Claude Platform Docs

Crea regola di federazione

BetaFederationRule Beta.Organization.Federation.Rules.Create(parameters, cancellationToken = default)
POST/v1/organizations/federation_rules

Richiede un token di accesso OAuth con lo scope org:admin, ottenuto da ant auth login --scope org:admin o da una regola di workload identity federation; le chiavi Admin API non sono accettate. Consulta Gestisci WIF con l'Admin API.

Crea una regola di federazione di proprietà della tua organizzazione.

L'emittente referenziato e l'account di servizio di destinazione devono già esistere nella stessa organizzazione; i riferimenti non validi vengono rifiutati con un errore 400. Il riferimento al workspace viene convalidato. L'appartenenza non viene verificata alla creazione della regola: lo scambio di token risolve un singolo workspace abilitato per chiamata e viene rifiutato a meno che l'account di servizio di destinazione non sia membro di quel workspace (è implicitamente membro del workspace predefinito). Le regole su emittenti condivisi noti (GitHub Actions, GitLab, Buildkite, Terraform Cloud, Google) devono vincolare l'identità del tenant tramite un claim che identifica il tenant, un prefisso del subject che fissa il tenant (come repo:YOUR_ORG/...) o una condizione CEL che fa riferimento a uno di questi claim di identità (ad es. claims.repository_owner). I chiamanti OAuth possono gestire solo regole il cui oauth_scope è workspace:developer o workspace:inference; altri scope richiedono una sessione Console.

Parameters
RuleCreateParams parameters
required string issuerID

Body param: Tagged ID of the federation issuer.

required BetaFederationRuleMatch match

Body param: Conditions the verified JWT must satisfy for this rule to apply. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

required string name

Body param: Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

maxLength255
minLength1
required string oauthScope

Body param: Space-separated OAuth scopes. OAuth callers may only set workspace:developer or workspace:inference; other scopes (such as org:admin) require a Console session.

minLength1
required BetaServiceAccountTarget target

Body param: Identity that tokens minted via this rule act as. Currently always a service_account target.

bool appliesToAllWorkspaces

Body param: When true, enable this rule for every workspace in the org (including workspaces created later).

IReadOnlyDictionary<string, string>? attributes

Body param: CEL expressions {name: expr} extracting named values from claims. Not yet supported; any non-empty value is rejected with 400.

string? description

Body param: Optional free-text description.

maxLength2000
long tokenLifetimeSeconds

Body param: Lifetime in seconds for access tokens minted via this rule (60-86400). Defaults to 3600 (1h). Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

maximum86400
minimum60
string? workspaceID

Body param: Tagged ID of the workspace to enable this rule for. Required unless applies_to_all_workspaces is true. Additional workspaces can be added via the /federation_rules/{federation_rule_id}/workspaces sub-resource.

IReadOnlyList<AnthropicBeta> betas

Header param: Optional header to specify the beta version(s) you want to use.

MessageBatches2024_09_24("message-batches-2024-09-24")
PromptCaching2024_07_31("prompt-caching-2024-07-31")
ComputerUse2024_10_22("computer-use-2024-10-22")
ComputerUse2025_01_24("computer-use-2025-01-24")
Pdfs2024_09_25("pdfs-2024-09-25")
TokenCounting2024_11_01("token-counting-2024-11-01")
TokenEfficientTools2025_02_19("token-efficient-tools-2025-02-19")
Output128k2025_02_19("output-128k-2025-02-19")
FilesApi2025_04_14("files-api-2025-04-14")
McpClient2025_04_04("mcp-client-2025-04-04")
McpClient2025_11_20("mcp-client-2025-11-20")
DevFullThinking2025_05_14("dev-full-thinking-2025-05-14")
InterleavedThinking2025_05_14("interleaved-thinking-2025-05-14")
CodeExecution2025_05_22("code-execution-2025-05-22")
ExtendedCacheTtl2025_04_11("extended-cache-ttl-2025-04-11")
Context1m2025_08_07("context-1m-2025-08-07")
ContextManagement2025_06_27("context-management-2025-06-27")
ModelContextWindowExceeded2025_08_26("model-context-window-exceeded-2025-08-26")
Skills2025_10_02("skills-2025-10-02")
FastMode2026_02_01("fast-mode-2026-02-01")
Output300k2026_03_24("output-300k-2026-03-24")
UserProfiles2026_03_24("user-profiles-2026-03-24")
UserProfiles2026_08_18("user-profiles-2026-08-18")
UserProfiles2026_09_04("user-profiles-2026-09-04")
AdvisorTool2026_03_01("advisor-tool-2026-03-01")
ManagedAgents2026_04_01("managed-agents-2026-04-01")
CacheDiagnosis2026_04_07("cache-diagnosis-2026-04-07")
Dreaming2026_04_21("dreaming-2026-04-21")
ThinkingTokenCount2026_05_13("thinking-token-count-2026-05-13")
ServerSideFallback2026_06_01("server-side-fallback-2026-06-01")
ServerSideFallback2026_07_01("server-side-fallback-2026-07-01")
FallbackCredit2026_06_01("fallback-credit-2026-06-01")
FallbackCredit2026_07_01("fallback-credit-2026-07-01")
AgentMemory2026_07_22("agent-memory-2026-07-22")
MidConversationToolChanges2026_07_01("mid-conversation-tool-changes-2026-07-01")
Compact2026_01_12("compact-2026-01-12")
ComputerUse2025_11_24("computer-use-2025-11-24")
McpTunnels2026_06_22("mcp-tunnels-2026-06-22")
StructuredOutputs2025_11_13("structured-outputs-2025-11-13")
TaskBudgets2026_03_13("task-budgets-2026-03-13")
ThinkingDisplayUpdates2026_08_18("thinking-display-updates-2026-08-18")
CEUserManagement2026_07_13("ce-user-management-2026-07-13")
MidConversationOutputConfig2026_07_01("mid-conversation-output-config-2026-07-01")
ThinkingBindingControls2026_08_01("thinking-binding-controls-2026-08-01")
MidConversationSystemClearAt2026_08_21("mid-conversation-system-clear-at-2026-08-21")
Compact2026_09_04("compact-2026-09-04")
Returns
class BetaFederationRule { Type = "federation_rule"; ID; AppliesToAllWorkspaces; /* 17 more */ }

Authorization rule binding an external OIDC identity to Anthropic.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

Crea regola di federazione
RuleCreateParams parameters = new()
{
    IssuerID = "issuer_id",
    Match = new()
    {
        Audience = "audience",
        Claims = new Dictionary<string, string>() { { "foo", "string" } },
        Condition = "condition",
        SubjectPrefix = "subject_prefix",
    },
    Name = "x",
    OAuthScope = "x",
    Target = new()
    {
        ServiceAccountID = "svac_01SDCCSbTxrXDpWc1phhtcfK",
        ServiceAccountName = "service_account_name",
    },
};

var betaFederationRule = await client.Beta.Organization.Federation.Rules.Create(parameters);

Console.WriteLine(betaFederationRule);
Returns Examples
Response 200
{
  "id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
  "applies_to_all_workspaces": true,
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "attributes": {
    "foo": "string"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "description": "description",
  "issuer_id": "issuer_id",
  "issuer_name": "issuer_name",
  "match": {
    "audience": "audience",
    "claims": {
      "foo": "string"
    },
    "condition": "condition",
    "subject_prefix": "subject_prefix"
  },
  "name": "prod-deploy-pipeline",
  "oauth_scope": "oauth_scope",
  "target": {
    "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
    "type": "service_account",
    "service_account_name": "service_account_name"
  },
  "token_lifetime_seconds": 0,
  "type": "federation_rule",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id",
  "workspace_id": "workspace_id",
  "workspace_ids": [
    "string"
  ]
}