Archive Federation Rule
api/admin/federation_rules/archive
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/admin/federation_rules/archive Changed · +27 / -22 lines
# Archive Federation Rule ## Path parameters ## Headers ## Returns ## Example ### Response (200) ## Archive Federation Rule ### Path Parameters ### Header Parameters ### Returns ### Example #### Response
---- -title: Archive Federation Rule -url: https://platform.claude.com/docs/en/api/admin/federation_rules/archive ---- +# Archive Federation Rule -## Archive Federation Rule +**POST** `/v1/organizations/federation_rules/{federation_rule_id}/archive` -**post** `/v1/organizations/federation_rules/{federation_rule_id}/archive` - Archive a federation rule. Token exchange through this rule stops immediately. Idempotent;
whose `oauth_scope` is `workspace:developer` or `workspace:inference`; other scopes require a Console session. Admin API keys are not accepted. -### Path Parameters +## Path parameters - `federation_rule_id: string` ID of the federation rule to archive. -### Header Parameters +## Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Returns +## Returns -- `FederationRule object { id, applies_to_all_workspaces, archived_at, 17 more }` +- `FederationRule object` Authorization rule binding an external OIDC identity to Anthropic.
If set, this rule is archived and rejects token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
When this rule was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this rule.
Issuer's display name at read time. - - `match: object { audience, claims, condition, subject_prefix }` + - `match: object` Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default. + maxLength: 1024 + - `claims: optional map[string] or null` Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400. + maxLength: 4096 + - `subject_prefix: optional string or null` Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`. + maxLength: 1024 + - `name: string` Admin-chosen slug identifier.
Space-separated OAuth scopes granted on the minted token. - - `target: object { service_account_id, type, service_account_name }` + - `target: object` Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `type: "service_account"` - - `"service_account"` - - `service_account_name: optional string or null` Service account's display name at read time. Ignored on writes.
- `type: "federation_rule"` - - `"federation_rule"` + default: federation_rule - `updated_at: string` When this rule was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this rule.
Tagged IDs of the workspaces this rule is enabled for. May be empty for older rules that only carry the legacy `workspace_id` binding. Ignored at exchange time when `applies_to_all_workspaces` is true (the list may still be non-empty). -### Example +## Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID/archive \ -X POST \ -H 'anthropic-version: 2023-06-01' \
-H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" ``` -#### Response +### Response (200) ```json {