Claude Platform Docs

Aggiorna regola di federazione

$client->beta->organization->federation->rules->update(string federationRuleID, ?bool appliesToAllWorkspaces, ?array<string,string> attributes, ?string description, ?BetaFederationRuleMatch match, ?string name, ?string oauthScope, ?BetaServiceAccountTarget target, ?int tokenLifetimeSeconds, ?string workspaceID, ?list<AnthropicBeta> betas): BetaFederationRule
POST/v1/organizations/federation_rules/{federation_rule_id}

Richiede un token di accesso OAuth con lo scope org:admin, ottenuto da ant auth login --scope org:admin o da una regola di workload identity federation; le chiavi Admin API non sono accettate. Consulta Gestisci WIF con l'Admin API.

Aggiorna parzialmente una regola di federazione.

issuer_id è immutabile. match e target vengono sostituiti come oggetti interi quando impostati. Gli account di servizio e i workspace referenziati devono esistere nella tua organizzazione; i riferimenti non validi vengono rifiutati con un errore 400. Le regole archiviate non possono essere aggiornate; viene restituito 400. Crea invece una nuova regola. Le regole su emittenti condivisi noti (GitHub Actions, GitLab, Buildkite, Terraform Cloud, Google) devono vincolare l'identità del tenant tramite un claim che identifica il tenant, un prefisso del subject che fissa il tenant (come repo:YOUR_ORG/...) o una condizione CEL che fa riferimento a uno di questi claim di identità (ad es. claims.repository_owner). Su questi emittenti il requisito viene ricontrollato a ogni aggiornamento; se il match memorizzato di una regola esistente non vincola ancora l'identità del tenant, qualsiasi aggiornamento (anche una ridenominazione o una modifica della descrizione) deve fornire anche un match conforme nella stessa richiesta. I chiamanti OAuth possono gestire solo regole il cui oauth_scope è workspace:developer o workspace:inference; altri scope richiedono una sessione Console.

Parameters
federationRuleID: string

ID of the federation rule to update.

appliesToAllWorkspaces?:optional bool

When true, enables this rule for every workspace in the org (including workspaces created later). Setting false is rejected with 400 if no workspace would remain enabled; a rule with only a legacy workspace_id binding continues to mint.

attributes?:optional array<string,string>

Replaces the CEL expressions {name: expr} extracting named values from claims. Send null to clear them. Not yet supported; any non-empty value is rejected with 400.

description?:optional string

Replaces the description. Omit to leave unchanged; send null to clear (the field is stored as an empty string).

match?:optional BetaFederationRuleMatch

Does the incoming JWT qualify?

All populated fields must pass; omitted fields are skipped. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

name?:optional string

Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

oauthScope?:optional string

Replaces the space-separated OAuth scopes granted on minted tokens. OAuth callers may only set workspace:developer or workspace:inference; other scopes (such as org:admin) require a Console session.

target?:optional BetaServiceAccountTarget

Bind to a fixed service account by ID.

tokenLifetimeSeconds?:optional int

Replaces the lifetime in seconds for access tokens minted via this rule (60-86400). Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

workspaceID?:optional string

Replaces the existing single workspace enablement (the previous one is removed). Rejected with 400 if the rule is enabled for more than one workspace; use the /federation_rules/{federation_rule_id}/workspaces sub-resource instead.

betas?:optional list<AnthropicBeta>

Optional header to specify the beta version(s) you want to use.

Returns
class BetaFederationRule { $type = 'federation_rule'; $id; $appliesToAllWorkspaces; /* 17 more */ }
Aggiorna regola di federazione
<?php

require_once dirname(__DIR__) . '/vendor/autoload.php';

$client = new Client(apiKey: 'my-anthropic-api-key');

$betaFederationRule = $client->beta->organization->federation->rules->update(
  'federation_rule_id',
  appliesToAllWorkspaces: true,
  attributes: ['foo' => 'string'],
  description: 'description',
  match: [
    'audience' => 'audience',
    'claims' => ['foo' => 'string'],
    'condition' => 'condition',
    'subjectPrefix' => 'subject_prefix',
  ],
  name: 'x',
  oauthScope: 'x',
  target: [
    'serviceAccountID' => 'svac_01SDCCSbTxrXDpWc1phhtcfK',
    'type' => 'service_account',
    'serviceAccountName' => 'service_account_name',
  ],
  tokenLifetimeSeconds: 60,
  workspaceID: 'workspace_id',
  betas: [AnthropicBeta::MESSAGE_BATCHES_2024_09_24],
);

var_dump($betaFederationRule);
Returns Examples
Response 200
{
  "id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
  "applies_to_all_workspaces": true,
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "attributes": {
    "foo": "string"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "description": "description",
  "issuer_id": "issuer_id",
  "issuer_name": "issuer_name",
  "match": {
    "audience": "audience",
    "claims": {
      "foo": "string"
    },
    "condition": "condition",
    "subject_prefix": "subject_prefix"
  },
  "name": "prod-deploy-pipeline",
  "oauth_scope": "oauth_scope",
  "target": {
    "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
    "type": "service_account",
    "service_account_name": "service_account_name"
  },
  "token_lifetime_seconds": 0,
  "type": "federation_rule",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id",
  "workspace_id": "workspace_id",
  "workspace_ids": [
    "string"
  ]
}