Claude Platform Docs

페더레이션 규칙 업데이트

POST/v1/organizations/federation_rules/{federation_rule_id}

org:admin 범위의 OAuth 액세스 토큰이 필요합니다. 이 토큰은 ant auth login --scope org:admin 또는 워크로드 ID 페더레이션 규칙을 통해 얻을 수 있으며, Admin API 키는 허용되지 않습니다. Admin API로 WIF 관리를 참조하세요.

페더레이션 규칙을 부분적으로 업데이트합니다.

issuer_id는 변경할 수 없습니다. matchtarget은 설정 시 전체 객체로 교체됩니다. 참조된 서비스 계정과 워크스페이스는 조직에 존재해야 하며, 잘못된 참조는 400 오류로 거부됩니다. 보관된 규칙은 업데이트할 수 없으며 400을 반환합니다. 대신 새 규칙을 생성하세요. 잘 알려진 공유 발급자(GitHub Actions, GitLab, Buildkite, Terraform Cloud, Google)에 대한 규칙은 ID를 담은 클레임, 테넌트를 고정하는 subject 접두사(예: repo:YOUR_ORG/...), 또는 이러한 ID 클레임 중 하나를 참조하는 CEL 조건(예: claims.repository_owner)을 통해 테넌트 ID를 제한해야 합니다. 이러한 발급자에서는 업데이트할 때마다 이 요구 사항이 다시 확인됩니다. 기존 규칙에 저장된 match가 아직 테넌트 ID를 제한하지 않는 경우, 모든 업데이트(이름 변경이나 설명 변경 포함)는 동일한 요청에서 요건을 충족하는 match도 함께 제공해야 합니다. OAuth 호출자는 oauth_scopeworkspace:developer 또는 workspace:inference인 규칙만 관리할 수 있으며, 다른 범위는 Console 세션이 필요합니다.

Path parameters
federation_rule_id: string

ID of the federation rule to update.

Headers
"anthropic-beta": optional array of string

Optional header to specify the beta version(s) you want to use.

To use multiple betas, use a comma separated list like beta1,beta2 or specify the header multiple times for each beta.

Body
applies_to_all_workspaces: optional boolean or null

When true, enables this rule for every workspace in the org (including workspaces created later). Setting false is rejected with 400 if no workspace would remain enabled; a rule with only a legacy workspace_id binding continues to mint.

attributes: optional map[string] or null

Replaces the CEL expressions {name: expr} extracting named values from claims. Send null to clear them. Not yet supported; any non-empty value is rejected with 400.

description: optional string or null

Replaces the description. Omit to leave unchanged; send null to clear (the field is stored as an empty string).

maxLength2000
match: optional object{ audience, claims, condition, subject_prefix } or null

Does the incoming JWT qualify?

All populated fields must pass; omitted fields are skipped. At least one of subject_prefix (other than a wildcard-only value like *), claims, or condition is required; audience alone is not sufficient.

audience: optional string or null

Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.

maxLength1024
claims: optional map[string] or null

Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.

condition: optional string or null

CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.

maxLength4096
subject_prefix: optional string or null

Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.

maxLength1024
name: optional string or null

Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

maxLength255
minLength1
oauth_scope: optional string or null

Replaces the space-separated OAuth scopes granted on minted tokens. OAuth callers may only set workspace:developer or workspace:inference; other scopes (such as org:admin) require a Console session.

minLength1
target: optional object{ service_account_id, type, service_account_name } or null

Bind to a fixed service account by ID.

service_account_id: string

Tagged ID of the service account to mint tokens for.

type: "service_account"
service_account_name: optional string or null

Service account's display name at read time. Ignored on writes.

token_lifetime_seconds: optional number or null

Replaces the lifetime in seconds for access tokens minted via this rule (60-86400). Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

maximum86400
minimum60
workspace_id: optional string or null

Replaces the existing single workspace enablement (the previous one is removed). Rejected with 400 if the rule is enabled for more than one workspace; use the /federation_rules/{federation_rule_id}/workspaces sub-resource instead.

Returns
FederationRule object{ id, applies_to_all_workspaces, archived_at, 17 more }

Authorization rule binding an external OIDC identity to Anthropic.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

페더레이션 규칙 업데이트
cURL
curl https://api.anthropic.com/v1/organizations/federation_rules/$FEDERATION_RULE_ID \
    -H 'Content-Type: application/json' \
    -H 'anthropic-version: 2023-06-01' \
    -H "Authorization: Bearer $ANTHROPIC_AUTH_TOKEN" \
    -d '{}'
Returns Examples
Response 200
{
  "id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
  "applies_to_all_workspaces": true,
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "attributes": {
    "foo": "string"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "description": "description",
  "issuer_id": "issuer_id",
  "issuer_name": "issuer_name",
  "match": {
    "audience": "audience",
    "claims": {
      "foo": "string"
    },
    "condition": "condition",
    "subject_prefix": "subject_prefix"
  },
  "name": "prod-deploy-pipeline",
  "oauth_scope": "oauth_scope",
  "target": {
    "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
    "type": "service_account",
    "service_account_name": "service_account_name"
  },
  "token_lifetime_seconds": 0,
  "type": "federation_rule",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id",
  "workspace_id": "workspace_id",
  "workspace_ids": [
    "string"
  ]
}