Create Federation Rule
api/admin/federation_rules/create
Nearest release: v2.1.245, published an hour after this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/admin/federation_rules/create Changed · +43 / -26 lines
# Create Federation Rule ## Headers ## Body parameters ## Returns ## Example ### Response (200) ## Create Federation Rule ### Header Parameters ### Body Parameters ### Returns ### Example #### Response
---- -title: Create Federation Rule -url: https://platform.claude.com/docs/en/api/admin/federation_rules/create ---- +# Create Federation Rule -## Create Federation Rule +**POST** `/v1/organizations/federation_rules` -**post** `/v1/organizations/federation_rules` - Create a federation rule owned by your organization. The referenced issuer and the target service account must already exist
`workspace:inference`; other scopes require a Console session. Admin API keys are not accepted. -### Header Parameters +## Headers - `"anthropic-beta": optional array of string`
To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta. -### Body Parameters +## Body parameters - `issuer_id: string` Tagged ID of the federation issuer. -- `match: object { audience, claims, condition, subject_prefix }` +- `match: object` Conditions the verified JWT must satisfy for this rule to apply. At least one of `subject_prefix` (other than a wildcard-only value like `*`), `claims`, or `condition` is required; `audience` alone is not sufficient.
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default. + maxLength: 1024 + - `claims: optional map[string] or null` Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400. + maxLength: 4096 + - `subject_prefix: optional string or null` Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`. + maxLength: 1024 + - `name: string` Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409. + maxLength: 255, minLength: 1 + - `oauth_scope: string` Space-separated OAuth scopes. OAuth callers may only set `workspace:developer` or `workspace:inference`; other scopes (such as `org:admin`) require a Console session. -- `target: object { service_account_id, type, service_account_name }` + minLength: 1 +- `target: object` + Identity that tokens minted via this rule act as. Currently always a `service_account` target. - `service_account_id: string`
- `type: "service_account"` - - `"service_account"` - - `service_account_name: optional string or null` Service account's display name at read time. Ignored on writes.
Optional free-text description. + maxLength: 2000 + - `token_lifetime_seconds: optional number` Lifetime in seconds for access tokens minted via this rule (60-86400). Defaults to 3600 (1h). Minted tokens are capped at `max(60, min(this value, 2 × remaining assertion validity))` seconds. + maximum: 86400, minimum: 60 + - `workspace_id: optional string or null` Tagged ID of the workspace to enable this rule for. Required unless `applies_to_all_workspaces` is true. Additional workspaces can be added via the `/federation_rules/{federation_rule_id}/workspaces` sub-resource. -### Returns +## Returns -- `FederationRule object { id, applies_to_all_workspaces, archived_at, 17 more }` +- `FederationRule object` Authorization rule binding an external OIDC identity to Anthropic.
If set, this rule is archived and rejects token exchange. + format: date-time + - `archived_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
When this rule was created. + format: date-time + - `created_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that created this rule.
Issuer's display name at read time. - - `match: object { audience, claims, condition, subject_prefix }` + - `match: object` Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default. + maxLength: 1024 + - `claims: optional map[string] or null` Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400. + maxLength: 4096 + - `subject_prefix: optional string or null` Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`. + maxLength: 1024 + - `name: string` Admin-chosen slug identifier.
Space-separated OAuth scopes granted on the minted token. - - `target: object { service_account_id, type, service_account_name }` + - `target: object` Identity that tokens minted via this rule act as. Currently always a `service_account` target.
- `type: "service_account"` - - `"service_account"` - - `service_account_name: optional string or null` Service account's display name at read time. Ignored on writes.
- `type: "federation_rule"` - - `"federation_rule"` + default: federation_rule - `updated_at: string` When this rule was last updated. + format: date-time + - `updated_by_actor_id: string or null` Tagged ID (`user_`/`svac_`) of the actor that last updated this rule.
Tagged IDs of the workspaces this rule is enabled for. May be empty for older rules that only carry the legacy `workspace_id` binding. Ignored at exchange time when `applies_to_all_workspaces` is true (the list may still be non-empty). -### Example +## Example -```http +```bash curl https://api.anthropic.com/v1/organizations/federation_rules \ -H 'Content-Type: application/json' \ -H 'anthropic-version: 2023-06-01' \
}' ``` -#### Response +### Response (200) ```json {