEFabcdef0123456789XY"
11941190 );
11951191 
from line 1196
12001196 ```go Go
12011197 client := anthropic.NewClient()
12021198 
1203 rule, err := client.Beta.Organization.Federation.Rules.Archive(
1199 rule, err := client.Organization.Federation.Rules.Archive(
12041200 context.Background(),
12051201 "fdrl_01ABCDEFabcdef0123456789XY",
1206 anthropic.BetaOrganizationFederationRuleArchiveParams{},
12071202 )
12081203 if err != nil {
12091204 log.Fatal(err)
from line 1211
12161211 ```java Java
12171212 AnthropicClient client = AnthropicOkHttpClient.fromEnv();
12181213 
1219 var rule = client.beta().organization().federation().rules()
1214 var rule = client.organization().federation().rules()
12201215 .archive("fdrl_01ABCDEFabcdef0123456789XY");
12211216 
12221217 IO.println("id: " + rule.id());
from line 1221
12261221 ```php PHP
12271222 $client = new Client();
12281223 
1229 $rule = $client->beta->organization->federation->rules->archive(
1224 $rule = $client->organization->federation->rules->archive(
12301225 federationRuleID: 'fdrl_01ABCDEFabcdef0123456789XY',
12311226 );
12321227 
from line 1233
12381233 client = Anthropic::Client.new
12391234 
12401235 rule_id = "fdrl_01ABCDEFabcdef0123456789XY"
1241 rule = client.beta.organization.federation.rules.archive(rule_id)
1236 rule = client.organization.federation.rules.archive(rule_id)
12421237 
12431238 puts "id: #{rule.id}"
12441239 puts "archived_at: #{rule.archived_at}"
from line 1251
12561251 
12571252To read or update a single rule, use `GET` and `POST` on `/v1/organizations/federation_rules/{rule_id}`. To manage the workspaces a rule can mint tokens in, use `GET` and `POST` on `/v1/organizations/federation_rules/{rule_id}/workspaces`, and `DELETE` on `/v1/organizations/federation_rules/{rule_id}/workspaces/{workspace_id}`.
12581253 
1259For complete parameter details and response schemas, see the [Federation rules API reference](https://platform.claude.com/docs/en/api/beta/organization/federation/rules).
1254For complete parameter details and response schemas, see the [Federation rules API reference](https://platform.claude.com/docs/en/api/organization/federation/rules).
12601255 
12611256## Permissions and constraints
12621257 
from line 1274
12791274* [Workload Identity Federation](https://platform.claude.com/docs/en/manage-claude/workload-identity-federation): concepts and the Console setup walkthrough
12801275* [WIF reference](https://platform.claude.com/docs/en/manage-claude/wif-reference): environment variables, validation rules, OAuth scopes, and error codes
12811276* [Admin API](https://platform.claude.com/docs/en/manage-claude/admin-api): the rest of the organization management surface
1282* [Admin API reference](https://platform.claude.com/docs/en/api/beta/organization): generated request and response schemas for every Admin API endpoint
1277* [Admin API reference](https://platform.claude.com/docs/en/api/organization): generated request and response schemas for the service account and federation endpoints
12831278 
Feedback