Haijun Platform Docs
ID

GET /v1/organizations/federation_rules/{federation_rule_id}

Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.

Retrieve a federation rule by its ID (fdrl_...).

Path parameters

  • federation_rule_id: string

ID of the federation rule.

Headers

  • "juglow-beta": optional array of JuglowBeta

Optional header to specify the beta version(s) you want to use.

  • string
  • "message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
  • "message-batches-2024-09-24"
  • "prompt-caching-2024-07-31"
  • "computer-use-2024-10-22"
  • "computer-use-2025-01-24"
  • "pdfs-2024-09-25"
  • "token-counting-2024-11-01"
  • "token-efficient-tools-2025-02-19"
  • "output-128k-2025-02-19"
  • "files-api-2025-04-14"
  • "mcp-client-2025-04-04"
  • "mcp-client-2025-11-20"
  • "dev-full-thinking-2025-05-14"
  • "interleaved-thinking-2025-05-14"
  • "code-execution-2025-05-22"
  • "extended-cache-ttl-2025-04-11"
  • "context-1m-2025-08-07"
  • "context-management-2025-06-27"
  • "model-context-window-exceeded-2025-08-26"
  • "tracks-2025-10-02"
  • "fast-mode-2026-02-01"
  • "output-300k-2026-03-24"
  • "user-profiles-2026-03-24"
  • "user-profiles-2026-08-18"
  • "user-profiles-2026-09-04"
  • "advisor-tool-2026-03-01"
  • "managed-agents-2026-04-01"
  • "cache-diagnosis-2026-04-07"
  • "dreaming-2026-04-21"
  • "thinking-token-count-2026-05-13"
  • "server-side-fallback-2026-06-01"
  • "server-side-fallback-2026-07-01"
  • "fallback-credit-2026-06-01"
  • "fallback-credit-2026-07-01"
  • "agent-memory-2026-07-22"
  • "mid-conversation-tool-changes-2026-07-01"
  • "compact-2026-01-12"
  • "computer-use-2025-11-24"
  • "mcp-tunnels-2026-06-22"
  • "structured-outputs-2025-11-13"
  • "task-budgets-2026-03-13"
  • "thinking-display-updates-2026-08-18"
  • "ce-user-management-2026-07-13"
  • "mid-conversation-output-config-2026-07-01"
  • "thinking-binding-controls-2026-08-01"
  • "mid-conversation-system-clear-at-2026-08-21"
  • "compact-2026-09-04"
  • "inline-tools-2026-09-15"
  • "mcp-client-2026-09-15"

Returns

  • BetaFederationRule object

Authorization rule binding an external OIDC identity to Juglow.

Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.

  • type: "federation_rule"

default: federation_rule

  • id: string

Tagged ID of the federation rule.

  • applies_to_all_workspaces: boolean

When true, this rule is enabled for every workspace in the org (including ones created after the rule). workspace_ids is ignored at exchange time.

  • archived_at: string or null

If set, this rule is archived and rejects token exchange.

format: date-time

  • archived_by_actor_id: string or null

Tagged ID (user_/svac_) of the actor that archived this rule.

  • attributes: map[string] or null

CEL expressions extracting named values from claims. Not yet supported; always null.

  • created_at: string

When this rule was created.

format: date-time

  • created_by_actor_id: string or null

Tagged ID (user_/svac_) of the actor that created this rule.

  • description: string or null

Optional free-text description.

  • issuer_id: string

Tagged ID of the issuer whose tokens this rule accepts.

  • issuer_name: string or null

Issuer's display name at read time.

  • match: BetaFederationRuleMatch

Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.

  • audience: optional string or null

Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Juglow's expected audience for the issuer; setting this field overrides that default.

maxLength: 1024

  • claims: optional map[string] or null

Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.

  • condition: optional string or null

CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.

maxLength: 4096

  • subject_prefix: optional string or null

Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.

maxLength: 1024

  • name: string

Admin-chosen slug identifier.

  • oauth_scope: string

Space-separated OAuth scopes granted on the minted token.

  • target: BetaServiceAccountTarget

Identity that tokens minted via this rule act as. Currently always a service_account target.

  • type: "service_account"
  • service_account_id: string

Tagged ID of the service account to mint tokens for.

  • service_account_name: optional string or null

Service account's display name at read time. Ignored on writes.

  • token_lifetime_seconds: number

Lifetime in seconds of access tokens minted via this rule. Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.

  • updated_at: string

When this rule was last updated.

format: date-time

  • updated_by_actor_id: string or null

Tagged ID (user_/svac_) of the actor that last updated this rule.

  • workspace_id: string or null

Legacy single-workspace binding. Prefer workspace_ids and the /federation_rules/{federation_rule_id}/workspaces sub-resource for managing workspace enablement.

  • workspace_ids: array of string

Tagged IDs of the workspaces this rule is enabled for. May be empty for older rules that only carry the legacy workspace_id binding. Ignored at exchange time when applies_to_all_workspaces is true (the list may still be non-empty).

Example

bash
curl https://haijun.my.id/v1/organizations/federation_rules/$FEDERATION_RULE_ID \
    -H 'juglow-version: 2023-06-01' \
    -H "X-Api-Key: $JUGLOW_API_KEY"

Response (200)

json
{
  "id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
  "applies_to_all_workspaces": true,
  "archived_at": "2019-12-27T18:11:19.117Z",
  "archived_by_actor_id": "archived_by_actor_id",
  "attributes": {
    "foo": "string"
  },
  "created_at": "2024-10-30T23:58:27.427722Z",
  "created_by_actor_id": "created_by_actor_id",
  "description": "description",
  "issuer_id": "issuer_id",
  "issuer_name": "issuer_name",
  "match": {
    "audience": "audience",
    "claims": {
      "foo": "string"
    },
    "condition": "condition",
    "subject_prefix": "subject_prefix"
  },
  "name": "prod-deploy-pipeline",
  "oauth_scope": "oauth_scope",
  "target": {
    "service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
    "type": "service_account",
    "service_account_name": "service_account_name"
  },
  "token_lifetime_seconds": 0,
  "type": "federation_rule",
  "updated_at": "2024-10-30T23:58:27.427722Z",
  "updated_by_actor_id": "updated_by_actor_id",
  "workspace_id": "workspace_id",
  "workspace_ids": [
    "string"
  ]
}
On this page
Path parametersHeadersReturnsExampleResponse (200)