Claude Platform Docs

フェデレーションルールを更新

$client->beta->organization->federation->rules->update(string federationRuleID, ?bool appliesToAllWorkspaces, ?array<string,string> attributes, ?string description, ?BetaFederationRuleMatch match, ?string name, ?string oauthScope, ?BetaServiceAccountTarget target, ?int tokenLifetimeSeconds, ?string workspaceID, ?list<AnthropicBeta> betas): BetaFederationRule
POST/v1/organizations/federation_rules/{federation_rule_id}

org:admin スコープを持つ OAuth アクセストークンが必要です。これは ant auth login --scope org:admin またはワークロード ID フェデレーションルールから取得します。Admin APIキーは受け付けられません。Admin API で WIF を管理するを参照してください。

フェデレーションルールを部分的に更新します。

issuer_id は不変です。matchtarget は、設定されるとオブジェクト全体として置き換えられます。参照されるサービスアカウントとワークスペースは組織内に存在している必要があります。無効な参照は 400 エラーで拒否されます。アーカイブ済みのルールは更新できず、400 が返されます。代わりに新しいルールを作成してください。よく知られた共有発行者(GitHub Actions、GitLab、Buildkite、Terraform Cloud、Google)上のルールは、ID を含むクレーム、テナントを固定するサブジェクトプレフィックス(repo:YOUR_ORG/... など)、またはそれらの ID クレームのいずれかを参照する CEL 条件(例: claims.repository_owner)によってテナント ID を制約する必要があります。これらの発行者では、この要件は更新のたびに再チェックされます。既存のルールに保存されている match がまだテナント ID を制約していない場合、どのような更新(名前の変更や説明の変更であっても)でも、同じリクエスト内で要件に適合する match を併せて指定する必要があります。OAuth 呼び出し元が管理できるのは、oauth_scopeworkspace:developer または workspace:inference のルールのみです。その他のスコープには Console セッションが必要です。

Parameters
federationRuleID: string

ID of the federation rule to update.

appliesToAllWorkspaces?:optional bool

When true, enables this rule for every workspace in the org (including workspaces created later). Setting false is rejected with 400 if no workspace would remain enabled; a rule with only a legacy workspace_id binding continues to mint.

attributes?:optional array<string,string>

Replaces the CEL expressions {name: expr} extracting named values from claims. Send null to clear them. Not yet supported; any non-empty value is rejected with 400.

description?:optional string

Replaces the description. Omit to leave unchanged; send null to clear (the field is stored as an empty string).

match?:optional BetaFederationRuleMatch

Does the incoming JWT qualify?

All populated fields must pass; omitted fields are skipped. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

name?:optional string

Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

oauthScope?:optional string

Replaces the space-separated OAuth scopes granted on minted tokens. OAuth callers may only set workspace:developer or workspace:inference; other scopes (such as org:admin) require a Console session.

target?:optional BetaServiceAccountTarget

Bind to a fixed service account by ID.

tokenLifetimeSeconds?:optional int

Replaces the lifetime in seconds for access tokens minted via this rule (60-86400). Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

workspaceID?:optional string

Replaces the existing single workspace enablement (the previous one is removed). Rejected with 400 if the rule is enabled for more than one workspace; use the /federation_rules/{federation_rule_id}/workspaces sub-resource instead.

betas?:optional list<AnthropicBeta>

Optional header to specify the beta version(s) you want to use.

Returns
class BetaFederationRule { $type = 'federation_rule'; $id; $appliesToAllWorkspaces; /* 17 more */ }
フェデレーションルールを更新
<?php

require_once dirname(__DIR__) . '/vendor/autoload.php';

$client = new Client(apiKey: 'my-anthropic-api-key');

$betaFederationRule = $client->beta->organization->federation->rules->update(
  'federation_rule_id',
  appliesToAllWorkspaces: true,
  attributes: ['foo' => 'string'],
  description: 'description',
  match: [
    'audience' => 'audience',
    'claims' => ['foo' => 'string'],
    'condition' => 'condition',
    'subjectPrefix' => 'subject_prefix',
  ],
  name: 'x',
  oauthScope: 'x',
  target: [
    'serviceAccountID' => 'svac_01SDCCSbTxrXDpWc1phhtcfK',
    'type' => 'service_account',
    'serviceAccountName' => 'service_account_name',
  ],
  tokenLifetimeSeconds: 60,
  workspaceID: 'workspace_id',
  betas: [AnthropicBeta::MESSAGE_BATCHES_2024_09_24],
);

var_dump($betaFederationRule);
Returns Examples
Response 200
{
  "id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
  "applies_to_all_workspaces": true,
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "attributes": {
    "foo": "string"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "description": "description",
  "issuer_id": "issuer_id",
  "issuer_name": "issuer_name",
  "match": {
    "audience": "audience",
    "claims": {
      "foo": "string"
    },
    "condition": "condition",
    "subject_prefix": "subject_prefix"
  },
  "name": "prod-deploy-pipeline",
  "oauth_scope": "oauth_scope",
  "target": {
    "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
    "type": "service_account",
    "service_account_name": "service_account_name"
  },
  "token_lifetime_seconds": 0,
  "type": "federation_rule",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id",
  "workspace_id": "workspace_id",
  "workspace_ids": [
    "string"
  ]
}