Claude Platform Docs

Rules

Create Federation Rule
BetaFederationRule beta().organization().federation().rules().create(RuleCreateParamsparams, RequestOptionsrequestOptions = RequestOptions.none())
POST/v1/organizations/federation_rules
List Federation Rules
RuleListPage beta().organization().federation().rules().list(RuleListParamsparams = RuleListParams.none(), RequestOptionsrequestOptions = RequestOptions.none())
GET/v1/organizations/federation_rules
Get Federation Rule
BetaFederationRule beta().organization().federation().rules().retrieve(RuleRetrieveParamsparams = RuleRetrieveParams.none(), RequestOptionsrequestOptions = RequestOptions.none())
GET/v1/organizations/federation_rules/{federation_rule_id}
Update Federation Rule
BetaFederationRule beta().organization().federation().rules().update(RuleUpdateParamsparams = RuleUpdateParams.none(), RequestOptionsrequestOptions = RequestOptions.none())
POST/v1/organizations/federation_rules/{federation_rule_id}
Archive Federation Rule
BetaFederationRule beta().organization().federation().rules().archive(RuleArchiveParamsparams = RuleArchiveParams.none(), RequestOptionsrequestOptions = RequestOptions.none())
POST/v1/organizations/federation_rules/{federation_rule_id}/archive
Models
class BetaFederationRule:

Authorization rule binding an external OIDC identity to Anthropic.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

class BetaFederationRuleMatch:

Does the incoming JWT qualify?

All populated fields must pass; omitted fields are skipped. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

Optional<String> audience

Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.

maxLength1024
Optional<Claims> claims

Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.

Optional<String> condition

CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.

maxLength4096
Optional<String> subjectPrefix

Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.

maxLength1024
class BetaFederationRuleWorkspace:
LocalDateTime createdAt

When this workspace was enabled for the rule.

formatdate-time
Optional<String> createdByActorId

Tagged ID (user_... or svac_...) of the actor that enabled this workspace for the rule, if known.

String federationRuleId

Tagged ID of the federation rule.

JsonValue type "federation_rule_workspace"constant
String workspaceId

Tagged ID of the workspace this rule is enabled for.

Optional<String> workspaceName

Workspace display name. Populated when listing; null in the enable response.

class BetaServiceAccountTarget:

Bind to a fixed service account by ID.

String serviceAccountId

Tagged ID of the service account to mint tokens for.

JsonValue type "service_account"constant
Optional<String> serviceAccountName

Service account's display name at read time. Ignored on writes.

Add Federation Rule Workspace
BetaFederationRuleWorkspace beta().organization().federation().rules().workspaces().add(WorkspaceAddParamsparams, RequestOptionsrequestOptions = RequestOptions.none())
POST/v1/organizations/federation_rules/{federation_rule_id}/workspaces
List Federation Rule Workspaces
WorkspaceListPage beta().organization().federation().rules().workspaces().list(WorkspaceListParamsparams = WorkspaceListParams.none(), RequestOptionsrequestOptions = RequestOptions.none())
GET/v1/organizations/federation_rules/{federation_rule_id}/workspaces
Remove Federation Rule Workspace
WorkspaceRemoveResponse beta().organization().federation().rules().workspaces().remove(WorkspaceRemoveParamsparams, RequestOptionsrequestOptions = RequestOptions.none())
DELETE/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id}