Claude Platform Docs

Update Federation Issuer

beta.organization.federation.issuers.update(federation_issuer_id, **kwargs) -> BetaFederationIssuer
POST/v1/organizations/federation_issuers/{federation_issuer_id}

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Partially update a federation issuer.

Setting jwks replaces the full JWKS shape at once. Archived issuers cannot be updated; this returns 400. Create a new issuer instead.

Updating an issuer that backs a rule with a scope outside workspace:developer or workspace:inference requires a Console session.

Parameters
federation_issuer_id: String

ID of the federation issuer to update.

check_jti: bool

Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a jti claim; tokens without one are accepted without single-use enforcement.

issuer_url: String

Replaces the iss claim value to match against. For discovery-mode issuers without a discovery_base, this is also the URL Anthropic fetches the OIDC discovery document and signing keys from, so changing it repoints the JWKS source. Changing the issuer URL to a well-known shared platform is rejected while any live rule under this issuer would not constrain tenant identity.

minLength1
jwks: BetaJWKSDiscovery { type, ca_cert_pem, discovery_base } | BetaJWKSExplicitURL { type, url, ca_cert_pem } | BetaJWKSInline { keys, type }

Replaces the entire JWKS configuration.

One of the following:
class BetaJWKSDiscovery { type, ca_cert_pem, discovery_base }

JWKS via the issuer's OIDC discovery document.

type: :discovery
ca_cert_pem: String

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
discovery_base: String

Set when the discovery URL differs from issuer_url.

class BetaJWKSExplicitURL { type, url, ca_cert_pem }

JWKS fetched from a fixed endpoint.

type: :explicit_url
url: String

JWKS endpoint.

minLength1
ca_cert_pem: String

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
class BetaJWKSInline { keys, type }

JWKS supplied directly; no network fetch.

keys: Array[Hash[Symbol, untyped]]

Inline JWK objects.

minItems1
type: :inline
jwks_polling_disabled: bool

Only false is accepted, to re-enable polling after the system pauses it. Polling is paused automatically; sending true is rejected.

max_jwt_lifetime_seconds: Integer

Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both iat and exp; a missing iat is rejected.

maximum176400
exclusiveMinimum0
name: String

Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

maxLength255
minLength1
betas: Array[AnthropicBeta]

Optional header to specify the beta version(s) you want to use.

One of the following:
String = String
AnthropicBeta = :"message-batches-2024-09-24" | :"prompt-caching-2024-07-31" | :"computer-use-2024-10-22" | 38 more
One of the following:
:"message-batches-2024-09-24"
:"prompt-caching-2024-07-31"
:"computer-use-2024-10-22"
:"computer-use-2025-01-24"
:"pdfs-2024-09-25"
:"token-counting-2024-11-01"
:"token-efficient-tools-2025-02-19"
:"output-128k-2025-02-19"
:"files-api-2025-04-14"
:"mcp-client-2025-04-04"
:"mcp-client-2025-11-20"
:"dev-full-thinking-2025-05-14"
:"interleaved-thinking-2025-05-14"
:"code-execution-2025-05-22"
:"extended-cache-ttl-2025-04-11"
:"context-1m-2025-08-07"
:"context-management-2025-06-27"
:"model-context-window-exceeded-2025-08-26"
:"skills-2025-10-02"
:"fast-mode-2026-02-01"
:"output-300k-2026-03-24"
:"user-profiles-2026-03-24"
:"user-profiles-2026-08-18"
:"advisor-tool-2026-03-01"
:"managed-agents-2026-04-01"
:"cache-diagnosis-2026-04-07"
:"dreaming-2026-04-21"
:"thinking-token-count-2026-05-13"
:"server-side-fallback-2026-06-01"
:"server-side-fallback-2026-07-01"
:"fallback-credit-2026-06-01"
:"fallback-credit-2026-07-01"
:"agent-memory-2026-07-22"
:"mid-conversation-tool-changes-2026-07-01"
:"compact-2026-01-12"
:"computer-use-2025-11-24"
:"mcp-tunnels-2026-06-22"
:"structured-outputs-2025-11-13"
:"task-budgets-2026-03-13"
:"thinking-display-updates-2026-08-18"
:"ce-user-management-2026-07-13"
Returns
class BetaFederationIssuer { id, archived_at, archived_by_actor_id, 12 more }

Registered external OIDC identity provider.

Records an external IdP the organization trusts for the RFC 7523 jwt-bearer grant. The issuer_url must match the JWT iss claim exactly.

Update Federation Issuer

require "anthropic"

anthropic = Anthropic::Client.new(api_key: "my-anthropic-api-key")

beta_federation_issuer = anthropic.beta.organization.federation.issuers.update("federation_issuer_id")

puts(beta_federation_issuer)
{
  "id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "check_jti": true,
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "issuer_url": "https://token.actions.githubusercontent.com",
  "jwks": {
    "type": "discovery",
    "ca_cert_pem": "ca_cert_pem",
    "discovery_base": "discovery_base"
  },
  "jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
  "max_jwt_lifetime_seconds": 0,
  "name": "github-actions",
  "poll_status": {
    "consecutive_failures": 0,
    "last_fetched_at": "2019-12-27T18:11:19.117Z",
    "next_poll_at": "2019-12-27T18:11:19.117Z"
  },
  "type": "federation_issuer",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id"
}
Returns Examples
{
  "id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "check_jti": true,
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "issuer_url": "https://token.actions.githubusercontent.com",
  "jwks": {
    "type": "discovery",
    "ca_cert_pem": "ca_cert_pem",
    "discovery_base": "discovery_base"
  },
  "jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
  "max_jwt_lifetime_seconds": 0,
  "name": "github-actions",
  "poll_status": {
    "consecutive_failures": 0,
    "last_fetched_at": "2019-12-27T18:11:19.117Z",
    "next_poll_at": "2019-12-27T18:11:19.117Z"
  },
  "type": "federation_issuer",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id"
}