Claude Platform Docs

Crear regla de federación

$client->beta->organization->federation->rules->create(string issuerID, BetaFederationRuleMatch match, string name, string oauthScope, BetaServiceAccountTarget target, ?bool appliesToAllWorkspaces, ?array<string,string> attributes, ?string description, ?int tokenLifetimeSeconds, ?string workspaceID, ?list<AnthropicBeta> betas): BetaFederationRule
POST/v1/organizations/federation_rules

Requiere un token de acceso OAuth con el alcance org:admin, obtenido con ant auth login --scope org:admin o mediante una regla de federación de identidades de carga de trabajo; no se aceptan claves de Admin API. Consulta Administrar WIF con la Admin API.

Crea una regla de federación propiedad de tu organización.

El emisor referenciado y la cuenta de servicio de destino ya deben existir en la misma organización; las referencias no válidas se rechazan con un error 400. La referencia al espacio de trabajo se valida. La membresía no se verifica al crear la regla: el intercambio de tokens resuelve un único espacio de trabajo habilitado por llamada y se rechaza a menos que la cuenta de servicio de destino sea miembro de ese espacio de trabajo (es implícitamente miembro del espacio de trabajo predeterminado). Las reglas sobre emisores compartidos conocidos (GitHub Actions, GitLab, Buildkite, Terraform Cloud, Google) deben restringir la identidad del tenant mediante un claim que contenga identidad, un prefijo de subject que fije el tenant (como repo:YOUR_ORG/...) o una condición CEL que haga referencia a uno de esos claims de identidad (p. ej., claims.repository_owner). Los llamadores OAuth solo pueden administrar reglas cuyo oauth_scope sea workspace:developer o workspace:inference; otros alcances requieren una sesión de Console.

Parameters
issuerID: string

Tagged ID of the federation issuer.

Conditions the verified JWT must satisfy for this rule to apply. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

name: string

Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

oauthScope: string

Space-separated OAuth scopes. OAuth callers may only set workspace:developer or workspace:inference; other scopes (such as org:admin) require a Console session.

Identity that tokens minted via this rule act as. Currently always a service_account target.

appliesToAllWorkspaces?:optional bool

When true, enable this rule for every workspace in the org (including workspaces created later).

attributes?:optional array<string,string>

CEL expressions {name: expr} extracting named values from claims. Not yet supported; any non-empty value is rejected with 400.

description?:optional string

Optional free-text description.

tokenLifetimeSeconds?:optional int

Lifetime in seconds for access tokens minted via this rule (60-86400). Defaults to 3600 (1h). Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

workspaceID?:optional string

Tagged ID of the workspace to enable this rule for. Required unless applies_to_all_workspaces is true. Additional workspaces can be added via the /federation_rules/{federation_rule_id}/workspaces sub-resource.

betas?:optional list<AnthropicBeta>

Optional header to specify the beta version(s) you want to use.

Returns
class BetaFederationRule { $type = 'federation_rule'; $id; $appliesToAllWorkspaces; /* 17 more */ }
Crear regla de federación
<?php

require_once dirname(__DIR__) . '/vendor/autoload.php';

$client = new Client(apiKey: 'my-anthropic-api-key');

$betaFederationRule = $client->beta->organization->federation->rules->create(
  issuerID: 'issuer_id',
  match: [
    'audience' => 'audience',
    'claims' => ['foo' => 'string'],
    'condition' => 'condition',
    'subjectPrefix' => 'subject_prefix',
  ],
  name: 'x',
  oauthScope: 'x',
  target: [
    'serviceAccountID' => 'svac_01SDCCSbTxrXDpWc1phhtcfK',
    'type' => 'service_account',
    'serviceAccountName' => 'service_account_name',
  ],
  appliesToAllWorkspaces: true,
  attributes: ['foo' => 'string'],
  description: 'description',
  tokenLifetimeSeconds: 60,
  workspaceID: 'workspace_id',
  betas: [AnthropicBeta::MESSAGE_BATCHES_2024_09_24],
);

var_dump($betaFederationRule);
Returns Examples
Response 200
{
  "id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
  "applies_to_all_workspaces": true,
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "attributes": {
    "foo": "string"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "description": "description",
  "issuer_id": "issuer_id",
  "issuer_name": "issuer_name",
  "match": {
    "audience": "audience",
    "claims": {
      "foo": "string"
    },
    "condition": "condition",
    "subject_prefix": "subject_prefix"
  },
  "name": "prod-deploy-pipeline",
  "oauth_scope": "oauth_scope",
  "target": {
    "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
    "type": "service_account",
    "service_account_name": "service_account_name"
  },
  "token_lifetime_seconds": 0,
  "type": "federation_rule",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id",
  "workspace_id": "workspace_id",
  "workspace_ids": [
    "string"
  ]
}