Edit

FederatedCredentialPolicy interface

Defines which federated credentials can operate on behalf of a user. The policy is used to evaluate an incoming federated credential and define what actions can be taken on behalf of the user. A policy is scoped to a single publisher; the exchanged credential inherits the creator's role on that publisher.

Properties

created

When this entity was first created. The timestamp is in UTC.

createdByIdentityId

The ADO identity that created this policy. The exchanged credential will act as this identity, inheriting their role on the publisher (Owner, Contributor).

criteria

A JSON object used to evaluate whether a token matches a user-provided pattern. Some criteria may be implied by the Type and may not be explicitly stated here.

key

The unique key for this federated credential policy. Generated by the database.

lastMatched

When this policy was last evaluated against an external credential and it matched. The timestamp is in UTC. Null until the first match.

policyName

An optional human-readable label for this policy (e.g., "Release workflow"). Not used when matching credentials.

publisherId

The publisher that this policy grants access to. The exchanged credential will be scoped to this publisher. Used to look up trust policies when a token exchange request arrives.

type

A type enum determining how the Criteria field should be interpreted.

Property Details

created

When this entity was first created. The timestamp is in UTC.

created: Date

Property Value

Date

createdByIdentityId

The ADO identity that created this policy. The exchanged credential will act as this identity, inheriting their role on the publisher (Owner, Contributor).

createdByIdentityId: string

Property Value

string

criteria

A JSON object used to evaluate whether a token matches a user-provided pattern. Some criteria may be implied by the Type and may not be explicitly stated here.

criteria: string

Property Value

string

key

The unique key for this federated credential policy. Generated by the database.

key: number

Property Value

number

lastMatched

When this policy was last evaluated against an external credential and it matched. The timestamp is in UTC. Null until the first match.

lastMatched: Date

Property Value

Date

policyName

An optional human-readable label for this policy (e.g., "Release workflow"). Not used when matching credentials.

policyName: string

Property Value

string

publisherId

The publisher that this policy grants access to. The exchanged credential will be scoped to this publisher. Used to look up trust policies when a token exchange request arrives.

publisherId: string

Property Value

string

type

A type enum determining how the Criteria field should be interpreted.

type: GitHubActions

Property Value