GET /v1/organizations/federation_rules/{federation_rule_id}
Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.
Retrieve a federation rule by its ID (fdrl_...).
Path parameters
federation_rule_id: string
ID of the federation rule.
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
Returns
BetaFederationRule object
Authorization rule binding an external OIDC identity to Juglow.
Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.
type: "federation_rule"
default: federation_rule
id: string
Tagged ID of the federation rule.
applies_to_all_workspaces: boolean
When true, this rule is enabled for every workspace in the org (including ones created after the rule). workspace_ids is ignored at exchange time.
archived_at: string or null
If set, this rule is archived and rejects token exchange.
format: date-time
archived_by_actor_id: string or null
Tagged ID (user_/svac_) of the actor that archived this rule.
attributes: map[string] or null
CEL expressions extracting named values from claims. Not yet supported; always null.
created_at: string
When this rule was created.
format: date-time
created_by_actor_id: string or null
Tagged ID (user_/svac_) of the actor that created this rule.
description: string or null
Optional free-text description.
issuer_id: string
Tagged ID of the issuer whose tokens this rule accepts.
issuer_name: string or null
Issuer's display name at read time.
match: BetaFederationRuleMatch
Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
audience: optional string or null
Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Juglow's expected audience for the issuer; setting this field overrides that default.
maxLength: 1024
claims: optional map[string] or null
Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.
condition: optional string or null
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.
maxLength: 4096
subject_prefix: optional string or null
Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.
maxLength: 1024
name: string
Admin-chosen slug identifier.
oauth_scope: string
Space-separated OAuth scopes granted on the minted token.
target: BetaServiceAccountTarget
Identity that tokens minted via this rule act as. Currently always a service_account target.
type: "service_account"
service_account_id: string
Tagged ID of the service account to mint tokens for.
service_account_name: optional string or null
Service account's display name at read time. Ignored on writes.
token_lifetime_seconds: number
Lifetime in seconds of access tokens minted via this rule. Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.
updated_at: string
When this rule was last updated.
format: date-time
updated_by_actor_id: string or null
Tagged ID (user_/svac_) of the actor that last updated this rule.
workspace_id: string or null
Legacy single-workspace binding. Prefer workspace_ids and the /federation_rules/{federation_rule_id}/workspaces sub-resource for managing workspace enablement.
workspace_ids: array of string
Tagged IDs of the workspaces this rule is enabled for. May be empty for older rules that only carry the legacy workspace_id binding. Ignored at exchange time when applies_to_all_workspaces is true (the list may still be non-empty).
Example
curl https://haijun.my.id/v1/organizations/federation_rules/$FEDERATION_RULE_ID \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY"Response (200)
{
"id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
"applies_to_all_workspaces": true,
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"attributes": {
"foo": "string"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"issuer_id": "issuer_id",
"issuer_name": "issuer_name",
"match": {
"audience": "audience",
"claims": {
"foo": "string"
},
"condition": "condition",
"subject_prefix": "subject_prefix"
},
"name": "prod-deploy-pipeline",
"oauth_scope": "oauth_scope",
"target": {
"service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"type": "service_account",
"service_account_name": "service_account_name"
},
"token_lifetime_seconds": 0,
"type": "federation_rule",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id",
"workspace_id": "workspace_id",
"workspace_ids": [
"string"
]
}