Federation Issuers
api/admin/federation_issuers
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/admin/federation_issuers Changed · +228 / -129 lines
### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ### Query parameters ### Headers #### Response (200) ### Path parameters ### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ## Domain types ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Query Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ## Domain Types
---- -title: Federation Issuers -url: https://platform.claude.com/docs/en/api/admin/federation_issuers ---- - # Federation Issuers ## Create Federation Issuer -**post** `/v1/organizations/federation_issuers` +**POST** `/v1/organizations/federation_issuers` Register an OIDC issuer that Anthropic will trust for workload identity federation in your organization.
Requires an OAuth bearer or Console session; Admin API keys are not accepted. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Body Parameters +### Body parameters - `issuer_url: string` The `iss` claim value to match against. + minLength: 1 + - `name: string` Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409. + maxLength: 255, minLength: 1 + - `check_jti: optional boolean or null` Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Defaults to true. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement. -- `jwks: optional object { type, ca_cert_pem, discovery_base } or object { type, url, ca_cert_pem } or object { keys, type }` +- `jwks: optional object or object or object` How signing keys are obtained. Defaults to OIDC discovery. - - `Discovery object { type, ca_cert_pem, discovery_base }` + - `Discovery object` JWKS via the issuer's OIDC discovery document. - `type: "discovery"` - - `"discovery"` - - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. + maxLength: 8192 + - `discovery_base: optional string or null` Set when the discovery URL differs from `issuer_url`. - - `ExplicitURL object { type, url, ca_cert_pem }` + - `ExplicitURL object` JWKS fetched from a fixed endpoint. - `type: "explicit_url"` - - `"explicit_url"` - - `url: string` JWKS endpoint. + minLength: 1 + - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. - - `Inline object { keys, type }` + maxLength: 8192 + - `Inline object` + JWKS supplied directly; no network fetch. - `keys: array of map[unknown]`
Inline JWK objects. + minItems: 1 + - `type: "inline"` - - `"inline"` - - `max_jwt_lifetime_seconds: optional number or null` Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Defaults to 3600 (1h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected. + maximum: 176400, exclusiveMinimum: 0 + ### Returns -- `FederationIssuer object { id, archived_at, archived_by_actor_id, 12 more }` +- `FederationIssuer object` Registered external OIDC identity provider.
If set, all rules referencing this issuer reject token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
When this issuer was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
The `iss` claim value. Incoming JWTs must match exactly. - - `jwks: object { type, ca_cert_pem, discovery_base } or object { type, url, ca_cert_pem } or object { keys, type }` + - `jwks: object or object or object` How signing keys are obtained for signature verification. - - `Discovery object { type, ca_cert_pem, discovery_base }` + - `Discovery object` JWKS via the issuer's OIDC discovery document. - `type: "discovery"` - - `"discovery"` - - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. + maxLength: 8192 + - `discovery_base: optional string or null` Set when the discovery URL differs from `issuer_url`. - - `ExplicitURL object { type, url, ca_cert_pem }` + - `ExplicitURL object` JWKS fetched from a fixed endpoint. - `type: "explicit_url"` - - `"explicit_url"` - - `url: string` JWKS endpoint. + minLength: 1 + - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. - - `Inline object { keys, type }` + maxLength: 8192 + - `Inline object` + JWKS supplied directly; no network fetch. - `keys: array of map[unknown]`
Inline JWK objects. + minItems: 1 + - `type: "inline"` - - `"inline"` - - `jwks_polling_disabled_at: string or null` If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session. + format: date-time + - `max_jwt_lifetime_seconds: number` Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
Admin-chosen slug identifier. - - `poll_status: object { consecutive_failures, last_fetched_at, next_poll_at } or null` + - `poll_status: object or null` Status of automatic JWKS polling for a federation issuer.
When the last successful fetch completed. + format: date-time + - `next_poll_at: string or null` When the next fetch is scheduled. Null if paused. + format: date-time + - `type: "federation_issuer"` - - `"federation_issuer"` + default: federation_issuer - `updated_at: string` When this issuer was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this issuer.
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_issuers \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +#### Response (200) ```json {
## Get Federation Issuer -**get** `/v1/organizations/federation_issuers/{federation_issuer_id}` +**GET** `/v1/organizations/federation_issuers/{federation_issuer_id}` Retrieve a federation issuer by its ID (`fdis_...`). -### Path Parameters +### Path parameters - `federation_issuer_id: string` ID of the federation issuer. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
### Returns -- `FederationIssuer object { id, archived_at, archived_by_actor_id, 12 more }` +- `FederationIssuer object` Registered external OIDC identity provider.
If set, all rules referencing this issuer reject token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
When this issuer was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
The `iss` claim value. Incoming JWTs must match exactly. - - `jwks: object { type, ca_cert_pem, discovery_base } or object { type, url, ca_cert_pem } or object { keys, type }` + - `jwks: object or object or object` How signing keys are obtained for signature verification. - - `Discovery object { type, ca_cert_pem, discovery_base }` + - `Discovery object` JWKS via the issuer's OIDC discovery document. - `type: "discovery"` - - `"discovery"` - - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. + maxLength: 8192 + - `discovery_base: optional string or null` Set when the discovery URL differs from `issuer_url`. - - `ExplicitURL object { type, url, ca_cert_pem }` + - `ExplicitURL object` JWKS fetched from a fixed endpoint. - `type: "explicit_url"` - - `"explicit_url"` - - `url: string` JWKS endpoint. + minLength: 1 + - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. - - `Inline object { keys, type }` + maxLength: 8192 + - `Inline object` + JWKS supplied directly; no network fetch. - `keys: array of map[unknown]`
Inline JWK objects. + minItems: 1 + - `type: "inline"` - - `"inline"` - - `jwks_polling_disabled_at: string or null` If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session. + format: date-time + - `max_jwt_lifetime_seconds: number` Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
Admin-chosen slug identifier. - - `poll_status: object { consecutive_failures, last_fetched_at, next_poll_at } or null` + - `poll_status: object or null` Status of automatic JWKS polling for a federation issuer.
When the last successful fetch completed. + format: date-time + - `next_poll_at: string or null` When the next fetch is scheduled. Null if paused. + format: date-time + - `type: "federation_issuer"` - - `"federation_issuer"` + default: federation_issuer - `updated_at: string` When this issuer was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this issuer.
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## List Federation Issuers -**get** `/v1/organizations/federation_issuers` +**GET** `/v1/organizations/federation_issuers` List federation issuers in your organization. Archived issuers are excluded unless `include_archived=true`. -### Query Parameters +### Query parameters - `include_archived: optional boolean` Include archived resources. Defaults to false. + default: false + - `limit: optional number` Number of results per page. + default: 20, maximum: 100, minimum: 1 + - `page: optional string` Opaque cursor from a previous response's `next_page`. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
If set, all rules referencing this issuer reject token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
When this issuer was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
The `iss` claim value. Incoming JWTs must match exactly. - - `jwks: object { type, ca_cert_pem, discovery_base } or object { type, url, ca_cert_pem } or object { keys, type }` + - `jwks: object or object or object` How signing keys are obtained for signature verification. - - `Discovery object { type, ca_cert_pem, discovery_base }` + - `Discovery object` JWKS via the issuer's OIDC discovery document. - `type: "discovery"` - - `"discovery"` - - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. + maxLength: 8192 + - `discovery_base: optional string or null` Set when the discovery URL differs from `issuer_url`. - - `ExplicitURL object { type, url, ca_cert_pem }` + - `ExplicitURL object` JWKS fetched from a fixed endpoint. - `type: "explicit_url"` - - `"explicit_url"` - - `url: string` JWKS endpoint. + minLength: 1 + - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. - - `Inline object { keys, type }` + maxLength: 8192 + - `Inline object` + JWKS supplied directly; no network fetch. - `keys: array of map[unknown]`
Inline JWK objects. + minItems: 1 + - `type: "inline"` - - `"inline"` - - `jwks_polling_disabled_at: string or null` If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session. + format: date-time + - `max_jwt_lifetime_seconds: number` Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
Admin-chosen slug identifier. - - `poll_status: object { consecutive_failures, last_fetched_at, next_poll_at } or null` + - `poll_status: object or null` Status of automatic JWKS polling for a federation issuer.
When the last successful fetch completed. + format: date-time + - `next_poll_at: string or null` When the next fetch is scheduled. Null if paused. + format: date-time + - `type: "federation_issuer"` - - `"federation_issuer"` + default: federation_issuer - `updated_at: string` When this issuer was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this issuer.
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_issuers \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Update Federation Issuer -**post** `/v1/organizations/federation_issuers/{federation_issuer_id}` +**POST** `/v1/organizations/federation_issuers/{federation_issuer_id}` Partially update a federation issuer.
session. Requires an OAuth bearer or Console session; Admin API keys are not accepted. -### Path Parameters +### Path parameters - `federation_issuer_id: string` ID of the federation issuer to update. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Body Parameters +### Body parameters - `check_jti: optional boolean or null`
Replaces the `iss` claim value to match against. For discovery-mode issuers without a `discovery_base`, this is also the URL Anthropic fetches the OIDC discovery document and signing keys from, so changing it repoints the JWKS source. Changing the issuer URL to a well-known shared platform is rejected while any live rule under this issuer would not constrain tenant identity. -- `jwks: optional object { type, ca_cert_pem, discovery_base } or object { type, url, ca_cert_pem } or object { keys, type } or null` + minLength: 1 +- `jwks: optional object or object or object or null` + Replaces the entire JWKS configuration. - - `Discovery object { type, ca_cert_pem, discovery_base }` + - `Discovery object` JWKS via the issuer's OIDC discovery document. - `type: "discovery"` - - `"discovery"` - - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. + maxLength: 8192 + - `discovery_base: optional string or null` Set when the discovery URL differs from `issuer_url`. - - `ExplicitURL object { type, url, ca_cert_pem }` + - `ExplicitURL object` JWKS fetched from a fixed endpoint. - `type: "explicit_url"` - - `"explicit_url"` - - `url: string` JWKS endpoint. + minLength: 1 + - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. - - `Inline object { keys, type }` + maxLength: 8192 + - `Inline object` + JWKS supplied directly; no network fetch. - `keys: array of map[unknown]`
Inline JWK objects. + minItems: 1 + - `type: "inline"` - - `"inline"` - - `jwks_polling_disabled: optional boolean or null` Only `false` is accepted, to re-enable polling after the system pauses it. Polling is paused automatically; sending `true` is rejected.
Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected. + maximum: 176400, exclusiveMinimum: 0 + - `name: optional string or null` Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409. + maxLength: 255, minLength: 1 + ### Returns -- `FederationIssuer object { id, archived_at, archived_by_actor_id, 12 more }` +- `FederationIssuer object` Registered external OIDC identity provider.
If set, all rules referencing this issuer reject token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
When this issuer was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
The `iss` claim value. Incoming JWTs must match exactly. - - `jwks: object { type, ca_cert_pem, discovery_base } or object { type, url, ca_cert_pem } or object { keys, type }` + - `jwks: object or object or object` How signing keys are obtained for signature verification. - - `Discovery object { type, ca_cert_pem, discovery_base }` + - `Discovery object` JWKS via the issuer's OIDC discovery document. - `type: "discovery"` - - `"discovery"` - - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. + maxLength: 8192 + - `discovery_base: optional string or null` Set when the discovery URL differs from `issuer_url`. - - `ExplicitURL object { type, url, ca_cert_pem }` + - `ExplicitURL object` JWKS fetched from a fixed endpoint. - `type: "explicit_url"` - - `"explicit_url"` - - `url: string` JWKS endpoint. + minLength: 1 + - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. - - `Inline object { keys, type }` + maxLength: 8192 + - `Inline object` + JWKS supplied directly; no network fetch. - `keys: array of map[unknown]`
Inline JWK objects. + minItems: 1 + - `type: "inline"` - - `"inline"` - - `jwks_polling_disabled_at: string or null` If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session. + format: date-time + - `max_jwt_lifetime_seconds: number` Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
Admin-chosen slug identifier. - - `poll_status: object { consecutive_failures, last_fetched_at, next_poll_at } or null` + - `poll_status: object or null` Status of automatic JWKS polling for a federation issuer.
When the last successful fetch completed. + format: date-time + - `next_poll_at: string or null` When the next fetch is scheduled. Null if paused. + format: date-time + - `type: "federation_issuer"` - - `"federation_issuer"` + default: federation_issuer - `updated_at: string` When this issuer was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this issuer.
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
-d '{}' ``` -#### Response +#### Response (200) ```json {
## Archive Federation Issuer -**post** `/v1/organizations/federation_issuers/{federation_issuer_id}/archive` +**POST** `/v1/organizations/federation_issuers/{federation_issuer_id}/archive` Archive a federation issuer.
Requires an OAuth bearer or Console session; Admin API keys are not accepted. -### Path Parameters +### Path parameters - `federation_issuer_id: string` ID of the federation issuer to archive. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
### Returns -- `FederationIssuer object { id, archived_at, archived_by_actor_id, 12 more }` +- `FederationIssuer object` Registered external OIDC identity provider.
If set, all rules referencing this issuer reject token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
When this issuer was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
The `iss` claim value. Incoming JWTs must match exactly. - - `jwks: object { type, ca_cert_pem, discovery_base } or object { type, url, ca_cert_pem } or object { keys, type }` + - `jwks: object or object or object` How signing keys are obtained for signature verification. - - `Discovery object { type, ca_cert_pem, discovery_base }` + - `Discovery object` JWKS via the issuer's OIDC discovery document. - `type: "discovery"` - - `"discovery"` - - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. + maxLength: 8192 + - `discovery_base: optional string or null` Set when the discovery URL differs from `issuer_url`. - - `ExplicitURL object { type, url, ca_cert_pem }` + - `ExplicitURL object` JWKS fetched from a fixed endpoint. - `type: "explicit_url"` - - `"explicit_url"` - - `url: string` JWKS endpoint. + minLength: 1 + - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. - - `Inline object { keys, type }` + maxLength: 8192 + - `Inline object` + JWKS supplied directly; no network fetch. - `keys: array of map[unknown]`
Inline JWK objects. + minItems: 1 + - `type: "inline"` - - `"inline"` - - `jwks_polling_disabled_at: string or null` If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session. + format: date-time + - `max_jwt_lifetime_seconds: number` Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
Admin-chosen slug identifier. - - `poll_status: object { consecutive_failures, last_fetched_at, next_poll_at } or null` + - `poll_status: object or null` Status of automatic JWKS polling for a federation issuer.
When the last successful fetch completed. + format: date-time + - `next_poll_at: string or null` When the next fetch is scheduled. Null if paused. + format: date-time + - `type: "federation_issuer"` - - `"federation_issuer"` + default: federation_issuer - `updated_at: string` When this issuer was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this issuer.
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### Federation Issuer -- `FederationIssuer object { id, archived_at, archived_by_actor_id, 12 more }` +- `FederationIssuer object` Registered external OIDC identity provider.
If set, all rules referencing this issuer reject token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
When this issuer was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
The `iss` claim value. Incoming JWTs must match exactly. - - `jwks: object { type, ca_cert_pem, discovery_base } or object { type, url, ca_cert_pem } or object { keys, type }` + - `jwks: object or object or object` How signing keys are obtained for signature verification. - - `Discovery object { type, ca_cert_pem, discovery_base }` + - `Discovery object` JWKS via the issuer's OIDC discovery document. - `type: "discovery"` - - `"discovery"` - - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. + maxLength: 8192 + - `discovery_base: optional string or null` Set when the discovery URL differs from `issuer_url`. - - `ExplicitURL object { type, url, ca_cert_pem }` + - `ExplicitURL object` JWKS fetched from a fixed endpoint. - `type: "explicit_url"` - - `"explicit_url"` - - `url: string` JWKS endpoint. + minLength: 1 + - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. - - `Inline object { keys, type }` + maxLength: 8192 + - `Inline object` + JWKS supplied directly; no network fetch. - `keys: array of map[unknown]`
Inline JWK objects. + minItems: 1 + - `type: "inline"` - - `"inline"` - - `jwks_polling_disabled_at: string or null` If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session. + format: date-time + - `max_jwt_lifetime_seconds: number` Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
Admin-chosen slug identifier. - - `poll_status: object { consecutive_failures, last_fetched_at, next_poll_at } or null` + - `poll_status: object or null` Status of automatic JWKS polling for a federation issuer.
When the last successful fetch completed. + format: date-time + - `next_poll_at: string or null` When the next fetch is scheduled. Null if paused. + format: date-time + - `type: "federation_issuer"` - - `"federation_issuer"` + default: federation_issuer - `updated_at: string` When this issuer was last updated. + + format: date-time - `updated_by_actor_id: string or null`