Authorization rule binding an external OIDC identity to Anthropic.
Evaluates the match conditions and mints an OAuth access token for the
resolved target, scoped to a single workspace where the rule is enabled
(chosen by the caller at exchange time when the rule is enabled for more
than one). For rules enabled via workspace_ids or
applies_to_all_workspaces, the target service account must be a member
of that workspace (it is implicitly a member of the default workspace);
rules carrying only the legacy workspace_id binding do not enforce
this.