Claude Platform Docs

フェデレーションルールを作成

POST/v1/organizations/federation_rules

組織が所有するフェデレーションルールを作成します。

参照される発行者とターゲットのサービスアカウントは、同じ組織内にすでに存在している必要があります。無効な参照は400エラーで拒否されます。ワークスペースの参照は検証されます。メンバーシップはルール作成時にはチェックされません。トークン交換は呼び出しごとに単一の有効なワークスペースを解決し、ターゲットのサービスアカウントがそのワークスペースのメンバーでない限り拒否されます(デフォルトワークスペースには暗黙的にメンバーとして所属しています)。よく知られた共有発行者(GitHub Actions、GitLab、Buildkite、Terraform Cloud、Google)に対するルールは、IDを含むクレーム、テナントを固定するサブジェクトプレフィックス(repo:YOUR_ORG/... など)、またはそれらのIDクレームのいずれかを参照するCEL条件(例: claims.repository_owner)によってテナントIDを制約する必要があります。OAuth呼び出し元が管理できるのは、oauth_scopeworkspace:developer または workspace:inference のルールのみです。その他のスコープにはConsoleセッションが必要です。Admin APIキーは受け付けられません。

Headers
"anthropic-beta": optional array of string

Optional header to specify the beta version(s) you want to use.

To use multiple betas, use a comma separated list like beta1,beta2 or specify the header multiple times for each beta.

Body
issuer_id: string

Tagged ID of the federation issuer.

match: object{ audience, claims, condition, subject_prefix }

Conditions the verified JWT must satisfy for this rule to apply. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

audience: optional string or null

Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.

maxLength1024
claims: optional map[string] or null

Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.

condition: optional string or null

CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.

maxLength4096
subject_prefix: optional string or null

Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.

maxLength1024
name: string

Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

maxLength255
minLength1
oauth_scope: string

Space-separated OAuth scopes. OAuth callers may only set workspace:developer or workspace:inference; other scopes (such as org:admin) require a Console session.

minLength1
target: object{ service_account_id, type, service_account_name }

Identity that tokens minted via this rule act as. Currently always a service_account target.

service_account_id: string

Tagged ID of the service account to mint tokens for.

type: "service_account"
service_account_name: optional string or null

Service account's display name at read time. Ignored on writes.

applies_to_all_workspaces: optional boolean

When true, enable this rule for every workspace in the org (including workspaces created later).

attributes: optional map[string] or null

CEL expressions {name: expr} extracting named values from claims. Not yet supported; any non-empty value is rejected with 400.

description: optional string or null

Optional free-text description.

maxLength2000
token_lifetime_seconds: optional number

Lifetime in seconds for access tokens minted via this rule (60-86400). Defaults to 3600 (1h). Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

maximum86400
minimum60
workspace_id: optional string or null

Tagged ID of the workspace to enable this rule for. Required unless applies_to_all_workspaces is true. Additional workspaces can be added via the /federation_rules/{federation_rule_id}/workspaces sub-resource.

Returns
FederationRule object{ id, applies_to_all_workspaces, archived_at, 17 more }

Authorization rule binding an external OIDC identity to Anthropic.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

フェデレーションルールを作成
cURL
curl https://api.anthropic.com/v1/organizations/federation_rules \
    -H 'Content-Type: application/json' \
    -H 'anthropic-version: 2023-06-01' \
    -H "Authorization: Bearer $ANTHROPIC_OAUTH_TOKEN" \
    -d '{
          "issuer_id": "issuer_id",
          "match": {},
          "name": "x",
          "oauth_scope": "x",
          "target": {
            "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
            "type": "service_account"
          }
        }'
Returns Examples
Response 200
{
  "id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
  "applies_to_all_workspaces": true,
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "attributes": {
    "foo": "string"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "description": "description",
  "issuer_id": "issuer_id",
  "issuer_name": "issuer_name",
  "match": {
    "audience": "audience",
    "claims": {
      "foo": "string"
    },
    "condition": "condition",
    "subject_prefix": "subject_prefix"
  },
  "name": "prod-deploy-pipeline",
  "oauth_scope": "oauth_scope",
  "target": {
    "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
    "type": "service_account",
    "service_account_name": "service_account_name"
  },
  "token_lifetime_seconds": 0,
  "type": "federation_rule",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id",
  "workspace_id": "workspace_id",
  "workspace_ids": [
    "string"
  ]
}