Creates a credential provider.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
eiam:CreateCredentialProvider |
create |
*CredentialProvider
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| InstanceId |
string |
Yes |
The instance ID. |
idaas_ue2jvisn35ea5lmthk267xxxxx |
| ClientToken |
string |
Yes |
The idempotency token that ensures the idempotence of the request. Generate a unique parameter value from your client to ensure that different requests have unique values. ClientToken supports only ASCII characters and cannot exceed 64 characters in length. For more information, see References How to ensure idempotence. |
client-token-example |
| CredentialProviderIdentifier |
string |
Yes |
The business identifier of the credential provider. Note
Allowed characters include uppercase and lowercase letters, digits, and the special characters |
test_example_identifier |
| CredentialProviderName |
string |
Yes |
The name of the credential provider. Note
The length cannot exceed 64 characters. |
test_example_name |
| Description |
string |
No |
The description. Note
The length cannot exceed 128 characters. |
This is an example description |
| CredentialProviderType |
string |
Yes |
The type of the credential provider. Valid values:
|
oauth |
| CredentialProviderConfig |
object |
No |
The configuration of the credential provider. |
|
| OAuthProviderConfig |
object |
No |
The configuration of the OAuth credential provider. |
|
| ClientId |
string |
Yes |
The client_id in the OAuth protocol, which is the client ID. Note
The length cannot exceed 128 characters. |
client_id_example_xxx |
| ClientSecret |
string |
Yes |
The client_secret in the OAuth protocol, which is the client secret. Note
The length cannot exceed 1024 characters. |
client_secret_example_xxx |
| TokenEndpoint |
string |
No |
The token endpoint of the OAuth protocol. Note
The value must start with |
https://example.com/token |
| Scope |
string |
No |
The scope in the OAuth protocol, which specifies the permission scope. Note
The Scope configuration on the credential provider serves as the default value. If the scope parameter is not specified when calling the DeveloperAPI to obtain an OAuth Access Token, the Scope configuration on the credential provider is used for issuance. Important Separate multiple Scope values with spaces. The following restrictions apply to each individual Scope value:
|
example:test_01 example:test_02 |
| AuthorizationFlow |
string |
No |
The OAuth authorization flow type. Valid values:
|
m2m |
| AuthorizationEndpoint |
string |
No |
The authorization endpoint of the OAuth protocol. |
https://example.com/authorize |
| ProviderVendor |
string |
No |
The OAuth provider vendor type. Valid values:
|
custom |
| DiscoveryUrl |
string |
No |
The URL of the OAuth Discovery document. |
https://example.com/.well-known/openid-configuration |
| PkceEnabled |
boolean |
No |
Specifies whether to enable PKCE. |
true |
| PkceChallengeMethod |
string |
No |
The algorithm used to calculate the Code Challenge in PKCE. Valid values:
|
S256 |
| Issuer |
string |
No |
The Issuer endpoint of the OAuth protocol. |
https://example.com/issuer |
| JwtProviderConfig |
object |
No |
The configuration of the JWT credential provider. |
|
| Expiration |
integer |
No |
The validity period of the JWT, in seconds. |
900 |
| ExpirationCleanupEnabled |
boolean |
No |
Specifies whether to enable JWT expiration cleanup. |
true |
| DerivedShortTokenEnabled |
boolean |
No |
Specifies whether to enable the JWT derived short token feature. |
false |
| AllowedTokenIssuers |
array |
No |
The list of allowed JWT issuers. Note
The list cannot contain more than 200 entries. |
|
|
string |
No |
The allowed JWT issuer. Note
The length cannot exceed 1024 characters. |
https://test.issuer.com |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID. |
0441BD79-92F3-53AA-8657-F8CE4A2B912A |
| CredentialProviderId |
string |
The credential provider ID. |
atp_01kr2cmj5gxxx4fvmls2e93dxxxxx |
Examples
Success response
JSON format
{
"RequestId": "0441BD79-92F3-53AA-8657-F8CE4A2B912A",
"CredentialProviderId": "atp_01kr2cmj5gxxx4fvmls2e93dxxxxx"
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.