All Products
Search
Document Center

CloudSSO:SetExternalSAMLIdentityProvider

Last Updated:Aug 28, 2026

Configures a SAML identity provider (IdP).

Operation description

During SAML 2.0-based single sign-on (SSO) logon, CloudSSO is a service provider (SP), and the identity management system of an enterprise is an IdP.

Configure a SAML IdP by using one of the following methods. Obtain the required metadata file or parameter values from your IdP.

  • Use the metadata file: You can specify the EncodedMetadataDocument parameter to upload the metadata file.

  • Manually configure the IdP: You can manually specify the following parameters for your IdP: EntityId, LoginUrl, WantRequestSigned, and X509Certificate.

If a SAML IdP is already configured, calling this operation replaces the existing configurations.

  • If the IdP is configured by using the metadata file, all existing configurations are replaced with new configurations.

  • If the IdP is manually configured, the original parameter values that are different from the new parameter values are replaced.

Note

If SSO logon is enabled, new configurations take effect immediately. Evaluate the impact on your production environment before proceeding.

The following example configures an IdP by using the metadata file within the directory d-00fc2p61****.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

cloudsso:SetExternalSAMLIdentityProvider

update

*Directory

acs:cloudsso:{#regionId}:{#accountId}:directory/{#DirectoryId}

None None

Request parameters

Parameter

Type

Required

Description

Example

DirectoryId

string

Yes

The ID of the directory.

d-00fc2p61****

EncodedMetadataDocument

string

No

The metadata file of the IdP. The value of this parameter is Base64-encoded.

The file is provided by the IdP that supports SAML 2.0.

PD94bWwgdmVyc2lvbj0iMS4****

SSOStatus

string

No

The status of SSO logon. Valid values:

  • Enabled

  • Disabled (default)

Disabled

EntityId

string

No

The entity ID of the IdP.

http://www.okta.com/exk3qwgtjhetR2Od****

LoginUrl

string

No

The logon URL of the IdP.

https://dev-xxxxxx.okta.com/app/dev-xxxxxx_cloudssodemo_1/exk3qwgtjhetR2Od****/sso/saml

WantRequestSigned

boolean

No

Specifies whether CloudSSO signs SAML requests that are sent when users log on to the CloudSSO user portal to initiate SAML-based SSO. Valid values:

  • true: Signing is required.

  • false (default): Signing is not required.

false

X509Certificate

string

No

The X.509 certificate in the PEM format. If you specify this parameter, all existing certificates are replaced.

MIIC8DCCAdigAwIBAgIQP9eomUYGeoND****

BindingType

string

No

The binding for sending SAML requests. Valid values:

  • Post: HTTP Post bindings.

  • Redirect: HTTP Redirect bindings.

Redirect

Response elements

Element

Type

Description

Example

object

The response parameters.

RequestId

string

The request ID.

63160579-2E1B-57B0-8273-B27427172385

SAMLIdentityProviderConfiguration

object

The configurations of the IdP.

EntityId

string

The entity ID of the IdP.

http://www.okta.com/exk3qwgtjhetR2Od****

SSOStatus

string

The status of SSO logon. Valid values:

  • Enabled

  • Disabled

Disabled

DirectoryId

string

The ID of the directory.

d-00fc2p61****

EncodedMetadataDocument

string

The metadata file of the IdP. The value of this parameter is Base64-encoded.

PD94bWwgdmVyc2lvbj0iMS4****

CreateTime

string

The time when the IdP was configured for the first time.

2021-11-10T02:57:16Z

WantRequestSigned

boolean

Indicates whether CloudSSO signs SAML requests that are sent when users log on to the CloudSSO user portal to initiate SAML-based SSO. Valid values:

  • true: Signing is required.

  • false (default): Signing is not required.

false

UpdateTime

string

The time when the IdP configurations were last modified.

2021-11-10T02:57:16Z

CertificateIds

array

The IDs of the SAML signing certificates.

string

The ID of the SAML signing certificate.

Multiple IDs are separated by commas (,).

[ "idp-c-00buzdx63z8ewtdf****", "idp-c-00gmuxnr2mrek3t2****" ]

LoginUrl

string

The logon URL of the IdP.

https://dev-xxxxxx.okta.com/app/dev-xxxxxx_cloudssodemo_1/exk3qwgtjhetR2Od****/sso/saml

BindingType

string

The binding for sending SAML requests. Valid values:

  • Post: HTTP Post bindings.

  • Redirect: HTTP Redirect bindings.

Redirect

Examples

Success response

JSON format

{
  "RequestId": "63160579-2E1B-57B0-8273-B27427172385",
  "SAMLIdentityProviderConfiguration": {
    "EntityId": "http://www.okta.com/exk3qwgtjhetR2Od****",
    "SSOStatus": "Disabled",
    "DirectoryId": "d-00fc2p61****",
    "EncodedMetadataDocument": "PD94bWwgdmVyc2lvbj0iMS4****",
    "CreateTime": "2021-11-10T02:57:16Z",
    "WantRequestSigned": false,
    "UpdateTime": "2021-11-10T02:57:16Z",
    "CertificateIds": [
      "[ \"idp-c-00buzdx63z8ewtdf****\", \"idp-c-00gmuxnr2mrek3t2****\" ]"
    ],
    "LoginUrl": "https://dev-xxxxxx.okta.com/app/dev-xxxxxx_cloudssodemo_1/exk3qwgtjhetR2Od****/sso/saml",
    "BindingType": "Redirect"
  }
}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.