Queries the details of a credential provider.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
eiam:GetCredentialProvider |
get |
*CredentialProvider
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| InstanceId |
string |
Yes |
The instance ID. |
idaas_ue2jvisn35ea5lmthk267xxxxx |
| CredentialProviderId |
string |
Yes |
The credential provider ID. |
atp_01kr2cmj5gxxx4fvmls2e93dxxxxx |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID. |
0441BD79-92F3-53AA-8657-F8CE4A2B912A |
| CredentialProvider |
object |
The credential provider. |
|
| InstanceId |
string |
The instance ID. |
idaas_ue2jvisn35ea5lmthk267xxxxx |
| CredentialProviderId |
string |
The credential provider ID. |
atp_01kr2cmj5gxxx4fvmls2e93dxxxxx |
| CredentialProviderIdentifier |
string |
The business identifier of the credential provider. |
test_example_identifier |
| CredentialProviderName |
string |
The name of the credential provider. |
test_example_name |
| CreateTime |
integer |
The creation time of the credential provider. The value is a UNIX timestamp in milliseconds. |
1649830225000 |
| UpdateTime |
integer |
The update time of the credential provider. The value is a UNIX timestamp in milliseconds. |
1649830225000 |
| Description |
string |
The description. |
This is an example description |
| CredentialProviderType |
string |
The type of the credential provider. Valid values:
|
oauth |
| CredentialProviderCreationType |
string |
The creation type of the credential provider. Valid values:
|
user_custom |
| Status |
string |
The status of the credential provider. Valid values:
|
enabled |
| CredentialProviderConfig |
object |
The configuration of the credential provider. |
|
| ProviderCredentialIds |
array |
The list of credential IDs that correspond to the sensitive configurations of the credential provider. Note
The system securely stores the sensitive configuration information of the credential provider in the form of credentials. |
|
|
string |
The credential ID that corresponds to the sensitive configuration. |
cred_mkv7xxxxd7i4u7zqtzev2mxxxx |
|
| OAuthProviderConfig |
object |
The configuration of the OAuth credential provider. |
|
| ClientId |
string |
The client_id in the OAuth protocol, which is the client ID. |
client_id_example_xxx |
| TokenEndpoint |
string |
The token endpoint of the OAuth protocol. |
https://example.com/token |
| Scope |
string |
The scope in the OAuth protocol, which specifies the permission scope. Note
The scope configuration of the OAuth credential provider serves as the default value. If the scope parameter is not specified when you call the DeveloperAPI to obtain an OAuth access token, the scope configuration of the credential provider is used for token issuance. Important Multiple scope values are separated by spaces. |
example:test_01 example:test_02 |
| AuthorizationFlow |
string |
The OAuth authorization flow type. Valid values:
|
m2m |
| AuthorizationEndpoint |
string |
The authorization endpoint of the OAuth protocol. |
https://example.com/authorize |
| ProviderVendor |
string |
The OAuth provider vendor type. Valid values:
|
custom |
| DiscoveryUrl |
string |
The URL of the OAuth discovery document. |
https://example.com/.well-known/openid-configuration |
| SystemRedirectUri |
string |
The system-generated redirect URI. |
https://example.com/callback |
| PkceEnabled |
boolean |
Indicates whether Proof Key for Code Exchange (PKCE) is enabled. |
true |
| PkceChallengeMethod |
string |
The algorithm used to calculate the code challenge in PKCE. Valid values:
|
S256 |
| Issuer |
string |
The issuer endpoint of the OAuth protocol. |
https://example.com/issuer |
| JwtProviderConfig |
object |
The configuration of the JWT credential provider. |
|
| Issuer |
string |
JWT issuer。 |
https://test.issuer.com |
| JwksEndpoint |
string |
The JWKs endpoint URL. |
https://example123456.aliyunidaas.com/api/v2/auths_ngz2wj35ixxxdyat55nexxxxxx/oauth2/jwks |
| Expiration |
integer |
The validity period of the JWT. Unit: seconds. |
900 |
| ExpirationCleanupEnabled |
boolean |
Indicates whether JWT expiration cleanup is enabled. |
true |
| DerivedShortTokenEnabled |
boolean |
Indicates whether the JWT derived short token feature is enabled. |
false |
| AllowedTokenIssuers |
array |
The list of allowed JWT issuers. |
|
|
string |
The allowed JWT issuer. |
https://test.issuer.com |
Examples
Success response
JSON format
{
"RequestId": "0441BD79-92F3-53AA-8657-F8CE4A2B912A",
"CredentialProvider": {
"InstanceId": "idaas_ue2jvisn35ea5lmthk267xxxxx",
"CredentialProviderId": "atp_01kr2cmj5gxxx4fvmls2e93dxxxxx",
"CredentialProviderIdentifier": "test_example_identifier",
"CredentialProviderName": "test_example_name",
"CreateTime": 1649830225000,
"UpdateTime": 1649830225000,
"Description": "This is an example description",
"CredentialProviderType": "oauth",
"CredentialProviderCreationType": "user_custom",
"Status": "enabled",
"CredentialProviderConfig": {
"ProviderCredentialIds": [
"cred_mkv7xxxxd7i4u7zqtzev2mxxxx"
],
"OAuthProviderConfig": {
"ClientId": "client_id_example_xxx",
"TokenEndpoint": "https://example.com/token",
"Scope": "example:test_01 example:test_02",
"AuthorizationFlow": "m2m\n",
"AuthorizationEndpoint": "https://example.com/authorize\n",
"ProviderVendor": "custom",
"DiscoveryUrl": "https://example.com/.well-known/openid-configuration\n",
"SystemRedirectUri": "https://example.com/callback",
"PkceEnabled": true,
"PkceChallengeMethod": "S256\n",
"Issuer": "https://example.com/issuer\n"
},
"JwtProviderConfig": {
"Issuer": "https://test.issuer.com",
"JwksEndpoint": "https://example123456.aliyunidaas.com/api/v2/auths_ngz2wj35ixxxdyat55nexxxxxx/oauth2/jwks",
"Expiration": 900,
"ExpirationCleanupEnabled": true,
"DerivedShortTokenEnabled": false,
"AllowedTokenIssuers": [
"https://test.issuer.com"
]
}
}
}
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.