---
title: "Create Federation Issuer"
method: POST
path: "/v1/organizations/federation_issuers?beta=true"
---

# Create Federation Issuer

`POST /v1/organizations/federation_issuers?beta=true`

**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).

Register an OIDC issuer that Anthropic will trust for workload identity
federation in your organization.

The `jwks` field controls how the issuer's signing keys are obtained and
takes one of three shapes selected by `type`: `discovery` (resolve keys
through OIDC discovery), `explicit_url` (fetch keys from a fixed JWKS
URL), or `inline` (provide a static key set). When `jwks.type` is
`discovery` and no `discovery_base` is set, the issuer URL must be
publicly reachable over HTTPS so Anthropic can fetch the discovery
document; for `explicit_url` and `inline` modes the issuer URL is only
matched as the JWT's `iss` claim and is not fetched.

## Headers

- `anthropic-beta` string — Optional header to specify the beta version(s) you want to use. To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta.
- `anthropic-version` string — The version of the Claude API you want to use. Read more about versioning and our version history [here](https://platform.claude.com/docs/en/api/versioning).

## Request body

- BetaFederationIssuerCreateParams
  - `check_jti` boolean, nullable — Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Defaults to true. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
  - `issuer_url` string, required — The `iss` claim value to match against.
  - `jwks` union — How signing keys are obtained. Defaults to OIDC discovery.
    - BetaJwksDiscovery — JWKS via the issuer's OIDC discovery document.
      - `ca_cert_pem` string, nullable — Optional custom CA (PEM) for TLS verification of the JWKS fetch.
      - `discovery_base` string, nullable — Set when the discovery URL differs from `issuer_url`.
      - `type` 'discovery', required
    - BetaJwksExplicitUrl — JWKS fetched from a fixed endpoint.
      - `ca_cert_pem` string, nullable — Optional custom CA (PEM) for TLS verification of the JWKS fetch.
      - `type` 'explicit_url', required
      - `url` string, required — JWKS endpoint.
    - BetaJwksInline — JWKS supplied directly; no network fetch.
      - `keys` object[], required — Inline JWK objects.
      - `type` 'inline', required
  - `max_jwt_lifetime_seconds` integer, nullable — Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Defaults to 3600 (1h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
  - `name` string, required — Slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

## Response `200`

Successful Response

- BetaFederationIssuer — Registered external OIDC identity provider. Records an external IdP the organization trusts for the RFC 7523 jwt-bearer grant. The `issuer_url` must match the JWT `iss` claim exactly.
  - `archived_at` string, date-time, nullable, required — If set, all rules referencing this issuer reject token exchange.
  - `archived_by_actor_id` string, nullable, required — Tagged ID (`user_`/`svac_`) of the actor that archived this issuer.
  - `check_jti` boolean, required — Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a `jti` claim; tokens without one are accepted without single-use enforcement.
  - `created_at` string, date-time, required — When this issuer was created.
  - `created_by_actor_id` string, nullable, required — Tagged ID (`user_`/`svac_`) of the actor that created this issuer.
  - `id` string, required — Tagged ID of the federation issuer.
  - `issuer_url` string, required — The `iss` claim value. Incoming JWTs must match exactly.
  - `jwks` union, required — How signing keys are obtained for signature verification.
    - BetaJwksDiscovery — JWKS via the issuer's OIDC discovery document.
      - `ca_cert_pem` string, nullable — Optional custom CA (PEM) for TLS verification of the JWKS fetch.
      - `discovery_base` string, nullable — Set when the discovery URL differs from `issuer_url`.
      - `type` 'discovery', required
    - BetaJwksExplicitUrl — JWKS fetched from a fixed endpoint.
      - `ca_cert_pem` string, nullable — Optional custom CA (PEM) for TLS verification of the JWKS fetch.
      - `type` 'explicit_url', required
      - `url` string, required — JWKS endpoint.
    - BetaJwksInline — JWKS supplied directly; no network fetch.
      - `keys` object[], required — Inline JWK objects.
      - `type` 'inline', required
  - `jwks_polling_disabled_at` string, date-time, nullable, required — If set, Anthropic's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending `jwks_polling_disabled: false` via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than `workspace:developer` or `workspace:inference`; use a Console session.
  - `max_jwt_lifetime_seconds` integer, required — Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both `iat` and `exp`; a missing `iat` is rejected.
  - `name` string, required — Admin-chosen slug identifier.
  - `poll_status` BetaIssuerPollStatus, required — Status of automatic JWKS polling for a federation issuer. Anthropic periodically fetches the issuer's signing keys in the background. These fields summarize the most recent fetches so the health of the JWKS endpoint can be monitored.
    - `consecutive_failures` integer, required — Consecutive fetch failures since the last success.
    - `last_fetched_at` string, date-time, nullable, required — When the last successful fetch completed.
    - `next_poll_at` string, date-time, nullable, required — When the next fetch is scheduled. Null if paused.
  - `type` 'federation_issuer', required
  - `updated_at` string, date-time, required — When this issuer was last updated.
  - `updated_by_actor_id` string, nullable, required — Tagged ID (`user_`/`svac_`) of the actor that last updated this issuer.

## Other responses

- `400` — Invalid argument - The client specified an invalid argument
- `401` — Unauthenticated - The request does not have valid authentication credentials
- `403` — Permission denied - The caller does not have permission to execute the specified operation
- `404` — Not found - Some requested entity was not found
- `408` — Deadline exceeded - The deadline expired before the operation could complete
- `409` — Aborted - The operation was aborted due to concurrency issue
- `412` — Failed precondition - Operation was rejected because the system is not in required state
- `413` — Out of range - Operation was attempted past the valid range
- `429` — Resource exhausted - Some resource has been exhausted (rate limiting)
- `431` — Request header fields too large - Request metadata was too large
- `499` — Cancelled - The operation was cancelled by the client
- `500` — Internal - Internal server error
- `501` — Unimplemented - The operation is not implemented or supported
- `503` — Unavailable - The service is currently unavailable
- `504` — Deadline exceeded - Upstream service did not respond in time
- `529` — Overloaded - The service is temporarily overloaded

## Changes

- **2026-09-02** `4789294140a2` — 16 info
  - added the non-success response with the status `400`
  - added the non-success response with the status `401`
  - added the non-success response with the status `403`
  - added the non-success response with the status `404`
  - …12 more
- **2026-08-26** `942a11636c42` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/anthropics/apis/anthropic-api/changes/v1/organizations/federation_issuers?beta=true/post.md)

---

[API](https://skmtc.dev/anthropics/apis/anthropic-api.md) · [All operations](https://skmtc.dev/anthropics/apis/anthropic-api/llms.txt) · [OpenAPI document](https://skmtc.dev/anthropics/apis/anthropic-api/revisions/1bb7c7a0a4a9?raw)
