POST /v1/organizations/federation_rules/{federation_rule_id}
Requires an OAuth access token with the org:admin scope, from ant auth login --scope org:admin or a workload identity federation rule; Admin API keys are not accepted. See Manage WIF with the Admin API.
Partially update a federation rule.
issuer_id is immutable. match and target are replaced as whole objects when set. Referenced service accounts and workspaces must exist in your organization; invalid references are rejected with a 400 error. Archived rules cannot be updated; this returns 400. Create a new rule instead. Rules on well-known shared issuers (GitHub Actions, GitLab, Buildkite, Terraform Cloud, Google) must constrain tenant identity via an identity-bearing claim, a tenant-pinning subject prefix (such as repo:YOUR_ORG/...), or a CEL condition referencing one of those identity claims (e.g. claims.repository_owner). On these issuers the requirement is re-checked on every update; if an existing rule's stored match does not yet constrain tenant identity, any update (even a rename or description change) must also supply a conforming match in the same request. OAuth callers may only manage rules whose oauth_scope is workspace:developer or workspace:inference; other scopes require a Console session.
Path parameters
federation_rule_id: string
ID of the federation rule to update.
Headers
"juglow-beta": optional array of JuglowBeta
Optional header to specify the beta version(s) you want to use.
string
"message-batches-2024-09-24" or "prompt-caching-2024-07-31" or "computer-use-2024-10-22" or 45 more
"message-batches-2024-09-24"
"prompt-caching-2024-07-31"
"computer-use-2024-10-22"
"computer-use-2025-01-24"
"pdfs-2024-09-25"
"token-counting-2024-11-01"
"token-efficient-tools-2025-02-19"
"output-128k-2025-02-19"
"files-api-2025-04-14"
"mcp-client-2025-04-04"
"mcp-client-2025-11-20"
"dev-full-thinking-2025-05-14"
"interleaved-thinking-2025-05-14"
"code-execution-2025-05-22"
"extended-cache-ttl-2025-04-11"
"context-1m-2025-08-07"
"context-management-2025-06-27"
"model-context-window-exceeded-2025-08-26"
"tracks-2025-10-02"
"fast-mode-2026-02-01"
"output-300k-2026-03-24"
"user-profiles-2026-03-24"
"user-profiles-2026-08-18"
"user-profiles-2026-09-04"
"advisor-tool-2026-03-01"
"managed-agents-2026-04-01"
"cache-diagnosis-2026-04-07"
"dreaming-2026-04-21"
"thinking-token-count-2026-05-13"
"server-side-fallback-2026-06-01"
"server-side-fallback-2026-07-01"
"fallback-credit-2026-06-01"
"fallback-credit-2026-07-01"
"agent-memory-2026-07-22"
"mid-conversation-tool-changes-2026-07-01"
"compact-2026-01-12"
"computer-use-2025-11-24"
"mcp-tunnels-2026-06-22"
"structured-outputs-2025-11-13"
"task-budgets-2026-03-13"
"thinking-display-updates-2026-08-18"
"ce-user-management-2026-07-13"
"mid-conversation-output-config-2026-07-01"
"thinking-binding-controls-2026-08-01"
"mid-conversation-system-clear-at-2026-08-21"
"compact-2026-09-04"
"inline-tools-2026-09-15"
"mcp-client-2026-09-15"
Body parameters
applies_to_all_workspaces: optional boolean or null
When true, enables this rule for every workspace in the org (including workspaces created later). Setting false is rejected with 400 if no workspace would remain enabled; a rule with only a legacy workspace_id binding continues to mint.
attributes: optional map[string] or null
Replaces the CEL expressions {name: expr} extracting named values from claims. Send null to clear them. Not yet supported; any non-empty value is rejected with 400.
description: optional string or null
Replaces the description. Omit to leave unchanged; send null to clear (the field is stored as an empty string).
maxLength: 2000
match: optional BetaFederationRuleMatch or null
Replaces the entire match object. All populated matcher fields must pass.
audience: optional string or null
Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Juglow's expected audience for the issuer; setting this field overrides that default.
maxLength: 1024
claims: optional map[string] or null
Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.
condition: optional string or null
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.
maxLength: 4096
subject_prefix: optional string or null
Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.
maxLength: 1024
name: optional string or null
Replaces the slug identifier (lowercase, digits, hyphens). Unique within the organization; a duplicate name returns 409.
minLength: 1, maxLength: 255
oauth_scope: optional string or null
Replaces the space-separated OAuth scopes granted on minted tokens. OAuth callers may only set workspace:developer or workspace:inference; other scopes (such as org:admin) require a Console session.
minLength: 1
target: optional BetaServiceAccountTarget or null
Replaces the entire target object. Currently always a service_account target.
type: "service_account"
service_account_id: string
Tagged ID of the service account to mint tokens for.
service_account_name: optional string or null
Service account's display name at read time. Ignored on writes.
token_lifetime_seconds: optional number or null
Replaces the lifetime in seconds for access tokens minted via this rule (60-86400). Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.
minimum: 60, maximum: 86400
workspace_id: optional string or null
Replaces the existing single workspace enablement (the previous one is removed). Rejected with 400 if the rule is enabled for more than one workspace; use the /federation_rules/{federation_rule_id}/workspaces sub-resource instead.
Returns
BetaFederationRule object
Authorization rule binding an external OIDC identity to Juglow.
Evaluates the match conditions and mints an OAuth access token for the resolved target, scoped to a single workspace where the rule is enabled (chosen by the caller at exchange time when the rule is enabled for more than one). For rules enabled via workspace_ids or applies_to_all_workspaces, the target service account must be a member of that workspace (it is implicitly a member of the default workspace); rules carrying only the legacy workspace_id binding do not enforce this.
type: "federation_rule"
default: federation_rule
id: string
Tagged ID of the federation rule.
applies_to_all_workspaces: boolean
When true, this rule is enabled for every workspace in the org (including ones created after the rule). workspace_ids is ignored at exchange time.
archived_at: string or null
If set, this rule is archived and rejects token exchange.
format: date-time
archived_by_actor_id: string or null
Tagged ID (user_/svac_) of the actor that archived this rule.
attributes: map[string] or null
CEL expressions extracting named values from claims. Not yet supported; always null.
created_at: string
When this rule was created.
format: date-time
created_by_actor_id: string or null
Tagged ID (user_/svac_) of the actor that created this rule.
description: string or null
Optional free-text description.
issuer_id: string
Tagged ID of the issuer whose tokens this rule accepts.
issuer_name: string or null
Issuer's display name at read time.
match: BetaFederationRuleMatch
Conditions the verified JWT must satisfy for this rule to apply. All populated matcher fields must pass.
audience: optional string or null
Exact match against the aud claim (any element if array). When omitted, the JWT's aud must still equal Juglow's expected audience for the issuer; setting this field overrides that default.
maxLength: 1024
claims: optional map[string] or null
Exact-match {claim: value} pairs against top-level claims. Only string-valued claims can be matched; use condition for non-string claims.
condition: optional string or null
CEL expression over claims for logic the structural fields can't express. Must evaluate to a boolean and may reference only the claims variable; a constant-true expression (such as true) is rejected with 400.
maxLength: 4096
subject_prefix: optional string or null
Match the verified JWT sub claim. Exact match unless the value ends with *, in which case it is a prefix match. Example: repo:my-org/my-repo:ref:refs/heads/main.
maxLength: 1024
name: string
Admin-chosen slug identifier.
oauth_scope: string
Space-separated OAuth scopes granted on the minted token.
target: BetaServiceAccountTarget
Identity that tokens minted via this rule act as. Currently always a service_account target.
type: "service_account"
service_account_id: string
Tagged ID of the service account to mint tokens for.
service_account_name: optional string or null
Service account's display name at read time. Ignored on writes.
token_lifetime_seconds: number
Lifetime in seconds of access tokens minted via this rule. Minted tokens are capped at max(60, min(this value, 2 × remaining assertion validity)) seconds.
updated_at: string
When this rule was last updated.
format: date-time
updated_by_actor_id: string or null
Tagged ID (user_/svac_) of the actor that last updated this rule.
workspace_id: string or null
Legacy single-workspace binding. Prefer workspace_ids and the /federation_rules/{federation_rule_id}/workspaces sub-resource for managing workspace enablement.
workspace_ids: array of string
Tagged IDs of the workspaces this rule is enabled for. May be empty for older rules that only carry the legacy workspace_id binding. Ignored at exchange time when applies_to_all_workspaces is true (the list may still be non-empty).
Example
curl https://haijun.my.id/v1/organizations/federation_rules/$FEDERATION_RULE_ID \
-H 'Content-Type: application/json' \
-H 'juglow-version: 2023-06-01' \
-H "X-Api-Key: $JUGLOW_API_KEY" \
-d '{}'Response (200)
{
"id": "fdrl_01SDCCSbTxrXDpWc1phhtcfK",
"applies_to_all_workspaces": true,
"archived_at": "2019-12-27T18:11:19.117Z",
"archived_by_actor_id": "archived_by_actor_id",
"attributes": {
"foo": "string"
},
"created_at": "2024-10-30T23:58:27.427722Z",
"created_by_actor_id": "created_by_actor_id",
"description": "description",
"issuer_id": "issuer_id",
"issuer_name": "issuer_name",
"match": {
"audience": "audience",
"claims": {
"foo": "string"
},
"condition": "condition",
"subject_prefix": "subject_prefix"
},
"name": "prod-deploy-pipeline",
"oauth_scope": "oauth_scope",
"target": {
"service_account_id": "svac_01SDCCSbTxrXDpWc1phhtcfK",
"type": "service_account",
"service_account_name": "service_account_name"
},
"token_lifetime_seconds": 0,
"type": "federation_rule",
"updated_at": "2024-10-30T23:58:27.427722Z",
"updated_by_actor_id": "updated_by_actor_id",
"workspace_id": "workspace_id",
"workspace_ids": [
"string"
]
}