Claude Platform Docs

페더레이션 규칙 업데이트

$ ant beta:organization:federation:rules update
POST/v1/organizations/federation_rules/{federation_rule_id}

org:admin 범위의 OAuth 액세스 토큰이 필요합니다. 이 토큰은 ant auth login --scope org:admin 또는 워크로드 ID 페더레이션 규칙을 통해 얻을 수 있으며, Admin API 키는 허용되지 않습니다. Admin API로 WIF 관리를 참조하세요.

페더레이션 규칙을 부분적으로 업데이트합니다.

issuer_id는 변경할 수 없습니다. matchtarget은 설정 시 전체 객체로 교체됩니다. 참조된 서비스 계정과 워크스페이스는 조직에 존재해야 하며, 잘못된 참조는 400 오류로 거부됩니다. 보관된 규칙은 업데이트할 수 없으며 400을 반환합니다. 대신 새 규칙을 생성하세요. 잘 알려진 공유 발급자(GitHub Actions, GitLab, Buildkite, Terraform Cloud, Google)에 대한 규칙은 ID를 담은 클레임, 테넌트를 고정하는 subject 접두사(예: repo:YOUR_ORG/...), 또는 이러한 ID 클레임 중 하나를 참조하는 CEL 조건(예: claims.repository_owner)을 통해 테넌트 ID를 제한해야 합니다. 이러한 발급자에서는 업데이트할 때마다 이 요구 사항이 다시 확인됩니다. 기존 규칙에 저장된 match가 아직 테넌트 ID를 제한하지 않는 경우, 모든 업데이트(이름 변경이나 설명 변경 포함)는 동일한 요청에서 요건을 충족하는 match도 함께 제공해야 합니다. OAuth 호출자는 oauth_scopeworkspace:developer 또는 workspace:inference인 규칙만 관리할 수 있으며, 다른 범위는 Console 세션이 필요합니다.

Parameters
--federation-rule-id: string

Path param: ID of the federation rule to update.

--applies-to-all-workspaces: optional boolean

Body param: When true, enables this rule for every workspace in the org (including workspaces created later). Setting false is rejected with 400 if no workspace would remain enabled; a rule with only a legacy workspace_id binding continues to mint.

--attributes: optional map[string]

Body param: Replaces the CEL expressions {name: expr} extracting named values from claims. Send null to clear them. Not yet supported; any non-empty value is rejected with 400.

--description: optional string

Body param: Replaces the description. Omit to leave unchanged; send null to clear (the field is stored as an empty string).

maxLength2000
--match: optional object{ audience, claims, condition, subject_prefix }

Body param: Does the incoming JWT qualify?

All populated fields must pass; omitted fields are skipped. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

--name: optional string

Body param: Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

maxLength255
minLength1
--oauth-scope: optional string

Body param: Replaces the space-separated OAuth scopes granted on minted tokens. OAuth callers may only set workspace:developer or workspace:inference; other scopes (such as org:admin) require a Console session.

minLength1
--target: optional object{ service_account_id, type, service_account_name }

Body param: Bind to a fixed service account by ID.

--token-lifetime-seconds: optional number

Body param: Replaces the lifetime in seconds for access tokens minted via this rule (60-86400). Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

maximum86400
minimum60
--workspace-id: optional string

Body param: Replaces the existing single workspace enablement (the previous one is removed). Rejected with 400 if the rule is enabled for more than one workspace; use the /federation_rules/{federation_rule_id}/workspaces sub-resource instead.

--beta: optional array of AnthropicBeta

Header param: Optional header to specify the beta version(s) you want to use.

Returns
beta_federation_rule: object{ id, applies_to_all_workspaces, archived_at, 17 more }

Authorization rule binding an external OIDC identity to Anthropic.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

id: string

Tagged ID of the federation rule.

applies_to_all_workspaces: boolean

When true, this rule is enabled for every workspace in the org (including ones created after the rule). workspace_ids is ignored at exchange time.

archived_at: string

If set, this rule is archived and rejects token exchange.

formatdate-time
archived_by_actor_id: string

Tagged ID (user_/svac_) of the actor that archived this rule.

attributes: map[string]

CEL expressions extracting named values from claims. Not yet supported; always null.

created_at: string

When this rule was created.

formatdate-time
created_by_actor_id: string

Tagged ID (user_/svac_) of the actor that created this rule.

description: string

Optional free-text description.

issuer_id: string

Tagged ID of the issuer whose tokens this rule accepts.

issuer_name: string

Issuer's display name at read time.

match: object{ audience, claims, condition, subject_prefix }

Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.

audience: optional string

Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.

maxLength1024
claims: optional map[string]

Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.

condition: optional string

CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.

maxLength4096
subject_prefix: optional string

Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.

maxLength1024
name: string

Admin-chosen slug identifier.

oauth_scope: string

Space-separated OAuth scopes granted on the minted token.

target: object{ service_account_id, type, service_account_name }

Identity that tokens minted via this rule act as. Currently always a service_account target.

service_account_id: string

Tagged ID of the service account to mint tokens for.

type: "service_account"
service_account_name: optional string

Service account's display name at read time. Ignored on writes.

token_lifetime_seconds: number

Lifetime in seconds of access tokens minted via this rule. Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

type: "federation_rule"
updated_at: string

When this rule was last updated.

formatdate-time
updated_by_actor_id: string

Tagged ID (user_/svac_) of the actor that last updated this rule.

workspace_id: string

Legacy single-workspace binding. Prefer workspace_ids and the /federation_rules/{federation_rule_id}/workspaces sub-resource for managing workspace enablement.

workspace_ids: array of string

Tagged IDs of the workspaces this rule is enabled for. May be empty for older rules that only carry the legacy workspace_id binding. Ignored at exchange time when applies_to_all_workspaces is true (the list may still be non-empty).

페더레이션 규칙 업데이트
ant beta:organization:federation:rules update \
  --api-key my-anthropic-api-key \
  --federation-rule-id federation_rule_id
Returns Examples
Response 200
{
  "id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
  "applies_to_all_workspaces": true,
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "attributes": {
    "foo": "string"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "description": "description",
  "issuer_id": "issuer_id",
  "issuer_name": "issuer_name",
  "match": {
    "audience": "audience",
    "claims": {
      "foo": "string"
    },
    "condition": "condition",
    "subject_prefix": "subject_prefix"
  },
  "name": "prod-deploy-pipeline",
  "oauth_scope": "oauth_scope",
  "target": {
    "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
    "type": "service_account",
    "service_account_name": "service_account_name"
  },
  "token_lifetime_seconds": 0,
  "type": "federation_rule",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id",
  "workspace_id": "workspace_id",
  "workspace_ids": [
    "string"
  ]
}