---
title: "List Federation Rules"
method: GET
path: "/v1/organizations/federation_rules?beta=true"
---

# List Federation Rules

`GET /v1/organizations/federation_rules?beta=true`

**Requires an OAuth access token with the `org:admin` scope**, from `ant auth login --scope org:admin` or a workload identity federation rule; Admin API keys are not accepted. See [Manage WIF with the Admin API](/docs/en/manage-claude/wif-admin-api).

List federation rules in your organization.

Optionally filter by issuer with `issuer_id`. Archived rules are excluded
unless `include_archived=true`.

## Query parameters

- `limit` integer — Number of results per page.
- `page` string, nullable — Opaque cursor from a previous response's `next_page`.
- `issuer_id` string, nullable — Filter to rules referencing this federation issuer.
- `include_archived` boolean — Include archived resources. Defaults to false.

## Headers

- `anthropic-beta` string — Optional header to specify the beta version(s) you want to use. To use multiple betas, use a comma separated list like `beta1,beta2` or specify the header multiple times for each beta.
- `x-api-key` string — Your unique Admin API key for authentication. This key is required in the header of all Admin API requests, to authenticate your account and access Anthropic's services. Get your Admin API key through the [Console](https://console.anthropic.com/settings/admin-keys).
- `anthropic-version` string — The version of the Claude API you want to use. Read more about versioning and our version history [here](https://platform.claude.com/docs/en/api/versioning).

## Response `200`

Successful Response

- BetaFederationRuleListResponse
  - `data` BetaFederationRule[], required
    - `applies_to_all_workspaces` boolean, required — When true, this rule is enabled for every workspace in the org (including ones created after the rule). `workspace_ids` is ignored at exchange time.
    - `archived_at` string, date-time, nullable, required — If set, this rule is archived and rejects token exchange.
    - `archived_by_actor_id` string, nullable, required — Tagged ID (`user_`/`svac_`) of the actor that archived this rule.
    - `attributes` object, nullable, required — CEL expressions extracting named values from claims. Not yet supported; always null.
    - `created_at` string, date-time, required — When this rule was created.
    - `created_by_actor_id` string, nullable, required — Tagged ID (`user_`/`svac_`) of the actor that created this rule.
    - `description` string, nullable, required — Optional free-text description.
    - `id` string, required — Tagged ID of the federation rule.
    - `issuer_id` string, required — Tagged ID of the issuer whose tokens this rule accepts.
    - `issuer_name` string, nullable, required — Issuer's display name at read time.
    - `match` BetaRuleMatch, required — Does the incoming JWT qualify? All populated fields must pass; omitted fields are skipped. At least one of `subject_prefix` (other than a wildcard-only value like `*`), `claims`, or `condition` is required; `audience` alone is not sufficient.
      - `audience` string, nullable — Exact match against the `aud` claim (any element if array). When omitted, the JWT's `aud` must still equal Anthropic's expected audience for the issuer; setting this field overrides that default.
      - `claims` object, nullable — Exact-match `{claim: value}` pairs against top-level claims. Only string-valued claims can be matched; use `condition` for non-string claims.
      - `condition` string, nullable — CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the `claims` variable; a constant-true expression (such as `true`) is rejected with 400.
      - `subject_prefix` string, nullable — Match the verified JWT `sub` claim. Exact match unless the value ends with `*`, in which case it is a prefix match. Example: `repo:my-org/my-repo:ref:refs/heads/main`.
    - `name` string, required — Admin-chosen slug identifier.
    - `oauth_scope` string, required — Space-separated OAuth scopes granted on the minted token.
    - `target` BetaServiceAccountTarget, required — Bind to a fixed service account by ID.
      - `service_account_id` string, required — Tagged ID of the service account to mint tokens for.
      - `service_account_name` string, nullable — Service account's display name at read time. Ignored on writes.
      - `type` 'service_account', required
    - `token_lifetime_seconds` integer, required — Lifetime in seconds of access tokens minted via this rule. Minted tokens are capped at `max(60, min(this value, 2 × remaining assertion validity))` seconds.
    - `type` 'federation_rule', required
    - `updated_at` string, date-time, required — When this rule was last updated.
    - `updated_by_actor_id` string, nullable, required — Tagged ID (`user_`/`svac_`) of the actor that last updated this rule.
    - `workspace_id` string, nullable, required — Legacy single-workspace binding. Prefer `workspace_ids` and the `/federation_rules/{federation_rule_id}/workspaces` sub-resource for managing workspace enablement.
    - `workspace_ids` string[], required — Tagged IDs of the workspaces this rule is enabled for. May be empty for older rules that only carry the legacy `workspace_id` binding. Ignored at exchange time when `applies_to_all_workspaces` is true (the list may still be non-empty).
  - `next_page` string, nullable, required — Opaque cursor for the next page, or null if no more results.

## Other responses

- `400` — Invalid argument - The client specified an invalid argument
- `401` — Unauthenticated - The request does not have valid authentication credentials
- `403` — Permission denied - The caller does not have permission to execute the specified operation
- `404` — Not found - Some requested entity was not found
- `408` — Deadline exceeded - The deadline expired before the operation could complete
- `409` — Aborted - The operation was aborted due to concurrency issue
- `412` — Failed precondition - Operation was rejected because the system is not in required state
- `413` — Out of range - Operation was attempted past the valid range
- `429` — Resource exhausted - Some resource has been exhausted (rate limiting)
- `431` — Request header fields too large - Request metadata was too large
- `499` — Cancelled - The operation was cancelled by the client
- `500` — Internal - Internal server error
- `501` — Unimplemented - The operation is not implemented or supported
- `503` — Unavailable - The service is currently unavailable
- `504` — Deadline exceeded - Upstream service did not respond in time
- `529` — Overloaded - The service is temporarily overloaded

## Changes

- **2026-09-02** `4789294140a2` — 16 info
  - added the non-success response with the status `400`
  - added the non-success response with the status `401`
  - added the non-success response with the status `403`
  - added the non-success response with the status `404`
  - …12 more
- **2026-08-26** `942a11636c42` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/anthropics/apis/anthropic-api/changes/v1/organizations/federation_rules?beta=true/get.md)

---

[API](https://skmtc.dev/anthropics/apis/anthropic-api.md) · [All operations](https://skmtc.dev/anthropics/apis/anthropic-api/llms.txt) · [OpenAPI document](https://skmtc.dev/anthropics/apis/anthropic-api/revisions/1bb7c7a0a4a9?raw)
