List Federation Issuers
api/admin/federation_issuers/list
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/admin/federation_issuers/list Changed · +40 / -27 lines
# List Federation Issuers ## Query parameters ## Headers ## Returns ## Example ### Response (200) ## List Federation Issuers ### Query Parameters ### Header Parameters ### Returns ### Example #### Response
---- -title: List Federation Issuers -url: https://platform.claude.com/docs/en/api/admin/federation_issuers/list ---- +# List Federation Issuers -## List Federation Issuers +**GET** `/v1/organizations/federation_issuers` -**get** `/v1/organizations/federation_issuers` - List federation issuers in your organization. Archived issuers are excluded unless `include_archived=true`. -### Query Parameters +## Query parameters - `include_archived: optional boolean` Include archived resources. Defaults to false. + default: false + - `limit: optional number` Number of results per page. + default: 20, maximum: 100, minimum: 1 + - `page: optional string` Opaque cursor from a previous response's `next_page`. -### Header Parameters +## Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Returns +## Returns - `data: array of FederationIssuer`
If set, all rules referencing this issuer reject token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
When this issuer was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
The `iss` claim value. Incoming JWTs must match exactly. - - `jwks: object { type, ca_cert_pem, discovery_base } or object { type, url, ca_cert_pem } or object { keys, type }` + - `jwks: object or object or object` How signing keys are obtained for signature verification. - - `Discovery object { type, ca_cert_pem, discovery_base }` + - `Discovery object` JWKS via the issuer's OIDC discovery document. - `type: "discovery"` - - `"discovery"` - - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. + maxLength: 8192 + - `discovery_base: optional string or null` Set when the discovery URL differs from `issuer_url`. - - `ExplicitURL object { type, url, ca_cert_pem }` + - `ExplicitURL object` JWKS fetched from a fixed endpoint. - `type: "explicit_url"` - - `"explicit_url"` - - `url: string` JWKS endpoint. + minLength: 1 + - `ca_cert_pem: optional string or null` Optional custom CA (PEM) for TLS verification of the JWKS fetch. - - `Inline object { keys, type }` + maxLength: 8192 + - `Inline object` + JWKS supplied directly; no network fetch. - `keys: array of map[unknown]`
Inline JWK objects. + minItems: 1 + - `type: "inline"` - - `"inline"` - - `jwks_polling_disabled_at: string or null` If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session. + format: date-time + - `max_jwt_lifetime_seconds: number` Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
Admin-chosen slug identifier. - - `poll_status: object { consecutive_failures, last_fetched_at, next_poll_at } or null` + - `poll_status: object or null` Status of automatic JWKS polling for a federation issuer.
When the last successful fetch completed. + format: date-time + - `next_poll_at: string or null` When the next fetch is scheduled. Null if paused. + format: date-time + - `type: "federation_issuer"` - - `"federation_issuer"` + default: federation_issuer - `updated_at: string` When this issuer was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this issuer.
Opaque cursor for the next page, or null if no more results. -### Example +## Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_issuers \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +### Response (200) ```json {