Claude Platform Docs

Create Federation Rule

BetaFederationRule beta().organization().federation().rules().create(RuleCreateParamsparams, RequestOptionsrequestOptions = RequestOptions.none())
POST/v1/organizations/federation_rules

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Create a federation rule owned by your organization.

The referenced issuer and the target service account must already exist in the same organization; invalid references are rejected with a 400 error. The workspace reference is validated. Membership is not checked at rule creation: token exchange resolves a single enabled workspace per call and is rejected unless the target service account is a member of that workspace (it is implicitly a member of the default workspace). Rules on well-known shared issuers (GitHub Actions, GitLab, Buildkite, Terraform Cloud, Google) must constrain tenant identity via an identity-bearing claim, a tenant-pinning subject prefix (such as repo:YOUR_ORG/...), or a CEL condition referencing one of those identity claims (e.g. claims.repository_owner). OAuth callers may only manage rules whose oauth_scope is workspace:developer or workspace:inference; other scopes require a Console session.

Parameters
RuleCreateParams params
Optional<List<AnthropicBeta>> betas

Optional header to specify the beta version(s) you want to use.

MESSAGE_BATCHES_2024_09_24("message-batches-2024-09-24")
PROMPT_CACHING_2024_07_31("prompt-caching-2024-07-31")
COMPUTER_USE_2024_10_22("computer-use-2024-10-22")
COMPUTER_USE_2025_01_24("computer-use-2025-01-24")
PDFS_2024_09_25("pdfs-2024-09-25")
TOKEN_COUNTING_2024_11_01("token-counting-2024-11-01")
TOKEN_EFFICIENT_TOOLS_2025_02_19("token-efficient-tools-2025-02-19")
OUTPUT_128K_2025_02_19("output-128k-2025-02-19")
FILES_API_2025_04_14("files-api-2025-04-14")
MCP_CLIENT_2025_04_04("mcp-client-2025-04-04")
MCP_CLIENT_2025_11_20("mcp-client-2025-11-20")
DEV_FULL_THINKING_2025_05_14("dev-full-thinking-2025-05-14")
INTERLEAVED_THINKING_2025_05_14("interleaved-thinking-2025-05-14")
CODE_EXECUTION_2025_05_22("code-execution-2025-05-22")
EXTENDED_CACHE_TTL_2025_04_11("extended-cache-ttl-2025-04-11")
CONTEXT_1M_2025_08_07("context-1m-2025-08-07")
CONTEXT_MANAGEMENT_2025_06_27("context-management-2025-06-27")
MODEL_CONTEXT_WINDOW_EXCEEDED_2025_08_26("model-context-window-exceeded-2025-08-26")
SKILLS_2025_10_02("skills-2025-10-02")
FAST_MODE_2026_02_01("fast-mode-2026-02-01")
OUTPUT_300K_2026_03_24("output-300k-2026-03-24")
USER_PROFILES_2026_03_24("user-profiles-2026-03-24")
USER_PROFILES_2026_08_18("user-profiles-2026-08-18")
ADVISOR_TOOL_2026_03_01("advisor-tool-2026-03-01")
MANAGED_AGENTS_2026_04_01("managed-agents-2026-04-01")
CACHE_DIAGNOSIS_2026_04_07("cache-diagnosis-2026-04-07")
DREAMING_2026_04_21("dreaming-2026-04-21")
THINKING_TOKEN_COUNT_2026_05_13("thinking-token-count-2026-05-13")
SERVER_SIDE_FALLBACK_2026_06_01("server-side-fallback-2026-06-01")
SERVER_SIDE_FALLBACK_2026_07_01("server-side-fallback-2026-07-01")
FALLBACK_CREDIT_2026_06_01("fallback-credit-2026-06-01")
FALLBACK_CREDIT_2026_07_01("fallback-credit-2026-07-01")
AGENT_MEMORY_2026_07_22("agent-memory-2026-07-22")
MID_CONVERSATION_TOOL_CHANGES_2026_07_01("mid-conversation-tool-changes-2026-07-01")
COMPACT_2026_01_12("compact-2026-01-12")
COMPUTER_USE_2025_11_24("computer-use-2025-11-24")
MCP_TUNNELS_2026_06_22("mcp-tunnels-2026-06-22")
STRUCTURED_OUTPUTS_2025_11_13("structured-outputs-2025-11-13")
TASK_BUDGETS_2026_03_13("task-budgets-2026-03-13")
THINKING_DISPLAY_UPDATES_2026_08_18("thinking-display-updates-2026-08-18")
CE_USER_MANAGEMENT_2026_07_13("ce-user-management-2026-07-13")
String issuerId

Tagged ID of the federation issuer.

Conditions the verified JWT must satisfy for this rule to apply. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

String name

Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

maxLength255
minLength1
String oauthScope

Space-separated OAuth scopes. OAuth callers may only set workspace:developer or workspace:inference; other scopes (such as org:admin) require a Console session.

minLength1

Identity that tokens minted via this rule act as. Currently always a service_account target.

Optional<Boolean> appliesToAllWorkspaces

When true, enable this rule for every workspace in the org (including workspaces created later).

Optional<Attributes> attributes

CEL expressions {name: expr} extracting named values from claims. Not yet supported; any non-empty value is rejected with 400.

Optional<String> description

Optional free-text description.

maxLength2000
Optional<Long> tokenLifetimeSeconds

Lifetime in seconds for access tokens minted via this rule (60-86400). Defaults to 3600 (1h). Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

maximum86400
minimum60
Optional<String> workspaceId

Tagged ID of the workspace to enable this rule for. Required unless applies_to_all_workspaces is true. Additional workspaces can be added via the /federation_rules/{federation_rule_id}/workspaces sub-resource.

Returns
class BetaFederationRule:

Authorization rule binding an external OIDC identity to Anthropic.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

Create Federation Rule

package com.anthropic.example;

import com.anthropic.client.AnthropicClient;
import com.anthropic.client.okhttp.AnthropicOkHttpClient;
import com.anthropic.models.beta.organization.federation.rules.BetaFederationRule;
import com.anthropic.models.beta.organization.federation.rules.BetaFederationRuleMatch;
import com.anthropic.models.beta.organization.federation.rules.BetaServiceAccountTarget;
import com.anthropic.models.beta.organization.federation.rules.RuleCreateParams;

public final class Main {
    private Main() {}

    public static void main(String[] args) {
        AnthropicClient client = AnthropicOkHttpClient.fromEnv();

        RuleCreateParams params = RuleCreateParams.builder()
            .issuerId("issuer_id")
            .match(BetaFederationRuleMatch.builder().build())
            .name("x")
            .oauthScope("x")
            .target(BetaServiceAccountTarget.of("svac_01SDCCSbTxrXDpWc1phhtcfK"))
            .build();
        BetaFederationRule betaFederationRule = client.beta().organization().federation().rules().create(params);
    }
}
{
  "id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
  "applies_to_all_workspaces": true,
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "attributes": {
    "foo": "string"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "description": "description",
  "issuer_id": "issuer_id",
  "issuer_name": "issuer_name",
  "match": {
    "audience": "audience",
    "claims": {
      "foo": "string"
    },
    "condition": "condition",
    "subject_prefix": "subject_prefix"
  },
  "name": "prod-deploy-pipeline",
  "oauth_scope": "oauth_scope",
  "target": {
    "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
    "type": "service_account",
    "service_account_name": "service_account_name"
  },
  "token_lifetime_seconds": 0,
  "type": "federation_rule",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id",
  "workspace_id": "workspace_id",
  "workspace_ids": [
    "string"
  ]
}
Returns Examples
{
  "id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
  "applies_to_all_workspaces": true,
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "attributes": {
    "foo": "string"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "description": "description",
  "issuer_id": "issuer_id",
  "issuer_name": "issuer_name",
  "match": {
    "audience": "audience",
    "claims": {
      "foo": "string"
    },
    "condition": "condition",
    "subject_prefix": "subject_prefix"
  },
  "name": "prod-deploy-pipeline",
  "oauth_scope": "oauth_scope",
  "target": {
    "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
    "type": "service_account",
    "service_account_name": "service_account_name"
  },
  "token_lifetime_seconds": 0,
  "type": "federation_rule",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id",
  "workspace_id": "workspace_id",
  "workspace_ids": [
    "string"
  ]
}