Claude Platform Docs

Issuers

Create Federation Issuer
$ ant beta:organization:federation:issuers create
POST/v1/organizations/federation_issuers

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

List Federation Issuers
$ ant beta:organization:federation:issuers list
GET/v1/organizations/federation_issuers

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Get Federation Issuer
$ ant beta:organization:federation:issuers retrieve
GET/v1/organizations/federation_issuers/{federation_issuer_id}

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Update Federation Issuer
$ ant beta:organization:federation:issuers update
POST/v1/organizations/federation_issuers/{federation_issuer_id}

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Archive Federation Issuer
$ ant beta:organization:federation:issuers archive
POST/v1/organizations/federation_issuers/{federation_issuer_id}/archive

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Models
beta_federation_issuer: object{ type: "federation_issuer", id, archived_at, 12 more }

Registered external OIDC identity provider.

Records an external IdP the organization trusts for the RFC 7523 jwt-bearer grant. The issuer_url must match the JWT iss claim exactly.

beta_federation_issuer_poll_status: object{ consecutive_failures, last_fetched_at, next_poll_at }

Status of automatic JWKS polling for a federation issuer.

Anthropic periodically fetches the issuer's signing keys in the background. These fields summarize the most recent fetches so the health of the JWKS endpoint can be monitored.

consecutive_failures: number

Consecutive fetch failures since the last success.

last_fetched_at: string

When the last successful fetch completed.

formatdate-time
next_poll_at: string

When the next fetch is scheduled. Null if paused.

formatdate-time
beta_jwks_discovery: object{ type: "discovery", ca_cert_pem, discovery_base }

JWKS via the issuer's OIDC discovery document.

type: "discovery"
ca_cert_pem: optional string

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
discovery_base: optional string

Set when the discovery URL differs from issuer_url.

beta_jwks_explicit_url: object{ type: "explicit_url", url, ca_cert_pem }

JWKS fetched from a fixed endpoint.

type: "explicit_url"
url: string

JWKS endpoint.

minLength1
ca_cert_pem: optional string

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength8192
beta_jwks_inline: object{ type: "inline", keys }

JWKS supplied directly; no network fetch.

type: "inline"
keys: array of map[unknown]

Inline JWK objects.

minItems1