FederatedCredentialPolicy interface
Defines which federated credentials can operate on behalf of a user. The policy is used to evaluate an incoming federated credential and define what actions can be taken on behalf of the user. A policy is scoped to a single publisher; the exchanged credential inherits the creator's role on that publisher.
Properties
| created | When this entity was first created. The timestamp is in UTC. |
| created |
The ADO identity that created this policy. The exchanged credential will act as this identity, inheriting their role on the publisher (Owner, Contributor). |
| criteria | A JSON object used to evaluate whether a token matches a user-provided pattern. Some criteria may be implied by the Type and may not be explicitly stated here. |
| key | The unique key for this federated credential policy. Generated by the database. |
| last |
When this policy was last evaluated against an external credential and it matched. The timestamp is in UTC. Null until the first match. |
| policy |
An optional human-readable label for this policy (e.g., "Release workflow"). Not used when matching credentials. |
| publisher |
The publisher that this policy grants access to. The exchanged credential will be scoped to this publisher. Used to look up trust policies when a token exchange request arrives. |
| type | A type enum determining how the Criteria field should be interpreted. |
Property Details
created
When this entity was first created. The timestamp is in UTC.
created: Date
Property Value
Date
createdByIdentityId
The ADO identity that created this policy. The exchanged credential will act as this identity, inheriting their role on the publisher (Owner, Contributor).
createdByIdentityId: string
Property Value
string
criteria
A JSON object used to evaluate whether a token matches a user-provided pattern. Some criteria may be implied by the Type and may not be explicitly stated here.
criteria: string
Property Value
string
key
The unique key for this federated credential policy. Generated by the database.
key: number
Property Value
number
lastMatched
When this policy was last evaluated against an external credential and it matched. The timestamp is in UTC. Null until the first match.
lastMatched: Date
Property Value
Date
policyName
An optional human-readable label for this policy (e.g., "Release workflow"). Not used when matching credentials.
policyName: string
Property Value
string
publisherId
The publisher that this policy grants access to. The exchanged credential will be scoped to this publisher. Used to look up trust policies when a token exchange request arrives.
publisherId: string
Property Value
string
type
A type enum determining how the Criteria field should be interpreted.
type: GitHubActions