Claude Platform Docs

Issuer

Federation-Issuer erstellen
POST/v1/organizations/federation_issuers

Erfordert ein OAuth-Access-Token mit dem Scope org:admin, aus ant auth login --scope org:admin oder einer Workload-Identity-Federation-Regel; Admin-API-Keys werden nicht akzeptiert. Siehe WIF mit der Admin API verwalten.

Federation-Issuer auflisten
GET/v1/organizations/federation_issuers

Erfordert ein OAuth-Access-Token mit dem Scope org:admin, aus ant auth login --scope org:admin oder einer Workload-Identity-Federation-Regel; Admin-API-Keys werden nicht akzeptiert. Siehe WIF mit der Admin API verwalten.

Federation-Issuer abrufen
GET/v1/organizations/federation_issuers/{federation_issuer_id}

Erfordert ein OAuth-Access-Token mit dem Scope org:admin, aus ant auth login --scope org:admin oder einer Workload-Identity-Federation-Regel; Admin-API-Keys werden nicht akzeptiert. Siehe WIF mit der Admin API verwalten.

Federation-Issuer aktualisieren
POST/v1/organizations/federation_issuers/{federation_issuer_id}

Erfordert ein OAuth-Access-Token mit dem Scope org:admin, aus ant auth login --scope org:admin oder einer Workload-Identity-Federation-Regel; Admin-API-Keys werden nicht akzeptiert. Siehe WIF mit der Admin API verwalten.

Federation-Issuer archivieren
POST/v1/organizations/federation_issuers/{federation_issuer_id}/archive

Erfordert ein OAuth-Access-Token mit dem Scope org:admin, aus ant auth login --scope org:admin oder einer Workload-Identity-Federation-Regel; Admin-API-Keys werden nicht akzeptiert. Siehe WIF mit der Admin API verwalten.

Models
FederationIssuer object{ type: "federation_issuer", id, archived_at, 12 more }

Registered external OIDC identity provider.

Records an external IdP the organization trusts for the RFC 7523 jwt-bearer grant. The issuer_url must match the JWT iss claim exactly.

FederationIssuerPollStatus object{ consecutive_failures, last_fetched_at, next_poll_at }

Status of automatic JWKS polling for a federation issuer.

Anthropic periodically fetches the issuer's signing keys in the background. These fields summarize the most recent fetches so the health of the JWKS endpoint can be monitored.

consecutive_failures: number

Consecutive fetch failures since the last success.

last_fetched_at: string or null

When the last successful fetch completed.

formatdate-time
next_poll_at: string or null

When the next fetch is scheduled. Null if paused.

formatdate-time
JWKSDiscovery object{ type: "discovery", ca_cert_pem, discovery_base }

JWKS via the issuer's OIDC discovery document.

type: "discovery"
ca_cert_pem: optional string or null

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
discovery_base: optional string or null

Set when the discovery URL differs from issuer_url.

JWKSExplicitURL object{ type: "explicit_url", url, ca_cert_pem }

JWKS fetched from a fixed endpoint.

type: "explicit_url"
url: string

JWKS endpoint.

minLength1
ca_cert_pem: optional string or null

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
JWKSInline object{ type: "inline", keys }

JWKS supplied directly; no network fetch.

type: "inline"
keys: array of map[unknown]

Inline JWK objects.

minItems1