Claude Platform Docs

페더레이션 발급자 생성

$client->beta->organization->federation->issuers->create(string issuerURL, string name, ?bool checkJTI, ?JWKS jwks, ?int maxJWTLifetimeSeconds, ?list<AnthropicBeta> betas): BetaFederationIssuer
POST/v1/organizations/federation_issuers

org:admin 범위의 OAuth 액세스 토큰이 필요합니다. 이 토큰은 ant auth login --scope org:admin 또는 워크로드 ID 페더레이션 규칙을 통해 얻을 수 있으며, Admin API 키는 허용되지 않습니다. Admin API로 WIF 관리를 참조하세요.

조직에서 워크로드 ID 페더레이션을 위해 Anthropic이 신뢰할 OIDC 발급자를 등록합니다.

jwks 필드는 발급자의 서명 키를 얻는 방법을 제어하며 type으로 선택되는 세 가지 형태 중 하나를 취합니다. discovery(OIDC 디스커버리를 통해 키 확인), explicit_url(고정된 JWKS URL에서 키 가져오기), inline(정적 키 세트 제공)입니다. jwks.typediscovery이고 discovery_base가 설정되지 않은 경우, Anthropic이 디스커버리 문서를 가져올 수 있도록 발급자 URL은 HTTPS를 통해 공개적으로 접근 가능해야 합니다. explicit_urlinline 모드에서는 발급자 URL이 JWT의 iss 클레임과 일치하는지만 확인하며 가져오지 않습니다.

Parameters
issuerURL: string

The iss claim value to match against.

name: string

Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

checkJTI?:optional bool

Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Defaults to true. Applies only to assertions carrying a jti claim; tokens without one are accepted without single-use enforcement.

jwks?:optional JWKS

How signing keys are obtained. Defaults to OIDC discovery.

maxJWTLifetimeSeconds?:optional int

Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Defaults to 3600 (1h). Assertions must carry both iat and exp; a missing iat is rejected.

betas?:optional list<AnthropicBeta>

Optional header to specify the beta version(s) you want to use.

Returns
class BetaFederationIssuer { $type = 'federation_issuer'; $id; $archivedAt; /* 12 more */ }
페더레이션 발급자 생성
<?php

require_once dirname(__DIR__) . '/vendor/autoload.php';

$client = new Client(apiKey: 'my-anthropic-api-key');

$betaFederationIssuer = $client
  ->beta
  ->organization
  ->federation
  ->issuers
  ->create(
  issuerURL: 'x',
  name: 'x',
  checkJTI: true,
  jwks: [
    'type' => 'discovery',
    'caCertPEM' => 'ca_cert_pem',
    'discoveryBase' => 'discovery_base',
  ],
  maxJWTLifetimeSeconds: 1,
  betas: [AnthropicBeta::MESSAGE_BATCHES_2024_09_24],
);

var_dump($betaFederationIssuer);
Returns Examples
Response 200
{
  "id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "check_jti": true,
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "issuer_url": "https://token.actions.githubusercontent.com",
  "jwks": {
    "type": "discovery",
    "ca_cert_pem": "ca_cert_pem",
    "discovery_base": "discovery_base"
  },
  "jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
  "max_jwt_lifetime_seconds": 0,
  "name": "github-actions",
  "poll_status": {
    "consecutive_failures": 0,
    "last_fetched_at": "2019-12-27T18:11:19.117Z",
    "next_poll_at": "2019-12-27T18:11:19.117Z"
  },
  "type": "federation_issuer",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id"
}