Claude Platform Docs

Crear regla de federación

$ ant beta:organization:federation:rules create
POST/v1/organizations/federation_rules

Requiere un token de acceso OAuth con el alcance org:admin, obtenido con ant auth login --scope org:admin o mediante una regla de federación de identidades de carga de trabajo; no se aceptan claves de Admin API. Consulta Administrar WIF con la Admin API.

Crea una regla de federación propiedad de tu organización.

El emisor referenciado y la cuenta de servicio de destino ya deben existir en la misma organización; las referencias no válidas se rechazan con un error 400. La referencia al espacio de trabajo se valida. La membresía no se verifica al crear la regla: el intercambio de tokens resuelve un único espacio de trabajo habilitado por llamada y se rechaza a menos que la cuenta de servicio de destino sea miembro de ese espacio de trabajo (es implícitamente miembro del espacio de trabajo predeterminado). Las reglas sobre emisores compartidos conocidos (GitHub Actions, GitLab, Buildkite, Terraform Cloud, Google) deben restringir la identidad del tenant mediante un claim que contenga identidad, un prefijo de subject que fije el tenant (como repo:YOUR_ORG/...) o una condición CEL que haga referencia a uno de esos claims de identidad (p. ej., claims.repository_owner). Los llamadores OAuth solo pueden administrar reglas cuyo oauth_scope sea workspace:developer o workspace:inference; otros alcances requieren una sesión de Console.

Parameters
--issuer-id: string

Body param: Tagged ID of the federation issuer.

--match: object{ audience, claims, condition, subject_prefix }

Body param: Conditions the verified JWT must satisfy for this rule to apply. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

--name: string

Body param: Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

maxLength255
minLength1
--oauth-scope: string

Body param: Space-separated OAuth scopes. OAuth callers may only set workspace:developer or workspace:inference; other scopes (such as org:admin) require a Console session.

minLength1
--target: object{ service_account_id, type, service_account_name }

Body param: Identity that tokens minted via this rule act as. Currently always a service_account target.

--applies-to-all-workspaces: optional boolean

Body param: When true, enable this rule for every workspace in the org (including workspaces created later).

--attributes: optional map[string]

Body param: CEL expressions {name: expr} extracting named values from claims. Not yet supported; any non-empty value is rejected with 400.

--description: optional string

Body param: Optional free-text description.

maxLength2000
--token-lifetime-seconds: optional number

Body param: Lifetime in seconds for access tokens minted via this rule (60-86400). Defaults to 3600 (1h). Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

maximum86400
minimum60
--workspace-id: optional string

Body param: Tagged ID of the workspace to enable this rule for. Required unless applies_to_all_workspaces is true. Additional workspaces can be added via the /federation_rules/{federation_rule_id}/workspaces sub-resource.

--beta: optional array of AnthropicBeta

Header param: Optional header to specify the beta version(s) you want to use.

Returns
beta_federation_rule: object{ id, applies_to_all_workspaces, archived_at, 17 more }

Authorization rule binding an external OIDC identity to Anthropic.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

id: string

Tagged ID of the federation rule.

applies_to_all_workspaces: boolean

When true, this rule is enabled for every workspace in the org (including ones created after the rule). workspace_ids is ignored at exchange time.

archived_at: string

If set, this rule is archived and rejects token exchange.

formatdate-time
archived_by_actor_id: string

Tagged ID (user_/svac_) of the actor that archived this rule.

attributes: map[string]

CEL expressions extracting named values from claims. Not yet supported; always null.

created_at: string

When this rule was created.

formatdate-time
created_by_actor_id: string

Tagged ID (user_/svac_) of the actor that created this rule.

description: string

Optional free-text description.

issuer_id: string

Tagged ID of the issuer whose tokens this rule accepts.

issuer_name: string

Issuer's display name at read time.

match: object{ audience, claims, condition, subject_prefix }

Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.

audience: optional string

Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.

maxLength1024
claims: optional map[string]

Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.

condition: optional string

CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.

maxLength4096
subject_prefix: optional string

Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.

maxLength1024
name: string

Admin-chosen slug identifier.

oauth_scope: string

Space-separated OAuth scopes granted on the minted token.

target: object{ service_account_id, type, service_account_name }

Identity that tokens minted via this rule act as. Currently always a service_account target.

service_account_id: string

Tagged ID of the service account to mint tokens for.

type: "service_account"
service_account_name: optional string

Service account's display name at read time. Ignored on writes.

token_lifetime_seconds: number

Lifetime in seconds of access tokens minted via this rule. Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

type: "federation_rule"
updated_at: string

When this rule was last updated.

formatdate-time
updated_by_actor_id: string

Tagged ID (user_/svac_) of the actor that last updated this rule.

workspace_id: string

Legacy single-workspace binding. Prefer workspace_ids and the /federation_rules/{federation_rule_id}/workspaces sub-resource for managing workspace enablement.

workspace_ids: array of string

Tagged IDs of the workspaces this rule is enabled for. May be empty for older rules that only carry the legacy workspace_id binding. Ignored at exchange time when applies_to_all_workspaces is true (the list may still be non-empty).

Crear regla de federación
ant beta:organization:federation:rules create \
  --api-key my-anthropic-api-key \
  --issuer-id issuer_id \
  --match '{}' \
  --name x \
  --oauth-scope x \
  --target '{service_account_id: svac_01SDCCSbTxrXDpWc1phhtcfK, type: service_account}'
Returns Examples
Response 200
{
  "id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
  "applies_to_all_workspaces": true,
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "attributes": {
    "foo": "string"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "description": "description",
  "issuer_id": "issuer_id",
  "issuer_name": "issuer_name",
  "match": {
    "audience": "audience",
    "claims": {
      "foo": "string"
    },
    "condition": "condition",
    "subject_prefix": "subject_prefix"
  },
  "name": "prod-deploy-pipeline",
  "oauth_scope": "oauth_scope",
  "target": {
    "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
    "type": "service_account",
    "service_account_name": "service_account_name"
  },
  "token_lifetime_seconds": 0,
  "type": "federation_rule",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id",
  "workspace_id": "workspace_id",
  "workspace_ids": [
    "string"
  ]
}