Federation Rules
api/admin/federation_rules
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/admin/federation_rules Changed · +203 / -188 lines
### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ### Query parameters ### Headers #### Response (200) ### Path parameters ### Headers ### Body parameters #### Response (200) ### Path parameters ### Headers #### Response (200) ## Domain types ## Federation Rules › Workspaces ### List Federation Rule Workspaces #### Path parameters #### Query parameters #### Headers #### Returns #### Example ##### Response (200) ### Add Federation Rule Workspace #### Path parameters #### Headers #### Body parameters #### Returns #### Example ##### Response (200) ### Remove Federation Rule Workspace #### Path parameters #### Headers #### Returns #### Example ##### Response (200) ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ### Query Parameters ### Header Parameters #### Response ### Path Parameters ### Header Parameters ### Body Parameters #### Response ### Path Parameters ### Header Parameters #### Response ## Domain Types # Workspaces ## List Federation Rule Workspaces ### Path Parameters ### Query Parameters ### Header Parameters #### Response ## Add Federation Rule Workspace ### Path Parameters ### Header Parameters ### Body Parameters #### Response ## Remove Federation Rule Workspace ### Path Parameters ### Header Parameters #### Response ## Domain Types ### Workspace List Response ### Workspace Create Response ### Workspace Delete Response
---- -title: Federation Rules -url: https://platform.claude.com/docs/en/api/admin/federation_rules ---- - # Federation Rules ## Create Federation Rule -**post** `/v1/organizations/federation_rules` +**POST** `/v1/organizations/federation_rules` Create a federation rule owned by your organization.
`workspace:inference`; other scopes require a Console session. Admin API keys are not accepted. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Body Parameters +### Body parameters - `issuer_id: string` Tagged ID of the federation issuer. -- `match: object { audience, claims, condition, subject_prefix }` +- `match: object` Conditions the verified JWT must satisfy for this rule to apply. At least one of `subject_prefix` (other than a wildcard-only value like `*`), `claims`, or `condition` is required; `audience` alone is not sufficient.
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default. + maxLength: 1024 + - `claims: optional map[string] or null` Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400. + maxLength: 4096 + - `subject_prefix: optional string or null` Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`. + maxLength: 1024 + - `name: string` Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409. + maxLength: 255, minLength: 1 + - `oauth_scope: string` Space-separated OAuth scopes. OAuth callers may only set `workspace:developer` or `workspace:inference`; other scopes (such as `org:admin`) require a Console session. -- `target: object { service_account_id, type, service_account_name }` + minLength: 1 +- `target: object` + Identity that tokens minted via this rule act as. Currently always a `service_account` target. - `service_account_id: string`
- `type: "service_account"` - - `"service_account"` - - `service_account_name: optional string or null` Service account's display name at read time. Ignored on writes.
Optional free-text description. + maxLength: 2000 + - `token_lifetime_seconds: optional number` Lifetime in seconds for access tokens minted via this rule (60-86400). Defaults to 3600 (1h). Minted tokens are capped at `max(60, min(this value, 2 × remaining assertion validity))` seconds. + maximum: 86400, minimum: 60 + - `workspace_id: optional string or null` Tagged ID of the workspace to enable this rule for. Required unless `applies_to_all_workspaces` is true. Additional workspaces can be added via the `/federation_rules/{federation_rule_id}/workspaces` sub-resource.
### Returns -- `FederationRule object { id, applies_to_all_workspaces, archived_at, 17 more }` +- `FederationRule object` Authorization rule binding an external OIDC identity to Anthropic.
If set, this rule is archived and rejects token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
When this rule was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this rule.
Issuer's display name at read time. - - `match: object { audience, claims, condition, subject_prefix }` + - `match: object` Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default. + maxLength: 1024 + - `claims: optional map[string] or null` Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400. + maxLength: 4096 + - `subject_prefix: optional string or null` Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`. + maxLength: 1024 + - `name: string` Admin-chosen slug identifier.
Space-separated OAuth scopes granted on the minted token. - - `target: object { service_account_id, type, service_account_name }` + - `target: object` Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `type: "service_account"` - - `"service_account"` - - `service_account_name: optional string or null` Service account's display name at read time. Ignored on writes.
- `type: "federation_rule"` - - `"federation_rule"` + default: federation_rule - `updated_at: string` When this rule was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this rule.
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_rules \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +#### Response (200) ```json {
## Get Federation Rule -**get** `/v1/organizations/federation_rules/{federation_rule_id}` +**GET** `/v1/organizations/federation_rules/{federation_rule_id}` Retrieve a federation rule by its ID (`fdrl_...`). -### Path Parameters +### Path parameters - `federation_rule_id: string` ID of the federation rule. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
### Returns -- `FederationRule object { id, applies_to_all_workspaces, archived_at, 17 more }` +- `FederationRule object` Authorization rule binding an external OIDC identity to Anthropic.
If set, this rule is archived and rejects token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
When this rule was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this rule.
Issuer's display name at read time. - - `match: object { audience, claims, condition, subject_prefix }` + - `match: object` Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default. + maxLength: 1024 + - `claims: optional map[string] or null` Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400. + maxLength: 4096 + - `subject_prefix: optional string or null` Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`. + maxLength: 1024 + - `name: string` Admin-chosen slug identifier.
Space-separated OAuth scopes granted on the minted token. - - `target: object { service_account_id, type, service_account_name }` + - `target: object` Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `type: "service_account"` - - `"service_account"` - - `service_account_name: optional string or null` Service account's display name at read time. Ignored on writes.
- `type: "federation_rule"` - - `"federation_rule"` + default: federation_rule - `updated_at: string` When this rule was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this rule.
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## List Federation Rules -**get** `/v1/organizations/federation_rules` +**GET** `/v1/organizations/federation_rules` List federation rules in your organization.
Optionally filter by issuer with `issuer_id`. Archived rules are excluded unless `include_archived=true`. -### Query Parameters +### Query parameters - `include_archived: optional boolean` Include archived resources. Defaults to false. + default: false + - `issuer_id: optional string` Filter to rules referencing this federation issuer.
Number of results per page. + default: 20, maximum: 100, minimum: 1 + - `page: optional string` Opaque cursor from a previous response's `next_page`. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
If set, this rule is archived and rejects token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
When this rule was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this rule.
Issuer's display name at read time. - - `match: object { audience, claims, condition, subject_prefix }` + - `match: object` Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default. + maxLength: 1024 + - `claims: optional map[string] or null` Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400. + maxLength: 4096 + - `subject_prefix: optional string or null` Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`. + maxLength: 1024 + - `name: string` Admin-chosen slug identifier.
Space-separated OAuth scopes granted on the minted token. - - `target: object { service_account_id, type, service_account_name }` + - `target: object` Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `type: "service_account"` - - `"service_account"` - - `service_account_name: optional string or null` Service account's display name at read time. Ignored on writes.
- `type: "federation_rule"` - - `"federation_rule"` + default: federation_rule - `updated_at: string` When this rule was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this rule.
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_rules \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
## Update Federation Rule -**post** `/v1/organizations/federation_rules/{federation_rule_id}` +**POST** `/v1/organizations/federation_rules/{federation_rule_id}` Partially update a federation rule.
`workspace:developer` or `workspace:inference`; other scopes require a Console session. Admin API keys are not accepted. -### Path Parameters +### Path parameters - `federation_rule_id: string` ID of the federation rule to update. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Body Parameters +### Body parameters - `applies_to_all_workspaces: optional boolean or null`
Replaces the description. Omit to leave unchanged; send `null` to clear (the field is stored as an empty string). -- `match: optional object { audience, claims, condition, subject_prefix } or null` + maxLength: 2000 +- `match: optional object or null` + Does the incoming JWT qualify? All populated fields must pass; omitted fields are skipped. At least one
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default. + maxLength: 1024 + - `claims: optional map[string] or null` Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400. + maxLength: 4096 + - `subject_prefix: optional string or null` Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`. + maxLength: 1024 + - `name: optional string or null` Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409. + maxLength: 255, minLength: 1 + - `oauth_scope: optional string or null` Replaces the space-separated OAuth scopes granted on minted tokens. OAuth callers may only set `workspace:developer` or `workspace:inference`; other scopes (such as `org:admin`) require a Console session. -- `target: optional object { service_account_id, type, service_account_name } or null` + minLength: 1 +- `target: optional object or null` + Bind to a fixed service account by ID. - `service_account_id: string`
- `type: "service_account"` - - `"service_account"` - - `service_account_name: optional string or null` Service account's display name at read time. Ignored on writes.
Replaces the lifetime in seconds for access tokens minted via this rule (60-86400). Minted tokens are capped at `max(60, min(this value, 2 × remaining assertion validity))` seconds. + maximum: 86400, minimum: 60 + - `workspace_id: optional string or null` Replaces the existing single workspace enablement (the previous one is removed). Rejected with 400 if the rule is enabled for more than one workspace; use the `/federation_rules/{federation_rule_id}/workspaces` sub-resource instead.
### Returns -- `FederationRule object { id, applies_to_all_workspaces, archived_at, 17 more }` +- `FederationRule object` Authorization rule binding an external OIDC identity to Anthropic.
If set, this rule is archived and rejects token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
When this rule was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this rule.
Issuer's display name at read time. - - `match: object { audience, claims, condition, subject_prefix }` + - `match: object` Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default. + maxLength: 1024 + - `claims: optional map[string] or null` Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400. + maxLength: 4096 + - `subject_prefix: optional string or null` Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`. + maxLength: 1024 + - `name: string` Admin-chosen slug identifier.
Space-separated OAuth scopes granted on the minted token. - - `target: object { service_account_id, type, service_account_name }` + - `target: object` Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `type: "service_account"` - - `"service_account"` - - `service_account_name: optional string or null` Service account's display name at read time. Ignored on writes.
- `type: "federation_rule"` - - `"federation_rule"` + default: federation_rule - `updated_at: string` When this rule was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this rule.
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
-d '{}' ``` -#### Response +#### Response (200) ```json {
## Archive Federation Rule -**post** `/v1/organizations/federation_rules/{federation_rule_id}/archive` +**POST** `/v1/organizations/federation_rules/{federation_rule_id}/archive` Archive a federation rule.
whose `oauth_scope` is `workspace:developer` or `workspace:inference`; other scopes require a Console session. Admin API keys are not accepted. -### Path Parameters +### Path parameters - `federation_rule_id: string` ID of the federation rule to archive. -### Header Parameters +### Headers - `"anthropic-beta": optional array of string`
### Returns -- `FederationRule object { id, applies_to_all_workspaces, archived_at, 17 more }` +- `FederationRule object` Authorization rule binding an external OIDC identity to Anthropic.
If set, this rule is archived and rejects token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
When this rule was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this rule.
Issuer's display name at read time. - - `match: object { audience, claims, condition, subject_prefix }` + - `match: object` Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default. + maxLength: 1024 + - `claims: optional map[string] or null` Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400. + maxLength: 4096 + - `subject_prefix: optional string or null` Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`. + maxLength: 1024 + - `name: string` Admin-chosen slug identifier.
Space-separated OAuth scopes granted on the minted token. - - `target: object { service_account_id, type, service_account_name }` + - `target: object` Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `type: "service_account"` - - `"service_account"` - - `service_account_name: optional string or null` Service account's display name at read time. Ignored on writes.
- `type: "federation_rule"` - - `"federation_rule"` + default: federation_rule - `updated_at: string` When this rule was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this rule.
### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +#### Response (200) ```json {
} ``` -## Domain Types +## Domain types ### Federation Rule -- `FederationRule object { id, applies_to_all_workspaces, archived_at, 17 more }` +- `FederationRule object` Authorization rule binding an external OIDC identity to Anthropic.
If set, this rule is archived and rejects token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
When this rule was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this rule.
Issuer's display name at read time. - - `match: object { audience, claims, condition, subject_prefix }` + - `match: object` Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default. + maxLength: 1024 + - `claims: optional map[string] or null` Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400. + maxLength: 4096 + - `subject_prefix: optional string or null` Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`. + maxLength: 1024 + - `name: string` Admin-chosen slug identifier.
Space-separated OAuth scopes granted on the minted token. - - `target: object { service_account_id, type, service_account_name }` + - `target: object` Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `type: "service_account"` - - `"service_account"` - - `service_account_name: optional string or null` Service account's display name at read time. Ignored on writes.
- `type: "federation_rule"` - - `"federation_rule"` + default: federation_rule - `updated_at: string` When this rule was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this rule.
Tagged IDs of the workspaces this rule is enabled for. May be empty for older rules that only carry the legacy `workspace_id` binding. Ignored at exchange time when `applies_to_all_workspaces` is true (the list may still be non-empty). -# Workspaces +## Federation Rules › Workspaces -## List Federation Rule Workspaces +### List Federation Rule Workspaces -**get** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces` +**GET** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces` List workspaces where this federation rule is enabled.
rules with `applies_to_all_workspaces` or a legacy single `workspace_id`, check those fields on the rule itself. -### Path Parameters +#### Path parameters - `federation_rule_id: string` ID of the federation rule. -### Query Parameters +#### Query parameters - `limit: optional number` Number of results per page. + default: 20, maximum: 100, minimum: 1 + - `page: optional string` Opaque cursor from a previous response's `next_page`. -### Header Parameters +#### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Returns +#### Returns -- `data: array of object { created_at, created_by_actor_id, federation_rule_id, 3 more }` +- `data: array of object` - `created_at: string` When this workspace was enabled for the rule. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_...` or `svac_...`) of the actor that enabled this workspace for the rule, if known.
- `type: "federation_rule_workspace"` - - `"federation_rule_workspace"` + default: federation_rule_workspace - `workspace_id: string`
Opaque cursor for the next page; null when there are no more results. -### Example +#### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \ -H 'anthropic-version: 2023-06-01' \ -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +##### Response (200) ```json {
} ``` -## Add Federation Rule Workspace +### Add Federation Rule Workspace -**post** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces` +**POST** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces` Enable a federation rule for a workspace.
`oauth_scope` is `workspace:developer` or `workspace:inference`; other scopes require a Console session. Admin API keys are not accepted. -### Path Parameters +#### Path parameters - `federation_rule_id: string` ID of the federation rule. -### Header Parameters +#### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Body Parameters +#### Body parameters - `workspace_id: string` Tagged ID of the workspace to enable this rule for. -### Returns +#### Returns - `created_at: string` When this workspace was enabled for the rule. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_...` or `svac_...`) of the actor that enabled this workspace for the rule, if known.
- `type: "federation_rule_workspace"` - - `"federation_rule_workspace"` + default: federation_rule_workspace - `workspace_id: string`
Workspace display name. Populated when listing; null in the enable response. -### Example +#### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +##### Response (200) ```json {
} ``` -## Remove Federation Rule Workspace +### Remove Federation Rule Workspace -**delete** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id}` +**DELETE** `/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id}` Disable a federation rule for a workspace.
`workspace:developer` or `workspace:inference`; other scopes require a Console session. Admin API keys are not accepted. -### Path Parameters +#### Path parameters - `federation_rule_id: string`
ID of the workspace to disable for. -### Header Parameters +#### Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Returns +#### Returns - `federation_rule_id: string`
- `type: "federation_rule_workspace_deleted"` - - `"federation_rule_workspace_deleted"` + default: federation_rule_workspace_deleted - `workspace_id: string` Tagged ID of the workspace named in the delete request. Removal is idempotent. -### Example +#### Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/workspaces/$WORKSPACE_ID \ -X DELETE \ -H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +##### Response (200) ```json {
"workspace_id": "workspace_id" } ``` - -## Domain Types - -### Workspace List Response - -- `WorkspaceListResponse object { created_at, created_by_actor_id, federation_rule_id, 3 more }` - - - `created_at: string` - - When this workspace was enabled for the rule. - - - `created_by_actor_id: string or null` - - Tagged ID (`user_...` or `svac_...`) of the actor that enabled this workspace for the rule, if known. - - - `federation_rule_id: string` - - Tagged ID of the federation rule. - - - `type: "federation_rule_workspace"` - - - `"federation_rule_workspace"` - - - `workspace_id: string` - - Tagged ID of the workspace this rule is enabled for. - - - `workspace_name: string or null` - - Workspace display name. Populated when listing; null in the enable response. - -### Workspace Create Response - -- `WorkspaceCreateResponse object { created_at, created_by_actor_id, federation_rule_id, 3 more }` - - - `created_at: string` - - When this workspace was enabled for the rule. - - - `created_by_actor_id: string or null` - - Tagged ID (`user_...` or `svac_...`) of the actor that enabled this workspace for the rule, if known. - - - `federation_rule_id: string` - - Tagged ID of the federation rule. - - - `type: "federation_rule_workspace"` - - - `"federation_rule_workspace"` - - - `workspace_id: string` - - Tagged ID of the workspace this rule is enabled for. - - - `workspace_name: string or null` - - Workspace display name. Populated when listing; null in the enable response. - -### Workspace Delete Response - -- `WorkspaceDeleteResponse object { federation_rule_id, type, workspace_id }` - - - `federation_rule_id: string` - - Tagged ID of the federation rule. - - - `type: "federation_rule_workspace_deleted"` - - - `"federation_rule_workspace_deleted"` - - - `workspace_id: string` - - Tagged ID of the workspace named in the delete request. Removal is idempotent.