Claude Platform Docs

Rules

Create Federation Rule
beta.organization.federation.rules.create(**kwargs) -> BetaFederationRule
POST/v1/organizations/federation_rules
List Federation Rules
beta.organization.federation.rules.list(**kwargs) -> PageCursor<BetaFederationRule>
GET/v1/organizations/federation_rules
Get Federation Rule
beta.organization.federation.rules.retrieve(federation_rule_id, **kwargs) -> BetaFederationRule
GET/v1/organizations/federation_rules/{federation_rule_id}
Update Federation Rule
beta.organization.federation.rules.update(federation_rule_id, **kwargs) -> BetaFederationRule
POST/v1/organizations/federation_rules/{federation_rule_id}
Archive Federation Rule
beta.organization.federation.rules.archive(federation_rule_id, **kwargs) -> BetaFederationRule
POST/v1/organizations/federation_rules/{federation_rule_id}/archive
Models
class BetaFederationRule { id, applies_to_all_workspaces, archived_at, 17 more }

Authorization rule binding an external OIDC identity to Anthropic.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

class BetaFederationRuleMatch { audience, claims, condition, subject_prefix }

Does the incoming JWT qualify?

All populated fields must pass; omitted fields are skipped. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

audience: String

Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.

maxLength1024
claims: Hash[Symbol, String]

Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.

condition: String

CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.

maxLength4096
subject_prefix: String

Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.

maxLength1024
class BetaFederationRuleWorkspace { created_at, created_by_actor_id, federation_rule_id, 3 more }
created_at: Time

When this workspace was enabled for the rule.

formatdate-time
created_by_actor_id: String

Tagged ID (user_... or svac_...) of the actor that enabled this workspace for the rule, if known.

federation_rule_id: String

Tagged ID of the federation rule.

type: :federation_rule_workspace
workspace_id: String

Tagged ID of the workspace this rule is enabled for.

workspace_name: String

Workspace display name. Populated when listing; null in the enable response.

class BetaServiceAccountTarget { service_account_id, type, service_account_name }

Bind to a fixed service account by ID.

service_account_id: String

Tagged ID of the service account to mint tokens for.

type: :service_account
service_account_name: String

Service account's display name at read time. Ignored on writes.

Add Federation Rule Workspace
beta.organization.federation.rules.workspaces.add(federation_rule_id, **kwargs) -> BetaFederationRuleWorkspace
POST/v1/organizations/federation_rules/{federation_rule_id}/workspaces
List Federation Rule Workspaces
beta.organization.federation.rules.workspaces.list(federation_rule_id, **kwargs) -> PageCursor<BetaFederationRuleWorkspace>
GET/v1/organizations/federation_rules/{federation_rule_id}/workspaces
Remove Federation Rule Workspace
beta.organization.federation.rules.workspaces.remove(workspace_id, **kwargs) -> WorkspaceRemoveResponse
DELETE/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id}