Claude Platform Docs

Actualizar emisor de federación

POST/v1/organizations/federation_issuers/{federation_issuer_id}

Requiere un token de acceso OAuth con el alcance org:admin, obtenido con ant auth login --scope org:admin o mediante una regla de federación de identidades de carga de trabajo; no se aceptan claves de Admin API. Consulta Administrar WIF con la Admin API.

Actualiza parcialmente un emisor de federación.

Establecer jwks reemplaza la forma JWKS completa de una vez. Los emisores archivados no pueden actualizarse; esto devuelve 400. Crea un nuevo emisor en su lugar.

Actualizar un emisor que respalda una regla con un alcance distinto de workspace:developer o workspace:inference requiere una sesión de Console.

Path parameters
federation_issuer_id: string

ID of the federation issuer to update.

Headers
"anthropic-beta": optional array of string

Optional header to specify the beta version(s) you want to use.

To use multiple betas, use a comma separated list like beta1,beta2 or specify the header multiple times for each beta.

Body
check_jti: optional boolean or null

Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a jti claim; tokens without one are accepted without single-use enforcement.

issuer_url: optional string or null

Replaces the iss claim value to match against. For discovery-mode issuers without a discovery_base, this is also the URL Anthropic fetches the OIDC discovery document and signing keys from, so changing it repoints the JWKS source. Changing the issuer URL to a well-known shared platform is rejected while any live rule under this issuer would not constrain tenant identity.

minLength1
jwks: optional object{ type, ca_cert_pem, discovery_base } or object{ type, url, ca_cert_pem } or object{ keys, type } or null

Replaces the entire JWKS configuration.

One of the following:
Discovery object{ type, ca_cert_pem, discovery_base }

JWKS via the issuer's OIDC discovery document.

type: "discovery"
ca_cert_pem: optional string or null

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
discovery_base: optional string or null

Set when the discovery URL differs from issuer_url.

ExplicitURL object{ type, url, ca_cert_pem }

JWKS fetched from a fixed endpoint.

type: "explicit_url"
url: string

JWKS endpoint.

minLength1
ca_cert_pem: optional string or null

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
Inline object{ keys, type }

JWKS supplied directly; no network fetch.

keys: array of map[unknown]

Inline JWK objects.

minItems1
type: "inline"
jwks_polling_disabled: optional boolean or null

Only false is accepted, to re-enable polling after the system pauses it. Polling is paused automatically; sending true is rejected.

max_jwt_lifetime_seconds: optional number or null

Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both iat and exp; a missing iat is rejected.

maximum176400
exclusiveMinimum0
name: optional string or null

Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

maxLength255
minLength1
Returns
FederationIssuer object{ id, archived_at, archived_by_actor_id, 12 more }

Registered external OIDC identity provider.

Records an external IdP the organization trusts for the RFC 7523 jwt-bearer grant. The issuer_url must match the JWT iss claim exactly.

Actualizar emisor de federación
cURL
curl https://api.anthropic.com/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID \
    -H 'Content-Type: application/json' \
    -H 'anthropic-version: 2023-06-01' \
    -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \
    -d '{}'
Returns Examples
Response 200
{
  "id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "check_jti": true,
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "issuer_url": "https://token.actions.githubusercontent.com",
  "jwks": {
    "type": "discovery",
    "ca_cert_pem": "ca_cert_pem",
    "discovery_base": "discovery_base"
  },
  "jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
  "max_jwt_lifetime_seconds": 0,
  "name": "github-actions",
  "poll_status": {
    "consecutive_failures": 0,
    "last_fetched_at": "2019-12-27T18:11:19.117Z",
    "next_poll_at": "2019-12-27T18:11:19.117Z"
  },
  "type": "federation_issuer",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id"
}