Claude Platform Docs

규칙

페더레이션 규칙 생성
BetaFederationRule Beta.Organization.Federation.Rules.Create(parameters, cancellationToken = default)
POST/v1/organizations/federation_rules

org:admin 범위의 OAuth 액세스 토큰이 필요합니다. 이 토큰은 ant auth login --scope org:admin 또는 워크로드 ID 페더레이션 규칙을 통해 얻을 수 있으며, Admin API 키는 허용되지 않습니다. Admin API로 WIF 관리를 참조하세요.

페더레이션 규칙 목록 조회
RuleListPage Beta.Organization.Federation.Rules.List(parameters, cancellationToken = default)
GET/v1/organizations/federation_rules

org:admin 범위의 OAuth 액세스 토큰이 필요합니다. 이 토큰은 ant auth login --scope org:admin 또는 워크로드 ID 페더레이션 규칙을 통해 얻을 수 있으며, Admin API 키는 허용되지 않습니다. Admin API로 WIF 관리를 참조하세요.

페더레이션 규칙 조회
BetaFederationRule Beta.Organization.Federation.Rules.Retrieve(parameters, cancellationToken = default)
GET/v1/organizations/federation_rules/{federation_rule_id}

org:admin 범위의 OAuth 액세스 토큰이 필요합니다. 이 토큰은 ant auth login --scope org:admin 또는 워크로드 ID 페더레이션 규칙을 통해 얻을 수 있으며, Admin API 키는 허용되지 않습니다. Admin API로 WIF 관리를 참조하세요.

페더레이션 규칙 업데이트
BetaFederationRule Beta.Organization.Federation.Rules.Update(parameters, cancellationToken = default)
POST/v1/organizations/federation_rules/{federation_rule_id}

org:admin 범위의 OAuth 액세스 토큰이 필요합니다. 이 토큰은 ant auth login --scope org:admin 또는 워크로드 ID 페더레이션 규칙을 통해 얻을 수 있으며, Admin API 키는 허용되지 않습니다. Admin API로 WIF 관리를 참조하세요.

페더레이션 규칙 보관
BetaFederationRule Beta.Organization.Federation.Rules.Archive(parameters, cancellationToken = default)
POST/v1/organizations/federation_rules/{federation_rule_id}/archive

org:admin 범위의 OAuth 액세스 토큰이 필요합니다. 이 토큰은 ant auth login --scope org:admin 또는 워크로드 ID 페더레이션 규칙을 통해 얻을 수 있으며, Admin API 키는 허용되지 않습니다. Admin API로 WIF 관리를 참조하세요.

Models
class BetaFederationRule { Type = "federation_rule"; ID; AppliesToAllWorkspaces; /* 17 more */ }

Authorization rule binding an external OIDC identity to Anthropic.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

class BetaFederationRuleMatch { Audience; Claims; Condition; SubjectPrefix; }

Does the incoming JWT qualify?

All populated fields must pass; omitted fields are skipped. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

string? Audience

Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.

maxLength1024
IReadOnlyDictionary<string, string>? Claims

Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.

string? Condition

CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.

maxLength4096
string? SubjectPrefix

Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.

maxLength1024
class BetaFederationRuleWorkspace { Type = "federation_rule_workspace"; CreatedAt; CreatedByActorID; /* 3 more */ }
JsonElement Type = "federation_rule_workspace"
required DateTimeOffset CreatedAt

When this workspace was enabled for the rule.

formatdate-time
required string? CreatedByActorID

Tagged ID (user_... or svac_...) of the actor that enabled this workspace for the rule, if known.

required string FederationRuleID

Tagged ID of the federation rule.

required string WorkspaceID

Tagged ID of the workspace this rule is enabled for.

required string? WorkspaceName

Workspace display name. Populated when listing; null in the enable response.

class BetaServiceAccountTarget { Type = "service_account"; ServiceAccountID; ServiceAccountName; }

Bind to a fixed service account by ID.

JsonElement Type = "service_account"
required string ServiceAccountID

Tagged ID of the service account to mint tokens for.

string? ServiceAccountName

Service account's display name at read time. Ignored on writes.

페더레이션 규칙 워크스페이스 추가
BetaFederationRuleWorkspace Beta.Organization.Federation.Rules.Workspaces.Add(parameters, cancellationToken = default)
POST/v1/organizations/federation_rules/{federation_rule_id}/workspaces

org:admin 범위의 OAuth 액세스 토큰이 필요합니다. 이 토큰은 ant auth login --scope org:admin 또는 워크로드 ID 페더레이션 규칙을 통해 얻을 수 있으며, Admin API 키는 허용되지 않습니다. Admin API로 WIF 관리를 참조하세요.

페더레이션 규칙 워크스페이스 목록 조회
WorkspaceListPage Beta.Organization.Federation.Rules.Workspaces.List(parameters, cancellationToken = default)
GET/v1/organizations/federation_rules/{federation_rule_id}/workspaces

org:admin 범위의 OAuth 액세스 토큰이 필요합니다. 이 토큰은 ant auth login --scope org:admin 또는 워크로드 ID 페더레이션 규칙을 통해 얻을 수 있으며, Admin API 키는 허용되지 않습니다. Admin API로 WIF 관리를 참조하세요.

페더레이션 규칙 워크스페이스 제거
WorkspaceRemoveResponse Beta.Organization.Federation.Rules.Workspaces.Remove(parameters, cancellationToken = default)
DELETE/v1/organizations/federation_rules/{federation_rule_id}/workspaces/{workspace_id}

org:admin 범위의 OAuth 액세스 토큰이 필요합니다. 이 토큰은 ant auth login --scope org:admin 또는 워크로드 ID 페더레이션 규칙을 통해 얻을 수 있으며, Admin API 키는 허용되지 않습니다. Admin API로 WIF 관리를 참조하세요.