Claude Platform Docs

Rules

Create Federation Rule
$ ant beta:organization:federation:rules create
POST/v1/organizations/federation_rules
List Federation Rules
$ ant beta:organization:federation:rules list
GET/v1/organizations/federation_rules
Get Federation Rule
$ ant beta:organization:federation:rules retrieve
GET/v1/organizations/federation_rules/{federation_rule_id}
Update Federation Rule
$ ant beta:organization:federation:rules update
POST/v1/organizations/federation_rules/{federation_rule_id}
Archive Federation Rule
$ ant beta:organization:federation:rules archive
POST/v1/organizations/federation_rules/{federation_rule_id}/archive
Models
beta_federation_rule: object{ id, applies_to_all_workspaces, archived_at, 17 more }

Authorization rule binding an external OIDC identity to Anthropic.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

beta_federation_rule_match: object{ audience, claims, condition, subject_prefix }

Does the incoming JWT qualify?

All populated fields must pass; omitted fields are skipped. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

audience: optional string

Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.

maxLength1024
claims: optional map[string]

Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.

condition: optional string

CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.

maxLength4096
subject_prefix: optional string

Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.

maxLength1024
beta_federation_rule_workspace: object{ created_at, created_by_actor_id, federation_rule_id, 3 more }
created_at: string

When this workspace was enabled for the rule.

formatdate-time
created_by_actor_id: string

Tagged ID (user_... or svac_...) of the actor that enabled this workspace for the rule, if known.

federation_rule_id: string

Tagged ID of the federation rule.

type: "federation_rule_workspace"
workspace_id: string

Tagged ID of the workspace this rule is enabled for.

workspace_name: string

Workspace display name. Populated when listing; null in the enable response.

beta_service_account_target: object{ service_account_id, type, service_account_name }

Bind to a fixed service account by ID.

service_account_id: string

Tagged ID of the service account to mint tokens for.

type: "service_account"
service_account_name: optional string

Service account's display name at read time. Ignored on writes.

Add Federation Rule Workspace
$ ant beta:organization:federation:rules:workspaces add
POST/v1/organizations/federation_rules/{federation_rule_id}/workspaces
List Federation Rule Workspaces
$ ant beta:organization:federation:rules:workspaces list
GET/v1/organizations/federation_rules/{federation_rule_id}/workspaces
Remove Federation Rule Workspace
$ ant beta:organization:federation:rules:workspaces remove
DELETE/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id}