Claude Platform Docs

Émetteurs

Créer un émetteur de fédération
POST/v1/organizations/federation_issuers

Nécessite un jeton d'accès OAuth avec la portée org:admin, obtenu via ant auth login --scope org:admin ou une règle de fédération d'identité de charge de travail ; les clés Admin API ne sont pas acceptées. Consultez Gérer WIF avec l'Admin API.

Lister les émetteurs de fédération
GET/v1/organizations/federation_issuers

Nécessite un jeton d'accès OAuth avec la portée org:admin, obtenu via ant auth login --scope org:admin ou une règle de fédération d'identité de charge de travail ; les clés Admin API ne sont pas acceptées. Consultez Gérer WIF avec l'Admin API.

Obtenir un émetteur de fédération
GET/v1/organizations/federation_issuers/{federation_issuer_id}

Nécessite un jeton d'accès OAuth avec la portée org:admin, obtenu via ant auth login --scope org:admin ou une règle de fédération d'identité de charge de travail ; les clés Admin API ne sont pas acceptées. Consultez Gérer WIF avec l'Admin API.

Mettre à jour un émetteur de fédération
POST/v1/organizations/federation_issuers/{federation_issuer_id}

Nécessite un jeton d'accès OAuth avec la portée org:admin, obtenu via ant auth login --scope org:admin ou une règle de fédération d'identité de charge de travail ; les clés Admin API ne sont pas acceptées. Consultez Gérer WIF avec l'Admin API.

Archiver un émetteur de fédération
POST/v1/organizations/federation_issuers/{federation_issuer_id}/archive

Nécessite un jeton d'accès OAuth avec la portée org:admin, obtenu via ant auth login --scope org:admin ou une règle de fédération d'identité de charge de travail ; les clés Admin API ne sont pas acceptées. Consultez Gérer WIF avec l'Admin API.

Models
FederationIssuer object{ type: "federation_issuer", id, archived_at, 12 more }

Registered external OIDC identity provider.

Records an external IdP the organization trusts for the RFC 7523 jwt-bearer grant. The issuer_url must match the JWT iss claim exactly.

FederationIssuerPollStatus object{ consecutive_failures, last_fetched_at, next_poll_at }

Status of automatic JWKS polling for a federation issuer.

Anthropic periodically fetches the issuer's signing keys in the background. These fields summarize the most recent fetches so the health of the JWKS endpoint can be monitored.

consecutive_failures: number

Consecutive fetch failures since the last success.

last_fetched_at: string or null

When the last successful fetch completed.

formatdate-time
next_poll_at: string or null

When the next fetch is scheduled. Null if paused.

formatdate-time
JWKSDiscovery object{ type: "discovery", ca_cert_pem, discovery_base }

JWKS via the issuer's OIDC discovery document.

type: "discovery"
ca_cert_pem: optional string or null

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
discovery_base: optional string or null

Set when the discovery URL differs from issuer_url.

JWKSExplicitURL object{ type: "explicit_url", url, ca_cert_pem }

JWKS fetched from a fixed endpoint.

type: "explicit_url"
url: string

JWKS endpoint.

minLength1
ca_cert_pem: optional string or null

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
JWKSInline object{ type: "inline", keys }

JWKS supplied directly; no network fetch.

type: "inline"
keys: array of map[unknown]

Inline JWK objects.

minItems1