Haijun Platform Docs
ID

POST /v1/organizations/federation_issuers/{federation_issuer_id}

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Partially update a federation issuer.

Setting jwks replaces the full JWKS shape at once. Archived issuers cannot be updated; this returns 400. Create a new issuer instead.

Updating an issuer that backs a rule with a scope outside workspace:developer or workspace:inference requires a Console session.

Path parameters

  • federation_issuer_id: string

ID of the federation issuer to update.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"

Body parameters

  • check_jti: optional boolean or null

Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a jti claim; tokens without one are accepted without single-use enforcement.

  • issuer_url: optional string or null

Replaces the iss claim value to match against. For discovery-mode issuers without a discovery_base, this is also the URL Juglow fetches the OIDC discovery document and signing keys from, so changing it repoints the JWKS source. Changing the issuer URL to a well-known shared platform is rejected while any live rule under this issuer would not constrain tenant identity.

minLength: 1

  • jwks: optional BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline or null

Replaces the entire JWKS configuration.

  • BetaJWKSDiscovery object

JWKS via the issuer's OIDC discovery document.

  • type: "discovery"
  • ca_cert_pem: optional string or null

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength: 8192

  • discovery_base: optional string or null

Set when the discovery URL differs from issuer_url.

  • BetaJWKSExplicitURL object

JWKS fetched from a fixed endpoint.

  • type: "explicit_url"
  • url: string

JWKS endpoint.

minLength: 1

  • ca_cert_pem: optional string or null

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength: 8192

  • BetaJWKSInline object

JWKS supplied directly; no network fetch.

  • type: "inline"
  • keys: array of map[unknown]

Inline JWK objects.

minItems: 1

  • jwks_polling_disabled: optional boolean or null

Only false is accepted, to re-enable polling after the system pauses it. Polling is paused automatically; sending true is rejected.

  • max_jwt_lifetime_seconds: optional number or null

Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both iat and exp; a missing iat is rejected.

minimum: 1, maximum: 176400

  • name: optional string or null

Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.

minLength: 1, maxLength: 255

Returns

  • BetaFederationIssuer object

Registered external OIDC identity provider.

Records an external IdP the organization trusts for the RFC 7523 jwt-bearer grant. The issuer_url must match the JWT iss claim exactly.

  • type: "federation_issuer"

default: federation_issuer

  • id: string

Tagged ID of the federation issuer.

  • archived_at: string or null

If set, all rules referencing this issuer reject token exchange.

format: date-time

  • archived_by_actor_id: string or null

Tagged ID (user_/svac_) of the actor that archived this issuer.

  • check_jti: boolean

Whether the jwt-bearer exchange enforces JTI single-use (replay protection) for tokens from this issuer. Applies only to assertions carrying a jti claim; tokens without one are accepted without single-use enforcement.

  • created_at: string

When this issuer was created.

format: date-time

  • created_by_actor_id: string or null

Tagged ID (user_/svac_) of the actor that created this issuer.

  • issuer_url: string

The iss claim value. Incoming JWTs must match exactly.

  • jwks: BetaJWKSDiscovery or BetaJWKSExplicitURL or BetaJWKSInline

How signing keys are obtained for signature verification.

  • BetaJWKSDiscovery object

JWKS via the issuer's OIDC discovery document.

  • type: "discovery"
  • ca_cert_pem: optional string or null

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength: 8192

  • discovery_base: optional string or null

Set when the discovery URL differs from issuer_url.

  • BetaJWKSExplicitURL object

JWKS fetched from a fixed endpoint.

  • type: "explicit_url"
  • url: string

JWKS endpoint.

minLength: 1

  • ca_cert_pem: optional string or null

Optional custom CA (PEM) for TLS verification of the JWKS fetch.

maxLength: 8192

  • BetaJWKSInline object

JWKS supplied directly; no network fetch.

  • type: "inline"
  • keys: array of map[unknown]

Inline JWK objects.

minItems: 1

  • jwks_polling_disabled_at: string or null

If set, Juglow's JWKS poller has paused polling for this issuer after repeated fetch failures. Re-enable by sending jwks_polling_disabled: false via the issuer update endpoint (POST) once the upstream JWKS endpoint is fixed. An OAuth caller cannot send this when the issuer backs a rule with any scope other than workspace:developer or workspace:inference; use a Console session.

format: date-time

  • max_jwt_lifetime_seconds: number

Maximum allowed iat→exp spread for assertions from this issuer (1-176400 seconds, i.e. up to 49h). Assertions must carry both iat and exp; a missing iat is rejected.

  • name: string

Admin-chosen slug identifier.

  • poll_status: BetaFederationIssuerPollStatus or null

Live state of Juglow's JWKS polling for this issuer. Populated on both single-issuer retrieval and list responses, including archived issuers. Typically null for inline-key issuers (no polling), or when poll status is temporarily unavailable or polling has not started yet.

  • consecutive_failures: number

Consecutive fetch failures since the last success.

  • last_fetched_at: string or null

When the last successful fetch completed.

format: date-time

  • next_poll_at: string or null

When the next fetch is scheduled. Null if paused.

format: date-time

  • updated_at: string

When this issuer was last updated.

format: date-time

  • updated_by_actor_id: string or null

Tagged ID (user_/svac_) of the actor that last updated this issuer.

Example

bash
curl https://haijun.my.id/v1/organizations/federation_issuers/$FEDERATION_ISSUER_ID \
    -H 'Content-Type: application/json' \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY" \
    -d '{}'

Response (200)

json
{
  "id": "fdis_01SDCCSbTxrXDpWc1phhtcfK",
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "check_jti": true,
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "issuer_url": "https://token.actions.githubusercontent.com",
  "jwks": {
    "type": "discovery",
    "ca_cert_pem": "ca_cert_pem",
    "discovery_base": "discovery_base"
  },
  "jwks_polling_disabled_at": "2019-12-27T18:11:19.117Z",
  "max_jwt_lifetime_seconds": 0,
  "name": "github-actions",
  "poll_status": {
    "consecutive_failures": 0,
    "last_fetched_at": "2019-12-27T18:11:19.117Z",
    "next_poll_at": "2019-12-27T18:11:19.117Z"
  },
  "type": "federation_issuer",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id"
}
On this page
Path parametersHeadersBody parametersReturnsExampleResponse (200)