Claude Platform Docs

Actualizar emisor de federación

$ ant beta:organization:federation:issuers update
POST/v1/organizations/federation_issuers/{federation_issuer_id}

Requiere un token de acceso OAuth con el alcance org:admin, obtenido con ant auth login --scope org:admin o mediante una regla de federación de identidades de carga de trabajo; no se aceptan claves de Admin API. Consulta Administrar WIF con la Admin API.

Actualiza parcialmente un emisor de federación.

Establecer jwks reemplaza la forma JWKS completa de una vez. Los emisores archivados no pueden actualizarse; esto devuelve 400. Crea un nuevo emisor en su lugar.

Actualizar un emisor que respalda una regla con un alcance distinto de workspace:developer o workspace:inference requiere una sesión de Console.

Parameters
--federation-issuer-id: string

Path param: ID of the federation issuer to update.

--check-jti: optional boolean

Body param: Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a jti claim; tokens without one are accepted without single-use enforcement.

--issuer-url: optional string

Body param: Replaces the iss claim value to match against. For discovery-mode issuers without a discovery_base, this is also the URL Anthropic fetches the OIDC discovery document and signing keys from, so changing it repoints the JWKS source. Changing the issuer URL to a well-known shared platform is rejected while any live rule under this issuer would not constrain tenant identity.

minLength1
--jwks: optional BetaJWKSDiscovery { type, ca_cert_pem, discovery_base } or BetaJWKSExplicitURL { type, url, ca_cert_pem } or BetaJWKSInline { keys, type }

Body param: Replaces the entire JWKS configuration.

--jwks-polling-disabled: optional boolean

Body param: Only false is accepted, to re-enable polling after the system pauses it. Polling is paused automatically; sending true is rejected.

--max-jwt-lifetime-seconds: optional number

Body param: Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both iat and exp; a missing iat is rejected.

maximum176400
exclusiveMinimum0
--name: optional string

Body param: Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

maxLength255
minLength1
--beta: optional array of AnthropicBeta

Header param: Optional header to specify the beta version(s) you want to use.

Returns
beta_federation_issuer: object{ id, archived_at, archived_by_actor_id, 12 more }

Registered external OIDC identity provider.

Records an external IdP the organization trusts for the RFC 7523 jwt-bearer grant. The issuer_url must match the JWT iss claim exactly.

id: string

Tagged ID of the federation issuer.

archived_at: string

If set, all rules referencing this issuer reject token exchange.

formatdate-time
archived_by_actor_id: string

Tagged ID (user_/svac_) of the actor that archived this issuer.

check_jti: boolean

Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a jti claim; tokens without one are accepted without single-use enforcement.

created_at: string

When this issuer was created.

formatdate-time
created_by_actor_id: string

Tagged ID (user_/svac_) of the actor that created this issuer.

issuer_url: string

The iss claim value. Incoming JWTs must match exactly.

jwks: BetaJWKSDiscovery { type, ca_cert_pem, discovery_base } or BetaJWKSExplicitURL { type, url, ca_cert_pem } or BetaJWKSInline { keys, type }

How signing keys are obtained for signature verification.

One of the following:
beta_jwks_discovery: object{ type, ca_cert_pem, discovery_base }

JWKS via the issuer's OIDC discovery document.

type: "discovery"
ca_cert_pem: optional string

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
discovery_base: optional string

Set when the discovery URL differs from issuer_url.

beta_jwks_explicit_url: object{ type, url, ca_cert_pem }

JWKS fetched from a fixed endpoint.

type: "explicit_url"
url: string

JWKS endpoint.

minLength1
ca_cert_pem: optional string

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
beta_jwks_inline: object{ keys, type }

JWKS supplied directly; no network fetch.

keys: array of map[unknown]

Inline JWK objects.

minItems1
type: "inline"
jwks_polling_disabled_at: string

If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending jwks_polling_disabled: false via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than workspace:developer or workspace:inference; use a Console session.

formatdate-time
max_jwt_lifetime_seconds: number

Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both iat and exp; a missing iat is rejected.

name: string

Admin-chosen slug identifier.

poll_status: object{ consecutive_failures, last_fetched_at, next_poll_at }

Status of automatic JWKS polling for a federation issuer.

Anthropic periodically fetches the issuer's signing keys in the background. These fields summarize the most recent fetches so the health of the JWKS endpoint can be monitored.

consecutive_failures: number

Consecutive fetch failures since the last success.

last_fetched_at: string

When the last successful fetch completed.

formatdate-time
next_poll_at: string

When the next fetch is scheduled. Null if paused.

formatdate-time
type: "federation_issuer"
updated_at: string

When this issuer was last updated.

formatdate-time
updated_by_actor_id: string

Tagged ID (user_/svac_) of the actor that last updated this issuer.

Actualizar emisor de federación
ant beta:organization:federation:issuers update \
  --api-key my-anthropic-api-key \
  --federation-issuer-id federation_issuer_id
Returns Examples
Response 200
{
  "id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "check_jti": true,
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "issuer_url": "https://token.actions.githubusercontent.com",
  "jwks": {
    "type": "discovery",
    "ca_cert_pem": "ca_cert_pem",
    "discovery_base": "discovery_base"
  },
  "jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
  "max_jwt_lifetime_seconds": 0,
  "name": "github-actions",
  "poll_status": {
    "consecutive_failures": 0,
    "last_fetched_at": "2019-12-27T18:11:19.117Z",
    "next_poll_at": "2019-12-27T18:11:19.117Z"
  },
  "type": "federation_issuer",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id"
}