Claude Platform Docs

フェデレーション発行者を作成

POST/v1/organizations/federation_issuers

組織内のワークロードIDフェデレーションのためにAnthropicが信頼するOIDC発行者を登録します。

jwks フィールドは発行者の署名鍵の取得方法を制御し、type で選択される3つの形式のいずれかを取ります。discovery(OIDCディスカバリーを通じて鍵を解決)、explicit_url(固定のJWKS URLから鍵を取得)、または inline(静的な鍵セットを提供)です。jwks.typediscoverydiscovery_base が設定されていない場合、Anthropicがディスカバリードキュメントを取得できるように、発行者URLはHTTPS経由で公開アクセス可能である必要があります。explicit_url および inline モードでは、発行者URLはJWTの iss クレームとして照合されるだけで、取得はされません。

OAuthベアラーまたはConsoleセッションが必要です。Admin APIキーは受け付けられません。

Headers
"anthropic-beta": optional array of string

Optional header to specify the beta version(s) you want to use.

To use multiple betas, use a comma separated list like beta1,beta2 or specify the header multiple times for each beta.

Body
issuer_url: string

The iss claim value to match against.

minLength1
name: string

Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

maxLength255
minLength1
check_jti: optional boolean or null

Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Defaults to true. Applies only to assertions carrying a jti claim; tokens without one are accepted without single-use enforcement.

jwks: optional object{ type, ca_cert_pem, discovery_base } or object{ type, url, ca_cert_pem } or object{ keys, type }

How signing keys are obtained. Defaults to OIDC discovery.

One of the following:
Discovery object{ type, ca_cert_pem, discovery_base }

JWKS via the issuer's OIDC discovery document.

type: "discovery"
ca_cert_pem: optional string or null

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
discovery_base: optional string or null

Set when the discovery URL differs from issuer_url.

ExplicitURL object{ type, url, ca_cert_pem }

JWKS fetched from a fixed endpoint.

type: "explicit_url"
url: string

JWKS endpoint.

minLength1
ca_cert_pem: optional string or null

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
Inline object{ keys, type }

JWKS supplied directly; no network fetch.

keys: array of map[unknown]

Inline JWK objects.

minItems1
type: "inline"
max_jwt_lifetime_seconds: optional number or null

Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Defaults to 3600 (1h). Assertions must carry both iat and exp; a missing iat is rejected.

maximum176400
exclusiveMinimum0
Returns
FederationIssuer object{ id, archived_at, archived_by_actor_id, 12 more }

Registered external OIDC identity provider.

Records an external IdP the organization trusts for the RFC 7523 jwt-bearer grant. The issuer_url must match the JWT iss claim exactly.

フェデレーション発行者を作成
cURL
curl https://api.anthropic.com/v1/organizations/federation_issuers \
    -H 'Content-Type: application/json' \
    -H 'anthropic-version: 2023-06-01' \
    -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \
    -d '{
          "issuer_url": "x",
          "name": "x"
        }'
Returns Examples
Response 200
{
  "id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "check_jti": true,
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "issuer_url": "https://token.actions.githubusercontent.com",
  "jwks": {
    "type": "discovery",
    "ca_cert_pem": "ca_cert_pem",
    "discovery_base": "discovery_base"
  },
  "jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
  "max_jwt_lifetime_seconds": 0,
  "name": "github-actions",
  "poll_status": {
    "consecutive_failures": 0,
    "last_fetched_at": "2019-12-27T18:11:19.117Z",
    "next_poll_at": "2019-12-27T18:11:19.117Z"
  },
  "type": "federation_issuer",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id"
}