Claude Platform Docs

Create Federation Issuer

BetaFederationIssuer beta().organization().federation().issuers().create(IssuerCreateParamsparams, RequestOptionsrequestOptions = RequestOptions.none())
POST/v1/organizations/federation_issuers

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Register an OIDC issuer that Anthropic will trust for workload identity federation in your organization.

The jwks field controls how the issuer's signing keys are obtained and takes one of three shapes selected by type: discovery (resolve keys through OIDC discovery), explicit_url (fetch keys from a fixed JWKS URL), or inline (provide a static key set). When jwks.type is discovery and no discovery_base is set, the issuer URL must be publicly reachable over HTTPS so Anthropic can fetch the discovery document; for explicit_url and inline modes the issuer URL is only matched as the JWT's iss claim and is not fetched.

Parameters
IssuerCreateParams params
Optional<List<AnthropicBeta>> betas

Optional header to specify the beta version(s) you want to use.

MESSAGE_BATCHES_2024_09_24("message-batches-2024-09-24")
PROMPT_CACHING_2024_07_31("prompt-caching-2024-07-31")
COMPUTER_USE_2024_10_22("computer-use-2024-10-22")
COMPUTER_USE_2025_01_24("computer-use-2025-01-24")
PDFS_2024_09_25("pdfs-2024-09-25")
TOKEN_COUNTING_2024_11_01("token-counting-2024-11-01")
TOKEN_EFFICIENT_TOOLS_2025_02_19("token-efficient-tools-2025-02-19")
OUTPUT_128K_2025_02_19("output-128k-2025-02-19")
FILES_API_2025_04_14("files-api-2025-04-14")
MCP_CLIENT_2025_04_04("mcp-client-2025-04-04")
MCP_CLIENT_2025_11_20("mcp-client-2025-11-20")
DEV_FULL_THINKING_2025_05_14("dev-full-thinking-2025-05-14")
INTERLEAVED_THINKING_2025_05_14("interleaved-thinking-2025-05-14")
CODE_EXECUTION_2025_05_22("code-execution-2025-05-22")
EXTENDED_CACHE_TTL_2025_04_11("extended-cache-ttl-2025-04-11")
CONTEXT_1M_2025_08_07("context-1m-2025-08-07")
CONTEXT_MANAGEMENT_2025_06_27("context-management-2025-06-27")
MODEL_CONTEXT_WINDOW_EXCEEDED_2025_08_26("model-context-window-exceeded-2025-08-26")
SKILLS_2025_10_02("skills-2025-10-02")
FAST_MODE_2026_02_01("fast-mode-2026-02-01")
OUTPUT_300K_2026_03_24("output-300k-2026-03-24")
USER_PROFILES_2026_03_24("user-profiles-2026-03-24")
USER_PROFILES_2026_08_18("user-profiles-2026-08-18")
ADVISOR_TOOL_2026_03_01("advisor-tool-2026-03-01")
MANAGED_AGENTS_2026_04_01("managed-agents-2026-04-01")
CACHE_DIAGNOSIS_2026_04_07("cache-diagnosis-2026-04-07")
DREAMING_2026_04_21("dreaming-2026-04-21")
THINKING_TOKEN_COUNT_2026_05_13("thinking-token-count-2026-05-13")
SERVER_SIDE_FALLBACK_2026_06_01("server-side-fallback-2026-06-01")
SERVER_SIDE_FALLBACK_2026_07_01("server-side-fallback-2026-07-01")
FALLBACK_CREDIT_2026_06_01("fallback-credit-2026-06-01")
FALLBACK_CREDIT_2026_07_01("fallback-credit-2026-07-01")
AGENT_MEMORY_2026_07_22("agent-memory-2026-07-22")
MID_CONVERSATION_TOOL_CHANGES_2026_07_01("mid-conversation-tool-changes-2026-07-01")
COMPACT_2026_01_12("compact-2026-01-12")
COMPUTER_USE_2025_11_24("computer-use-2025-11-24")
MCP_TUNNELS_2026_06_22("mcp-tunnels-2026-06-22")
STRUCTURED_OUTPUTS_2025_11_13("structured-outputs-2025-11-13")
TASK_BUDGETS_2026_03_13("task-budgets-2026-03-13")
THINKING_DISPLAY_UPDATES_2026_08_18("thinking-display-updates-2026-08-18")
CE_USER_MANAGEMENT_2026_07_13("ce-user-management-2026-07-13")
String issuerUrl

The iss claim value to match against.

minLength1
String name

Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

maxLength255
minLength1
Optional<Boolean> checkJti

Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Defaults to true. Applies only to assertions carrying a jti claim; tokens without one are accepted without single-use enforcement.

Optional<Jwks> jwks

How signing keys are obtained. Defaults to OIDC discovery.

class BetaJwksDiscovery:

JWKS via the issuer's OIDC discovery document.

JsonValue type "discovery"constant
Optional<String> caCertPem

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
Optional<String> discoveryBase

Set when the discovery URL differs from issuer_url.

class BetaJwksExplicitUrl:

JWKS fetched from a fixed endpoint.

JsonValue type "explicit_url"constant
String url

JWKS endpoint.

minLength1
Optional<String> caCertPem

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
class BetaJwksInline:

JWKS supplied directly; no network fetch.

List<Key> keys

Inline JWK objects.

minItems1
JsonValue type "inline"constant
Optional<Long> maxJwtLifetimeSeconds

Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Defaults to 3600 (1h). Assertions must carry both iat and exp; a missing iat is rejected.

maximum176400
exclusiveMinimum0
Returns
class BetaFederationIssuer:

Registered external OIDC identity provider.

Records an external IdP the organization trusts for the RFC 7523 jwt-bearer grant. The issuer_url must match the JWT iss claim exactly.

Create Federation Issuer

package com.anthropic.example;

import com.anthropic.client.AnthropicClient;
import com.anthropic.client.okhttp.AnthropicOkHttpClient;
import com.anthropic.models.beta.organization.federation.issuers.BetaFederationIssuer;
import com.anthropic.models.beta.organization.federation.issuers.IssuerCreateParams;

public final class Main {
    private Main() {}

    public static void main(String[] args) {
        AnthropicClient client = AnthropicOkHttpClient.fromEnv();

        IssuerCreateParams params = IssuerCreateParams.builder()
            .issuerUrl("x")
            .name("x")
            .build();
        BetaFederationIssuer betaFederationIssuer = client.beta().organization().federation().issuers().create(params);
    }
}
{
  "id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "check_jti": true,
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "issuer_url": "https://token.actions.githubusercontent.com",
  "jwks": {
    "type": "discovery",
    "ca_cert_pem": "ca_cert_pem",
    "discovery_base": "discovery_base"
  },
  "jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
  "max_jwt_lifetime_seconds": 0,
  "name": "github-actions",
  "poll_status": {
    "consecutive_failures": 0,
    "last_fetched_at": "2019-12-27T18:11:19.117Z",
    "next_poll_at": "2019-12-27T18:11:19.117Z"
  },
  "type": "federation_issuer",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id"
}
Returns Examples
{
  "id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "check_jti": true,
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "issuer_url": "https://token.actions.githubusercontent.com",
  "jwks": {
    "type": "discovery",
    "ca_cert_pem": "ca_cert_pem",
    "discovery_base": "discovery_base"
  },
  "jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
  "max_jwt_lifetime_seconds": 0,
  "name": "github-actions",
  "poll_status": {
    "consecutive_failures": 0,
    "last_fetched_at": "2019-12-27T18:11:19.117Z",
    "next_poll_at": "2019-12-27T18:11:19.117Z"
  },
  "type": "federation_issuer",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id"
}