建立聯合規則
POST/v1/organizations/federation_rules
需要具有 org:admin 範圍的 OAuth 存取權杖,可透過 ant auth login --scope org:admin 或工作負載身分聯合規則取得;不接受 Admin API 金鑰。請參閱使用 Admin API 管理 WIF。
建立由您的組織擁有的聯合規則。
所參照的簽發者與目標服務帳戶必須已存在於同一組織中;
無效的參照會以 400 錯誤拒絕。工作區參照會經過驗證。建立規則時
不會檢查成員資格:權杖交換每次呼叫會解析單一已啟用的工作區,
且除非目標服務帳戶是該工作區的成員(它隱含為預設工作區的成員),
否則會遭拒絕。針對知名共用簽發者(GitHub Actions、GitLab、Buildkite、
Terraform Cloud、Google)的規則必須透過帶有身分的宣告、
固定租用戶的主體前綴(例如 repo:YOUR_ORG/...),或參照其中一個
身分宣告的 CEL 條件(例如 claims.repository_owner)來限制租用戶身分。
OAuth 呼叫者只能管理 oauth_scope 為 workspace:developer 或
workspace:inference 的規則;其他範圍需要 Console 工作階段。
Parameters
Returns
建立聯合規則
<?php
require_once dirname(__DIR__) . '/vendor/autoload.php';
$client = new Client(apiKey: 'my-anthropic-api-key');
$betaFederationRule = $client->beta->organization->federation->rules->create(
issuerID: 'issuer_id',
match: [
'audience' => 'audience',
'claims' => ['foo' => 'string'],
'condition' => 'condition',
'subjectPrefix' => 'subject_prefix',
],
name: 'x',
oauthScope: 'x',
target: [
'serviceAccountID' => 'svac_01SDCCSbTxrXDpWc1phhtcfK',
'type' => 'service_account',
'serviceAccountName' => 'service_account_name',
],
appliesToAllWorkspaces: true,
attributes: ['foo' => 'string'],
description: 'description',
tokenLifetimeSeconds: 60,
workspaceID: 'workspace_id',
betas: [AnthropicBeta::MESSAGE_BATCHES_2024_09_24],
);
var_dump($betaFederationRule);Response 200
{
"id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
"applies_to_all_workspaces": true,
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"attributes": {
"foo": "string"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"issuer_id": "issuer_id",
"issuer_name": "issuer_name",
"match": {
"audience": "audience",
"claims": {
"foo": "string"
},
"condition": "condition",
"subject_prefix": "subject_prefix"
},
"name": "prod-deploy-pipeline",
"oauth_scope": "oauth_scope",
"target": {
"service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"type": "service_account",
"service_account_name": "service_account_name"
},
"token_lifetime_seconds": 0,
"type": "federation_rule",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id",
"workspace_id": "workspace_id",
"workspace_ids": [
"string"
]
}Returns Examples
Response 200
{
"id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
"applies_to_all_workspaces": true,
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"attributes": {
"foo": "string"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"issuer_id": "issuer_id",
"issuer_name": "issuer_name",
"match": {
"audience": "audience",
"claims": {
"foo": "string"
},
"condition": "condition",
"subject_prefix": "subject_prefix"
},
"name": "prod-deploy-pipeline",
"oauth_scope": "oauth_scope",
"target": {
"service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"type": "service_account",
"service_account_name": "service_account_name"
},
"token_lifetime_seconds": 0,
"type": "federation_rule",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id",
"workspace_id": "workspace_id",
"workspace_ids": [
"string"
]
}