Claude Platform Docs

Rules

Create Federation Rule
POST/v1/organizations/federation_rules
List Federation Rules
GET/v1/organizations/federation_rules
Get Federation Rule
GET/v1/organizations/federation_rules/{federation_rule_id}
Update Federation Rule
POST/v1/organizations/federation_rules/{federation_rule_id}
Archive Federation Rule
POST/v1/organizations/federation_rules/{federation_rule_id}/archive
Models
BetaFederationRule object{ id, applies_to_all_workspaces, archived_at, 17 more }

Authorization rule binding an external OIDC identity to Anthropic.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

BetaFederationRuleMatch object{ audience, claims, condition, subject_prefix }

Does the incoming JWT qualify?

All populated fields must pass; omitted fields are skipped. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

audience: optional string or null

Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.

maxLength1024
claims: optional map[string] or null

Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.

condition: optional string or null

CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.

maxLength4096
subject_prefix: optional string or null

Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.

maxLength1024
BetaFederationRuleWorkspace object{ created_at, created_by_actor_id, federation_rule_id, 3 more }
created_at: string

When this workspace was enabled for the rule.

formatdate-time
created_by_actor_id: string or null

Tagged ID (user_... or svac_...) of the actor that enabled this workspace for the rule, if known.

federation_rule_id: string

Tagged ID of the federation rule.

type: "federation_rule_workspace"
defaultfederation_rule_workspace
workspace_id: string

Tagged ID of the workspace this rule is enabled for.

workspace_name: string or null

Workspace display name. Populated when listing; null in the enable response.

BetaServiceAccountTarget object{ service_account_id, type, service_account_name }

Bind to a fixed service account by ID.

service_account_id: string

Tagged ID of the service account to mint tokens for.

type: "service_account"
service_account_name: optional string or null

Service account's display name at read time. Ignored on writes.

Add Federation Rule Workspace
POST/v1/organizations/federation_rules/{federation_rule_id}/workspaces
List Federation Rule Workspaces
GET/v1/organizations/federation_rules/{federation_rule_id}/workspaces
Remove Federation Rule Workspace
DELETE/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id}