Claude Platform Docs

Crea issuer di federazione

$client->beta->organization->federation->issuers->create(string issuerURL, string name, ?bool checkJTI, ?JWKS jwks, ?int maxJWTLifetimeSeconds, ?list<AnthropicBeta> betas): BetaFederationIssuer
POST/v1/organizations/federation_issuers

Richiede un token di accesso OAuth con lo scope org:admin, ottenuto da ant auth login --scope org:admin o da una regola di workload identity federation; le chiavi Admin API non sono accettate. Consulta Gestisci WIF con l'Admin API.

Registra un issuer (emittente) OIDC che Anthropic considererà attendibile per la workload identity federation (federazione delle identità dei workload) nella tua organizzazione.

Il campo jwks controlla come vengono ottenute le chiavi di firma dell'emittente e assume una di tre forme selezionate da type: discovery (risolve le chiavi tramite OIDC discovery), explicit_url (recupera le chiavi da un URL JWKS fisso) o inline (fornisce un set di chiavi statico). Quando jwks.type è discovery e non è impostato alcun discovery_base, l'URL dell'emittente deve essere raggiungibile pubblicamente tramite HTTPS affinché Anthropic possa recuperare il documento di discovery; per le modalità explicit_url e inline l'URL dell'emittente viene solo confrontato con il claim iss del JWT e non viene recuperato.

Parameters
issuerURL: string

The iss claim value to match against.

name: string

Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

checkJTI?:optional bool

Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Defaults to true. Applies only to assertions carrying a jti claim; tokens without one are accepted without single-use enforcement.

jwks?:optional JWKS

How signing keys are obtained. Defaults to OIDC discovery.

maxJWTLifetimeSeconds?:optional int

Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Defaults to 3600 (1h). Assertions must carry both iat and exp; a missing iat is rejected.

betas?:optional list<AnthropicBeta>

Optional header to specify the beta version(s) you want to use.

Returns
class BetaFederationIssuer { $type = 'federation_issuer'; $id; $archivedAt; /* 12 more */ }
Crea issuer di federazione
<?php

require_once dirname(__DIR__) . '/vendor/autoload.php';

$client = new Client(apiKey: 'my-anthropic-api-key');

$betaFederationIssuer = $client
  ->beta
  ->organization
  ->federation
  ->issuers
  ->create(
  issuerURL: 'x',
  name: 'x',
  checkJTI: true,
  jwks: [
    'type' => 'discovery',
    'caCertPEM' => 'ca_cert_pem',
    'discoveryBase' => 'discovery_base',
  ],
  maxJWTLifetimeSeconds: 1,
  betas: [AnthropicBeta::MESSAGE_BATCHES_2024_09_24],
);

var_dump($betaFederationIssuer);
Returns Examples
Response 200
{
  "id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "check_jti": true,
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "issuer_url": "https://token.actions.githubusercontent.com",
  "jwks": {
    "type": "discovery",
    "ca_cert_pem": "ca_cert_pem",
    "discovery_base": "discovery_base"
  },
  "jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
  "max_jwt_lifetime_seconds": 0,
  "name": "github-actions",
  "poll_status": {
    "consecutive_failures": 0,
    "last_fetched_at": "2019-12-27T18:11:19.117Z",
    "next_poll_at": "2019-12-27T18:11:19.117Z"
  },
  "type": "federation_issuer",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id"
}