Claude Platform Docs

Actualizar regla de federación

BetaFederationRule Beta.Organization.Federation.Rules.Update(parameters, cancellationToken = default)
POST/v1/organizations/federation_rules/{federation_rule_id}

Requiere un token de acceso OAuth con el alcance org:admin, obtenido con ant auth login --scope org:admin o mediante una regla de federación de identidades de carga de trabajo; no se aceptan claves de Admin API. Consulta Administrar WIF con la Admin API.

Actualiza parcialmente una regla de federación.

issuer_id es inmutable. match y target se reemplazan como objetos completos cuando se establecen. Las cuentas de servicio y los espacios de trabajo referenciados deben existir en tu organización; las referencias no válidas se rechazan con un error 400. Las reglas archivadas no pueden actualizarse; esto devuelve 400. Crea una nueva regla en su lugar. Las reglas sobre emisores compartidos conocidos (GitHub Actions, GitLab, Buildkite, Terraform Cloud, Google) deben restringir la identidad del tenant mediante un claim que contenga identidad, un prefijo de subject que fije el tenant (como repo:YOUR_ORG/...) o una condición CEL que haga referencia a uno de esos claims de identidad (p. ej., claims.repository_owner). En estos emisores, el requisito se vuelve a verificar en cada actualización; si el match almacenado de una regla existente aún no restringe la identidad del tenant, cualquier actualización (incluso un cambio de nombre o de descripción) también debe proporcionar un match conforme en la misma solicitud. Los llamadores OAuth solo pueden administrar reglas cuyo oauth_scope sea workspace:developer o workspace:inference; otros alcances requieren una sesión de Console.

Parameters
RuleUpdateParams parameters
required string federationRuleID

Path param: ID of the federation rule to update.

bool? appliesToAllWorkspaces

Body param: When true, enables this rule for every workspace in the org (including workspaces created later). Setting false is rejected with 400 if no workspace would remain enabled; a rule with only a legacy workspace_id binding continues to mint.

IReadOnlyDictionary<string, string>? attributes

Body param: Replaces the CEL expressions {name: expr} extracting named values from claims. Send null to clear them. Not yet supported; any non-empty value is rejected with 400.

string? description

Body param: Replaces the description. Omit to leave unchanged; send null to clear (the field is stored as an empty string).

maxLength2000

Body param: Does the incoming JWT qualify?

All populated fields must pass; omitted fields are skipped. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

string? name

Body param: Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

maxLength255
minLength1
string? oauthScope

Body param: Replaces the space-separated OAuth scopes granted on minted tokens. OAuth callers may only set workspace:developer or workspace:inference; other scopes (such as org:admin) require a Console session.

minLength1

Body param: Bind to a fixed service account by ID.

long? tokenLifetimeSeconds

Body param: Replaces the lifetime in seconds for access tokens minted via this rule (60-86400). Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

maximum86400
minimum60
string? workspaceID

Body param: Replaces the existing single workspace enablement (the previous one is removed). Rejected with 400 if the rule is enabled for more than one workspace; use the /federation_rules/{federation_rule_id}/workspaces sub-resource instead.

IReadOnlyList<AnthropicBeta> betas

Header param: Optional header to specify the beta version(s) you want to use.

MessageBatches2024_09_24("message-batches-2024-09-24")
PromptCaching2024_07_31("prompt-caching-2024-07-31")
ComputerUse2024_10_22("computer-use-2024-10-22")
ComputerUse2025_01_24("computer-use-2025-01-24")
Pdfs2024_09_25("pdfs-2024-09-25")
TokenCounting2024_11_01("token-counting-2024-11-01")
TokenEfficientTools2025_02_19("token-efficient-tools-2025-02-19")
Output128k2025_02_19("output-128k-2025-02-19")
FilesApi2025_04_14("files-api-2025-04-14")
McpClient2025_04_04("mcp-client-2025-04-04")
McpClient2025_11_20("mcp-client-2025-11-20")
DevFullThinking2025_05_14("dev-full-thinking-2025-05-14")
InterleavedThinking2025_05_14("interleaved-thinking-2025-05-14")
CodeExecution2025_05_22("code-execution-2025-05-22")
ExtendedCacheTtl2025_04_11("extended-cache-ttl-2025-04-11")
Context1m2025_08_07("context-1m-2025-08-07")
ContextManagement2025_06_27("context-management-2025-06-27")
ModelContextWindowExceeded2025_08_26("model-context-window-exceeded-2025-08-26")
Skills2025_10_02("skills-2025-10-02")
FastMode2026_02_01("fast-mode-2026-02-01")
Output300k2026_03_24("output-300k-2026-03-24")
UserProfiles2026_03_24("user-profiles-2026-03-24")
UserProfiles2026_08_18("user-profiles-2026-08-18")
UserProfiles2026_09_04("user-profiles-2026-09-04")
AdvisorTool2026_03_01("advisor-tool-2026-03-01")
ManagedAgents2026_04_01("managed-agents-2026-04-01")
CacheDiagnosis2026_04_07("cache-diagnosis-2026-04-07")
Dreaming2026_04_21("dreaming-2026-04-21")
ThinkingTokenCount2026_05_13("thinking-token-count-2026-05-13")
ServerSideFallback2026_06_01("server-side-fallback-2026-06-01")
ServerSideFallback2026_07_01("server-side-fallback-2026-07-01")
FallbackCredit2026_06_01("fallback-credit-2026-06-01")
FallbackCredit2026_07_01("fallback-credit-2026-07-01")
AgentMemory2026_07_22("agent-memory-2026-07-22")
MidConversationToolChanges2026_07_01("mid-conversation-tool-changes-2026-07-01")
Compact2026_01_12("compact-2026-01-12")
ComputerUse2025_11_24("computer-use-2025-11-24")
McpTunnels2026_06_22("mcp-tunnels-2026-06-22")
StructuredOutputs2025_11_13("structured-outputs-2025-11-13")
TaskBudgets2026_03_13("task-budgets-2026-03-13")
ThinkingDisplayUpdates2026_08_18("thinking-display-updates-2026-08-18")
CEUserManagement2026_07_13("ce-user-management-2026-07-13")
MidConversationOutputConfig2026_07_01("mid-conversation-output-config-2026-07-01")
ThinkingBindingControls2026_08_01("thinking-binding-controls-2026-08-01")
MidConversationSystemClearAt2026_08_21("mid-conversation-system-clear-at-2026-08-21")
Compact2026_09_04("compact-2026-09-04")
Returns
class BetaFederationRule { Type = "federation_rule"; ID; AppliesToAllWorkspaces; /* 17 more */ }

Authorization rule binding an external OIDC identity to Anthropic.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

Actualizar regla de federación
RuleUpdateParams parameters = new() { FederationRuleID = "federation_rule_id" };

var betaFederationRule = await client.Beta.Organization.Federation.Rules.Update(parameters);

Console.WriteLine(betaFederationRule);
Returns Examples
Response 200
{
  "id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
  "applies_to_all_workspaces": true,
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "attributes": {
    "foo": "string"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "description": "description",
  "issuer_id": "issuer_id",
  "issuer_name": "issuer_name",
  "match": {
    "audience": "audience",
    "claims": {
      "foo": "string"
    },
    "condition": "condition",
    "subject_prefix": "subject_prefix"
  },
  "name": "prod-deploy-pipeline",
  "oauth_scope": "oauth_scope",
  "target": {
    "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
    "type": "service_account",
    "service_account_name": "service_account_name"
  },
  "token_lifetime_seconds": 0,
  "type": "federation_rule",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id",
  "workspace_id": "workspace_id",
  "workspace_ids": [
    "string"
  ]
}