All Products
Search
Document Center

Identity as a Service:API overview

Last Updated:Sep 18, 2026

API standards and multilingual preset SDKs

The OpenAPI of this product (Eiam/2021-12-01) uses the RPC signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.

Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.

Custom signature scenarios

If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.

Account and security preparation

Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.

Region

API

Title

Description

ListRegions ListRegions Queries a list of supported Alibaba Cloud regions.

Instance management

API

Title

Description

GetServiceQuota Retrieve service quota Retrieves the service quota.
RenewFreeLicenseEndTime Renew a free edition instance Renews a Free Edition instance.
SetInstanceControlConfiguration Set instance control elements Sets the control elements of an instance.
SetInstanceGlobalizationConfig Set instance language and time zone information Sets the language and time zone information for an instance.
CreateInstanceTrialLicense Create a trial license Creates a trial License for an instance.
CheckInstanceModuleStatus Check whether an instance has a specific module feature Checks whether an instance has the feature of a specific module.
CheckInstanceForDelete Check instance deletion Checks whether an instance can be deleted.
GetInstanceGlobalizationConfig Retrieve instance language and time zone information Retrieves the language and time zone information of an instance.
GetInstanceControlConfiguration Query instance control items Queries instance control items.
GetInstanceModuleInfo Retrieve all module information under a first-level module Retrieves all module information under a first-level module.
GetInstanceQuota Retrieve a single quota type for an instance Retrieves the quota of a single type for an instance.
GetInstanceTrialStatus Get the trial status of an instance Retrieves the trial status of an instance.
CreateInstance Create an EIAM instance Creates an instance. All EIAM product capabilities are provided based on instances.
DeleteInstance Delete an EIAM instance Deletes an Employee Identity and Access Management (EIAM) instance that you no longer use.
UpdateInstanceDescription Update EIAM instance description Modifies the description of a specified EIAM instance.
ListInstances List EIAM instances Queries information about one or more EIAM instances.
GetInstance Query a single EIAM instance Queries the details of an EIAM instance.
EnableInitDomainAutoRedirect Enable automatic redirection from initialization domain to default domain for an EIAM instance Enables automatic redirection from the initialization domain to the default domain for an EIAM instance. After this feature is enabled, accessing the portal through the initialization domain will redirect to the default domain address.
DisableInitDomainAutoRedirect Disable automatic redirect from initialization domain to default domain for an EIAM instance Disables automatic redirect from the initialization domain to the default domain for an EIAM instance. After disabling, accessing the portal via the initialization domain will no longer redirect to the default domain.
GetInstanceLicense Query license information of an instance Queries the license information that is currently effective for an instance.

Domain name management

API

Title

Description

GetDomainDnsChallenge GetDomainDnsChallenge Queries the DNS Challenge record for a specified EIAM domain name. This record is used to verify domain ownership.
CreateDomain CreateDomain Creates a custom domain name for an EIAM (Entity and Identity Access Management) instance.
GetDomain GetDomain Retrieves information about a domain name for an EIAM instance.
SetDefaultDomain Set a specified EIAM instance domain name as the default domain name Sets a specified domain name of an EIAM instance as the default domain name.
ListDomains ListDomains Queries the domain names of an EIAM instance, including the default domain name and custom domain names.
DeleteDomain Delete a custom domain name of a specified EIAM instance Deletes a custom domain name of a specified Employee Identity and Access Management (EIAM) instance. Deletion of the instance initialization domain name or default domain name is rejected.
CreateDomainProxyToken Create a proxy token for an EIAM instance domain name Creates a proxy token for a domain name of an Employee Identity and Access Management (EIAM) instance.
ObtainDomainProxyToken Query proxy token information of an EIAM instance domain name Queries the proxy token of an EIAM instance domain name.
EnableDomainProxyToken Enable a domain proxy token for a specified EIAM instance Enables a domain proxy token for a specified EIAM instance domain name to verify domain security.
DisableDomainProxyToken Disable a domain proxy token for an EIAM instance Disables a specified domain proxy token for an EIAM instance. After the token is disabled, domain usage is affected.
ListDomainProxyTokens List Domain Proxy Tokens of an EIAM Instance Queries a list of domain proxy tokens of an EIAM instance.
DeleteDomainProxyToken Delete a proxy token for a specified EIAM instance domain name Deletes a proxy token for a specified domain name of an EIAM instance. Only proxy tokens in the disabled state can be deleted.
UpdateDomainIcpNumber UpdateDomainIcpNumber Updates the ICP filing number of a domain.
UpdateDomainBrand UpdateDomainBrand Updates the brand associated with a domain name.

Application management

API

Title

Description

Application basic information management Application basic information management
CreateApplication Create an EIAM application Creates an application resource in a specified EIAM instance.
DeleteApplication Delete an EIAM application Deletes an EIAM application resource.
UpdateApplicationDescription UpdateApplicationDescription Modifies the description of an Employee Identity and Access Management (EIAM) application.
EnableApplication EnableApplication Enables a disabled Employee Identity and Access Management (EIAM) application.
DisableApplication Disable an EIAM application Disables an application by changing its status from enabled to disabled, making all capabilities of the application unavailable.
GetApplication Query the details of an EIAM application Retrieves the details of a specified EIAM application.
ListApplications List EIAM applications Queries information about one or more EIAM applications by using paging.
GetApplicationTemplate Retrieve application template information Retrieves application template information.
UpdateApplicationInfo Update application basic information Updates the basic information of an application.
ListApplicationsForNetworkAccessEndpoint Retrieve application information under a network access endpoint Retrieves application information under a network access endpoint.
ListApplicationsForNetworkZone Retrieve applications associated with a network domain Retrieves the list of applications associated with a network domain.
ListApplicationsForGroup Query the list of applications accessible to an EIAM group Query the list of applications accessible to an EIAM group.
Application SSO configuration management Application SSO configuration management
EnableApplicationSso Enable SSO for an EIAM application Enables the SSO feature for an EIAM application.
DisableApplicationSso DisableApplicationSso Disables the single sign-on (SSO) feature for an Employee Identity and Access Management (EIAM) application. This way, employees cannot log on to the application by using SSO.
SetApplicationSsoConfig Set SSO configuration for an EIAM application Sets the single sign-on (SSO) configuration properties of an EIAM application.
GetApplicationSsoConfig Query SSO configuration of an EIAM application Queries the single sign-on (SSO) configuration properties of an EIAM application.
UpdateApplicationSsoFormParams UpdateApplicationSsoFormParams Updates the SSO parameters for an application template.
Application authorization management Application authorization management
AuthorizeApplicationToUsers Grant multiple EIAM accounts access to an application Grants multiple EIAM accounts access to an application in a batch.
AuthorizeApplicationToOrganizationalUnits AuthorizeApplicationToOrganizationalUnits Grants access to an application for multiple EIAM organizations in a batch operation.
AuthorizeApplicationToGroups Grant multiple EIAM groups access to an application Grants multiple EIAM groups access to an application in a batch.
RevokeApplicationFromUsers Revoke permissions of multiple EIAM accounts to access an application Revokes the permissions of multiple Enterprise Identity Access Management (EIAM) accounts to access an application in a batch.
RevokeApplicationFromOrganizationalUnits RevokeApplicationFromOrganizationalUnits Revokes application access from multiple EIAM organizations in a batch operation.
RevokeApplicationFromGroups Revoke the permissions of multiple EIAM groups to access an application Revokes the permissions of multiple Employee Identity and Access Management (EIAM) groups to access an application in a batch.
UpdateApplicationAuthorizationType UpdateApplicationAuthorizationType Modifies the authorization type of an Employee Identity and Access Management (EIAM) application.
ListUsersForApplication ListUsersForApplication Performs a paged query to list the accounts that have been granted access to an application. The response includes account IDs. To retrieve detailed information about an account, call the GetUser operation.
ListOrganizationalUnitsForApplication ListOrganizationalUnitsForApplication Performs a paged query to list the organizations that are granted access to an application. The response returns the IDs of the organizations. To obtain detailed information about a specific organization, call the GetOrganizationalUnit operation.
ListGroupsForApplication ListGroupsForApplication Performs a paged query to list the groups authorized to access an application. The response returns the group IDs. To obtain detailed information for a group, you can call the GetGroup operation.
ListApplicationsForUser ListApplicationsForUser Queries the applications that an EIAM account can access and returns a paginated list of application IDs. To retrieve detailed information about a specific application, call the GetApplication operation.
ListApplicationsForOrganizationalUnit Query applications accessible to an EIAM organizational unit Queries the list of applications accessible to an EIAM organizational unit by paging. The response includes application IDs. To obtain detailed application information, call the GetApplication operation.
Application federated credential management Application federated credential management
UpdateApplicationFederatedCredentialDescription UpdateApplicationFederatedCredentialDescription Updates the description of a federated credential for an application.
UpdateApplicationFederatedCredential Update an application federated identity credential Updates an application federated identity credential.
ListApplicationFederatedCredentials Query application federated identity credentials Queries the list of application federated identity credentials.
GetApplicationFederatedCredential Retrieve an application federated identity credential Retrieves an application federated identity credential.
EnableApplicationFederatedCredential EnableApplicationFederatedCredential Enables an application federated credential.
DisableApplicationFederatedCredential Disable an application federated identity credential Disables a federated identity credential for an application.
DeleteApplicationFederatedCredential Delete an application federated identity credential Deletes a federated identity credential of an application.
CreateApplicationFederatedCredential Create an application federated credential Creates an application federated credential.
Application clientSecret management Application clientSecret management
CreateApplicationClientSecret Create a client secret for an EIAM application Creates a client secret for an EIAM application. You can create a maximum of two client secrets for each EIAM application.
DeleteApplicationClientSecret Delete a client secret of an EIAM application Deletes a client secret of an EIAM application.
DisableApplicationClientSecret DisableApplicationClientSecret Disables a client key of an Employee Identity and Access Management (EIAM) application.
EnableApplicationClientSecret EnableApplicationClientSecret Enables the client key of an application in Identity as a Service (IDaaS) Employee Identity and Access Management (EIAM).
ListApplicationClientSecrets ListApplicationClientSecrets Queries all client secrets for an EIAM application. The key data in the response is masked. To obtain an unmasked key, call the ObtainApplicationClientSecret operation.
ObtainApplicationClientSecret Query a client secret of an EIAM application Retrieves the client secret of an EIAM application. The returned secret is not masked. To retrieve masked secrets, call the ListApplicationClientSecrets operation.
UpdateApplicationClientSecretExpirationTime Update the client secret validity period of an EIAM application Updates the expiration time of a specified ClientSecret for an application.
Application token management Application token management
UpdateApplicationTokenExpirationTime UpdateApplicationTokenExpirationTime Updates the expiration time of an application token.
EnableApplicationToken EnableApplicationToken Enables an application token.
DisableApplicationToken Disable an application token Disables an application token.
CreateApplicationToken Create an application token Creates an application token.
ListApplicationTokens Retrieve application token list Retrieves the list of application tokens.
ObtainApplicationToken Query a specified application token Queries a specified application token.
DeleteApplicationToken Delete an application token Deletes an ApplicationToken.
Application sub-account management Application sub-account management
AddApplicationAccountToUser Add an application account for a specified employee under the current application Adds an application account for a specified employee under the current application.
ListApplicationAccounts Query application accounts by paging Queries the application accounts of an application by paging.
ListApplicationAccountsForUser ListApplicationAccountsForUser Queries all accounts that belong to a specified user in an application.
RemoveApplicationAccountFromUser Delete an application account of a specified employee under the current application Deletes an application account of a specified employee under the current application.
Application API publication Application API publication
EnableApplicationApiInvoke EnableApplicationApiInvoke You can call the EnableApplicationApiInvoke operation to enable Developer API calls for an EIAM application.
DisableApplicationApiInvoke DisableApplicationApiInvoke Disables the Developer API feature for an Employee Identity and Access Management (EIAM) application.
SetApplicationGrantScope SetApplicationGrantScope Configures the permissions of the Developer API feature of an Employee Identity and Access Management (EIAM) application.
GetApplicationGrantScope Query the developer API authorization scope of an EIAM application Queries the Developer API authorization scope of an EIAM application.
Application account synchronization Application account synchronization
GetApplicationProvisioningUserPrimaryOrganizationalUnit GetApplicationProvisioningUserPrimaryOrganizationalUnit Queries the synchronization configuration of a specified application.
CheckApplicationProvisioningUserPrimaryOrganizationalUnit Check whether the primary organization for application synchronization is within the application synchronization scope Checks whether the primary organization for application synchronization is within the application synchronization scope.
SetApplicationProvisioningUserPrimaryOrganizationalUnit SetApplicationProvisioningUserPrimaryOrganizationalUnit Sets the primary organizational unit for an application's user provisioning.
DisableApplicationProvisioning DisableApplicationProvisioning Disables the account synchronization feature for an application in Identity as a Service (IDaaS) Employee Identity and Access Management (EIAM).
EnableApplicationProvisioning EnableApplicationProvisioning Enables the account synchronization feature for an application in Identity as a Service (IDaaS) Employee Identity and Access Management (EIAM).
SetApplicationProvisioningConfig Set account synchronization configuration for an EIAM application Sets the account synchronization configuration for an EIAM application.
SetApplicationProvisioningScope SetApplicationProvisioningScope Sets the account synchronization scope of applications in Identity as a Service (IDaaS) Employee IAM (EIAM). This scope is the same as the scope within which developers can call the DeveloperAPI to query and manage accounts.
GetApplicationProvisioningConfig GetApplicationProvisioningConfig Retrieves the account synchronization configuration for an Entity Identity and Access Management (EIAM) application.
GetApplicationProvisioningScope GetApplicationProvisioningScope Queries the account synchronization scope of applications in Identity as a Service (IDaaS) Employee IAM (EIAM). This scope is the same as the scope within which developers can call the DeveloperAPI to query and manage accounts.
Application advanced configuration Application advanced configuration
UpdateApplicationAdvancedConfig Modify application advanced configuration Modifies the advanced configuration of an application.
GetApplicationAdvancedConfig GetApplicationAdvancedConfig Retrieves the advanced configuration of an application.
Application role management Application role management
CreateApplicationRole Create an application role Creates an application role.
DeleteApplicationRole Delete an application role Deletes an application role.
UpdateApplicationRole UpdateApplicationRole Updates an application role.
UpdateApplicationRoleDescription Modify application role description Modifies the description of an application role.
GetApplicationRole Retrieve application role information Retrieves application role information.
ListApplicationRoles ListApplicationRoles Retrieves a list of application roles using a cursor.

M2M management

API

Title

Description

Basic capability management Basic capability management
EnableApplicationResourceServer EnableApplicationResourceServer Enables the ResourceServer feature for a specified application.
DisableApplicationResourceServer Disable the resourceServer capability of a specified application Disables the ResourceServer capability of a specified application.
EnableApplicationM2MClient EnableApplicationM2MClient Enables the machine-to-machine (M2M) client feature for an application. This allows the application to act as a caller (an OAuth client) to access resources.
DisableApplicationM2MClient DisableApplicationM2MClient Disables the machine-to-machine (M2M) client feature for an application. This feature enables an application to act as an OAuth client and make calls to access resources.
EnableResourceServerCustomSubject EnableResourceServerCustomSubject Enables the custom subject feature for a specified resource server. After this feature is enabled, the subject of an issued access token changes from to :. The `client.activeSubjectUrn` is set in the attribute mapping of the application's federated identity provider.
DisableResourceServerCustomSubject DisableResourceServerCustomSubject Disables the custom subject feature for a specified resource server.
SetApplicationResourceServerIdentifier SetApplicationResourceServerIdentifier Sets the unique identifier for a resource server. This identifier is used as the aud (audience) claim in a JSON Web Token (JWT) to specify the service that is intended to accept the token.
Authorization management Authorization management
Permission management Permission management
CreateResourceServerScope CreateResourceServerScope Creates a scope permission for a specified resource server.
UpdateResourceServerScope UpdateResourceServerScope Updates a scope permission for a specified resource server.
DeleteResourceServerScope Delete a scope permission under a specified resourceServer Deletes a scope permission under a specified ResourceServer.
GetResourceServerScope Query scope permissions under a specified resourceServer Queries the scope permissions under a specified ResourceServer.
ListResourceServerScopes Query scope permissions under a specified resourceServer Queries the list of scope permissions under a specified ResourceServer by using a cursor.
Machine authorization management Machine authorization management
AuthorizeResourceServerToClient Grant a specified resourceServer to a client application Grants a specified ResourceServer to a Client application.
RevokeResourceServerFromClient Revoke authorization granted by a resourceServer to a client application Revokes the authorization granted by a specified ResourceServer to a Client application.
AuthorizeResourceServerScopesToClient Grant scope permissions under a specified resourceServer to a client application Grants Scope permissions under a specified ResourceServer to a Client application.
RevokeResourceServerScopesFromClient Revoke scope permissions of a resourceServer from a client application Revokes the Scope permissions of a specified ResourceServer from a Client application.
User authorization management User authorization management
AuthorizeResourceServerScopesToUser Grant scope permissions under a specified resourceServer to an account Grants Scope permissions under a specified ResourceServer to an account.
RevokeResourceServerScopesFromUser Revoke scope permissions under a specified resourceServer from an account Revokes the Scope permissions under a specified ResourceServer from an account.
AuthorizeResourceServerScopesToOrganizationalUnit Grant scope permissions under a specified resourceServer to an organizational unit Grants scope permissions under a specified ResourceServer to an organizational unit.
RevokeResourceServerScopesFromOrganizationalUnit Revoke scope permissions under a specified resourceServer from an organizational unit Revokes the authorization of Scope permissions under a specified ResourceServer from an organizational unit.
AuthorizeResourceServerScopesToGroup Grant scope permissions under a specified resourceServer to a group Grants Scope permissions under a specified ResourceServer to a group.
RevokeResourceServerScopesFromGroup Revoke scope permissions of a specified resourceServer from a group Revokes the authorization of Scope permissions under a specified ResourceServer from a group.
ListUsersForResourceServer ListUsersForResourceServer List the scope permissions granted by a Resource Server to user accounts using cursor-based pagination.
ListResourceServersForUser Query resourceServer and scope permissions granted to the current account Queries the list of ResourceServer and Scope permissions granted to the current account by using a cursor-based approach.
ListOrganizationalUnitsForResourceServer ListOrganizationalUnitsForResourceServer Retrieves a cursor-paginated list of scopes that the current resource server has granted to an organization.
ListGroupsForResourceServer ListGroupsForResourceServer Lists the scopes authorized for groups on a specified resource server. This operation supports cursor-based pagination.
Application clientPublicKey management Application clientPublicKey management
CreateClientPublicKey Create an application clientPublicKey Creates a ClientPublicKey for an application. When an M2M client uses the PRIVATE_KEY_JWT method to request the token endpoint, this public key is used by the M2M authorization server to verify the assertion carried in the client's token endpoint request.
DeleteClientPublicKey Delete a specified application clientPublicKey Deletes a specified application ClientPublicKey.
EnableClientPublicKey Enable a specified application clientPublicKey Enables a specified application ClientPublicKey.
DisableClientPublicKey Disable a specified application clientPublicKey Disables a specified application ClientPublicKey.
SetPrimaryClientPublicKey SetPrimaryClientPublicKey Sets the specified client public key as the primary key for an application.
GetClientPublicKey Query the clientPublicKey of a specified application Queries the ClientPublicKey of a specified application.
ListClientPublicKeys ListClientPublicKeys Lists the client public keys for a specified application using a cursor.

Federated trust source management

API

Title

Description

DeleteFederatedCredentialProvider DeleteFederatedCredentialProvider Deletes a federated credential provider.
UpdateFederatedCredentialProviderDescription Update the description of a federated trust source Updates the description of a federated trust source.
UpdateFederatedCredentialProvider Update a federated trust source Updates a federated trust source.
ListFederatedCredentialProviders List federated trust sources Queries a list of federated trust sources.
ListApplicationFederatedCredentialsForProvider Query application federated credentials by federated trust source ID Queries the list of application federated credentials by federated trust source ID.
GetFederatedCredentialProvider GetFederatedCredentialProvider Retrieve a federated credential provider.
EnableFederatedCredentialProvider EnableFederatedCredentialProvider Enables a federated credential provider.
DisableFederatedCredentialProvider DisableFederatedCredentialProvider Disables a federated credential provider.
CreateFederatedCredentialProvider Create a federated trust source Creates a federated trust source.

Account management

API

Title

Description

DeleteUsers DeleteUsers Deletes multiple accounts in a batch.
Third-party logon account management Third-party logon account management
BindUserAuthnSourceMapping Associate a third-party logon account Associates a third-party logon account.
UnbindUserAuthnSourceMapping UnbindUserAuthnSourceMapping Unbinds a third-party logon account from a user.
ListUserAuthnSourceMappings Query third-party account bindings Queries the binding relationships of third-party login accounts.
CreateUser Create an EIAM account Creates an EIAM account in a specified EIAM instance.
AddUserToOrganizationalUnits Add an EIAM account to multiple EIAM organizations Adds a specified EIAM account to multiple EIAM organizations. If the account already exists in an organization, the operation returns a success response directly.
DeleteUser Delete an EIAM account Deletes a specified EIAM account and purges all information associated with the account.
RemoveUserFromOrganizationalUnits RemoveUserFromOrganizationalUnits Removes an Employee Identity and Access Management (EIAM) account from multiple EIAM organizations of Identity as a Service (IDaaS). You cannot remove an account from a primary organization.
UpdateUser Update the basic information of an EIAM account Updates the basic information of an EIAM account.
UpdateUserPassword UpdateUserPassword Updates the password information of an Employee Identity and Access Management (EIAM) account of Identity as a Service (IDaaS). The password must meet the requirements of the password policies that are configured in the IDaaS console.
UpdateUserDescription UpdateUserDescription Updates a user's description.
DisableUser Disable an EIAM account Sets an account status to disabled. If the account is already disabled, the operation returns success directly.
EnableUser Enable an EIAM account Sets an account to the enabled state.
UnlockUser Unlock an EIAM account Unlocks a locked EIAM account.
SetUserPrimaryOrganizationalUnit SetUserPrimaryOrganizationalUnit Updates the primary organizational unit to which an Identity as a Service (IDaaS) Employee Identity and Access Management (EIAM) account belongs. This account will be removed from the previous primary organizational unit and added to the new primary organization.
GetUser Query EIAM account information Queries the details of an EIAM account.
ListUsers List EIAM account information Queries EIAM account information by using paging.

Organization management

API

Title

Description

CreateOrganizationalUnit Create an EIAM organization Creates an EIAM organization under a specified organization.
DeleteOrganizationalUnit Delete an EIAM organizational unit Deletes a specified EIAM organizational unit. The deletion fails if the organizational unit contains EIAM accounts or child organizational units.
DeleteOrganizationalUnitChildren Delete an organization and all its accounts and sub-organizations Deletes all data of a specified organization. This operation can force delete all accounts and sub-organizations under the specified organization.
UpdateOrganizationalUnit UpdateOrganizationalUnit Updates the basic information about an Employee Identity and Access Management (EIAM) organization. The basic information about the organization is not updated by default if no parameter is specified.
UpdateOrganizationalUnitDescription UpdateOrganizationalUnitDescription Modifies the description of an Employee Identity and Access Management (EIAM) organization.
UpdateOrganizationalUnitParentId UpdateOrganizationalUnitParentId Updates the parent organization ID of an organization in Identity as a Service (IDaaS) Employee Identity and Access Management (EIAM). In this case, the organization is moved from a parent node to a new node.
GetRootOrganizationalUnit Query EIAM root organizational unit information Queries the root organizational unit information of EIAM.
GetOrganizationalUnit Query an EIAM organizational unit Queries the information of an EIAM organizational unit.
ListOrganizationalUnits ListOrganizationalUnits Performs a paged query for EIAM organizational units.
ListOrganizationalUnitParents List all ancestor organizations of an EIAM organization Queries all ancestor organizations of a specified EIAM organization. The organizations in the result list are sorted in hierarchical order from the top level to the bottom level.

Account group management

API

Title

Description

CreateGroup Create an EIAM account group Create an EIAM account group.
AddUsersToGroup Add multiple EIAM accounts to a specified EIAM account group Adds multiple Employee Identity and Access Management (EIAM) accounts to a specified EIAM account group.
DeleteGroup Delete an EIAM account group Delete an EIAM account group.
RemoveUsersFromGroup RemoveUsersFromGroup Removes Employee Identity and Access Management (EIAM) accounts from an EIAM group of Identity as a Service (IDaaS).
UpdateGroup UpdateGroup Updates the information about an account group in Identity as a Service (IDaaS) Employee Identity and Access Management (EIAM). If the information is empty, the information is not updated by default.
UpdateGroupDescription UpdateGroupDescription Updates the description of an Identity as a Service (IDaaS) Employee Identity and Access Management (EIAM) account group.
GetGroup Query an EIAM account group Queries the details of an EIAM account group.
ListGroups List EIAM Account Group Information List EIAM account groups.
ListUsersForGroup ListUsersForGroup Lists the users in a specified EIAM account group.
ListGroupsForUser List account groups of an EIAM account Queries the list of account groups to which a specified EIAM account belongs.

Identity provider management

API

Title

Description

ExecIdentityProviderMetadataUrlResolution ExecIdentityProviderMetadataUrlResolution Resolves the metadata for an identity provider.
SetIdentityProviderAuthnConfiguration ModifyAuthenticationInfo Modify Authentication Information
SetIdentityProviderUdPushConfiguration SetIdentityProviderUdPushConfiguration Modifies the push configuration for an identity provider (IdP).
GetIdentityProviderAdvancedConfiguration GetIdentityProviderAdvancedConfiguration Retrieves advanced configuration information.
GetIdentityProviderStatusCheckJob Retrieve an idP status check job Retrieves an IdP status check job.
GetIdentityProviderUdPushConfiguration GetIdentityProviderUdPushConfiguration Retrieve the IdP outbound synchronization configuration.
EnableIdentityProviderAdvancedAbility EnableIdentityProviderAdvancedAbility Enables advanced configuration.
CreateIdentityProviderStatusCheckJob CreateIdentityProviderStatusCheckJob Creates a status check job for an identity provider.
DisableIdentityProviderAdvancedAbility DisableIdentityProviderAdvancedAbility Disables the advanced configuration.
CreateIdentityProvider Create an identity provider Creates an identity provider.
DeleteIdentityProvider Delete an identity provider Deletes an identity provider.
UpdateIdentityProvider Update identity provider basic configuration Updates the basic configuration of an identity provider.
GetIdentityProvider Retrieve an identity provider Retrieves an identity provider.
ListIdentityProviders List Identity Providers Query the list of identity providers.
EnableIdentityProviderUdPull Enable Identity Provider Inbound Synchronization Enables the inbound synchronization feature for an identity provider.
DisableIdentityProviderUdPull Disable Identity Provider Inbound Synchronization Disables the inbound synchronization feature of an identity provider.
SetIdentityProviderUdPullConfiguration Set idP inbound synchronization configuration Modifies the inbound synchronization configuration of an Identity Provider (IdP).
GetIdentityProviderUdPullConfiguration Retrieve idP inbound synchronization configuration Retrieves the inbound synchronization configuration of an Identity Provider (IdP).
ListIdentityProvidersForNetworkAccessEndpoint ListIdentityProvidersForNetworkAccessEndpoint Retrieves information about Identity Providers (IdPs) for a network endpoint.
EnableIdentityProviderAuthn Enable authentication Enables authentication.
DisableIdentityProviderAuthn Disable authentication Disables authentication.

Password policy

API

Title

Description

SetForgetPasswordConfiguration Set EIAM forgot password policy Sets the forgot password policy for an EIAM instance.
SetPasswordInitializationConfiguration Set EIAM password initialization policy Sets the password initialization policy for a specified EIAM instance.
SetPasswordHistoryConfiguration Set EIAM password history policy Sets the password history policy for a specified Enterprise Identity and Access Management (EIAM) instance.
SetPasswordExpirationConfiguration Set EIAM password expiration policy Sets the password expiration policy for a specified Enterprise Identity and Access Management (EIAM) instance.
SetPasswordComplexityConfiguration SetPasswordComplexityConfiguration Sets the password complexity policy for a specified EIAM instance.
GetForgetPasswordConfiguration GetForgetPasswordConfiguration Queries the forgot password policy of a specified EIAM instance.
GetPasswordInitializationConfiguration Query EIAM password initialization policy Queries the password initialization policy of Employee Identity and Access Management (EIAM).
GetPasswordHistoryConfiguration Query EIAM password history policy Queries the password history policy of a specified EIAM instance.
GetPasswordExpirationConfiguration Query EIAM password expiration policy Queries the password expiration policy of a specified EIAM instance.
GetPasswordComplexityConfiguration GetPasswordComplexityConfiguration Retrieves the password complexity policy for a specified EIAM instance.

Conditional access policy

API

Title

Description

CreateConditionalAccessPolicy CreateConditionalAccessPolicy Creates a conditional access policy.
DeleteConditionalAccessPolicy Delete a conditional access policy Deletes a conditional access policy.
DisableConditionalAccessPolicy Disable a conditional access policy Disables a conditional access policy.
EnableConditionalAccessPolicy Enable a conditional access policy Enables a conditional access policy.
GetConditionalAccessPolicy Query Conditional Access Policy Get a conditional access policy.
ListConditionalAccessPolicies ListConditionalAccessPolicies List conditional access policies.
ListConditionalAccessPoliciesForNetworkZone List conditional access policies associated with a network zone Retrieves the list of conditional access policies associated with a network zone.
UpdateConditionalAccessPolicy Update a conditional access policy Updates a conditional access policy.
UpdateConditionalAccessPolicyDescription Update conditional access policy description Updates the description of a conditional access policy.
ListConditionalAccessPoliciesForUser List conditional access policies associated with a user Retrieves the list of conditional access policies associated with a user.
ListConditionalAccessPoliciesForApplication List Conditional Access Policies for Application List conditional access policies associated with an application.

Synchronization

API

Title

Description

ListSynchronizationJobs List Synchronization Jobs Query the list of synchronization job details.
RunSynchronizationJob Run a synchronization task Runs a synchronization task. This operation creates a new synchronization task and immediately executes it.
GetSynchronizationJob GetSynchronizationJob Obtains the information about a single synchronization job.

Branding

API

Title

Description

CreateBrand Create a brand Creates a brand.
GetBrand Query brand information Retrieves the details of a brand.
EnableBrand Enable a brand Enables a brand.
DisableBrand Disable a brand Disables a brand.
UpdateBrand Update a brand Modifies a brand.
DeleteBrand Delete Brand Delete Brand
ListBrands Query brand list Retrieves a list of brands.
SetLoginRedirectApplicationForBrand SetLoginRedirectApplicationForBrand Set login redirect application for brand
GetLoginRedirectApplicationForBrand Get brand logon redirect application Sets the post-logon redirect application for a brand.

Custom terms

API

Title

Description

CreateCustomPrivacyPolicy CreateCustomPrivacyPolicy You can create custom terms.
GetCustomPrivacyPolicy Retrieve a custom privacy policy Retrieves a custom privacy policy.
EnableCustomPrivacyPolicy Enable a custom clause Enables a custom clause.
DisableCustomPrivacyPolicy Disable a custom term Disables a custom term.
UpdateCustomPrivacyPolicy UpdateCustomPrivacyPolicy Updates a custom privacy policy.
DeleteCustomPrivacyPolicy Delete a custom clause Deletes a custom clause.
ListCustomPrivacyPolicies Query custom terms list Queries the list of custom terms.
AddCustomPrivacyPoliciesToBrand Add custom terms to a brand Adds terms to a brand.
RemoveCustomPrivacyPoliciesFromBrand Remove custom terms from a brand Removes custom terms associated with a brand.
ListCustomPrivacyPoliciesForBrand ListCustomPrivacyPoliciesForBrand Retrieves the resources of brand-linked instances.

Network endpoint

API

Title

Description

CreateNetworkAccessEndpoint Create a network access endpoint Creates a network access endpoint.
DeleteNetworkAccessEndpoint Delete a dedicated network access endpoint Deletes a dedicated network access endpoint.
UpdateNetworkAccessEndpointName UpdateNetworkAccessEndpointName Modifies the name of a private network access endpoint.
ListNetworkAccessEndpointAvailableRegions ListNetworkAccessEndpointAvailableRegions Lists the available regions for creating network access endpoints in IDaaS EIAM.
ListNetworkAccessEndpointAvailableZones Query zones supported by network endpoints Queries the list of zones that support the creation of network endpoints in a specified region for IDaaS EIAM.
GetNetworkAccessEndpoint Query a network access endpoint Queries the information about a specified network access endpoint.
ListNetworkAccessEndpoints List network access endpoints Queries the list of network access endpoints under an IDaaS EIAM instance.
ListNetworkAccessPaths Query access paths of a network access endpoint Queries the list of access paths under a specified network access endpoint.

Network zone

API

Title

Description

CreateNetworkZone CreateNetworkZone Creates a network zone object.
DeleteNetworkZone Delete a network zone object Deletes a network zone object.
UpdateNetworkZone Update a network zone object Updates a network zone object.
UpdateNetworkZoneDescription UpdateNetworkZoneDescription Updates the description of a network zone.
ListNetworkZones Query network zone objects Queries the list of network zone objects.
GetNetworkZone Retrieve a network zone object Retrieves a network zone object.

Authentication source

API

Title

Description

EnableInternalAuthenticationSource EnableInternalAuthenticationSource Enables an internal authentication source.
DisableInternalAuthenticationSource DisableInternalAuthenticationSource Disables an internal authentication source.

Authenticator

API

Title

Description

SetWebAuthnConfiguration SetWebAuthnConfiguration Sets the WebAuthn configuration.
UnbindTotpAuthenticator UnbindTotpAuthenticator Detaches the TOTP authenticator for a specified user.
DeleteWebAuthnAuthenticator DeleteWebAuthnAuthenticator Deletes the specified WebAuthn authenticator.

Cloud account

API

Title

Description

ListCloudAccounts List cloud accounts Queries information about one or more cloud accounts by using paging.
GetCloudAccount Query cloud account information Queries the resource information of a cloud account.
CreateCloudAccount Create a cloud account Creates a cloud account resource under a specified EIAM instance.
UpdateCloudAccount UpdateCloudAccount Updates the basic information of an Alibaba Cloud account.
UpdateCloudAccountDescription UpdateCloudAccountDescription Updates the description of an Alibaba Cloud account.
DeleteCloudAccount DeleteCloudAccount Deletes an Alibaba Cloud account resource.

Cloud role

API

Title

Description

ListCloudAccountRoles List cloud roles Queries information about one or more cloud roles by using paging.
GetCloudAccountRole Query a cloud role Queries the resource information of a cloud role.
CreateCloudAccountRole Create a cloud role Creates a cloud role resource under the specified cloud account resource.
DisableCloudAccountRole DisableCloudAccountRole Disables a cloud role for a specified Alibaba Cloud account.
EnableCloudAccountRole EnableCloudAccountRole Enables a cloud role for a specified Alibaba Cloud account.
UpdateCloudAccountRoleDescription UpdateCloudAccountRoleDescription Updates the description of a cloud role.
DeleteCloudAccountRole DeleteCloudAccountRole Deletes a cloud role from a specified Alibaba Cloud account.

Credential

API

Title

Description

ListCredentials List credentials Queries the information of one or more credentials by using paging.
GetCredential Query credential information Queries the information about a credential resource.
ObtainCredential Query a credential with sensitive information Queries a credential resource that contains sensitive information.
CreateCredential Create a credential Creates a credential resource in a specified EIAM instance.
DisableCredential DisableCredential Disables a credential resource.
EnableCredential Enable a credential Enables a credential resource.
UpdateCredential UpdateCredential Update basic information for a credential.
UpdateCredentialDescription Update the description of a credential Updates the description of a credential.
DeleteCredential DeleteCredential Deletes a credential resource.

Credential provider

API

Title

Description

CreateCredentialProvider Create a credential provider Creates a credential provider.
DeleteCredentialProvider Delete a credential provider Deletes a credential provider.
DisableCredentialProvider DisableCredentialProvider Disables a credential provider.
EnableCredentialProvider EnableCredentialProvider Enables a credential provider.
GetCredentialProvider Query credential provider details Queries the details of a credential provider.
ListCredentialProviders List credential providers Lists credential providers.
UpdateCredentialProvider Update a credential provider Updates a credential provider.
UpdateCredentialProviderDescription UpdateCredentialProviderDescription Update the description of a credential provider.

Data permission management

API

Title

Description

CreateAuthorizationRule Create an authorization rule Creates an authorization rule.
UpdateAuthorizationRule UpdateAuthorizationRule Updates the basic properties of an authorization rule.
UpdateAuthorizationRuleDescription Update the description of an authorization rule Updates the description of an authorization rule.
EnableAuthorizationRule Enable an authorization rule Enables an authorization rule.
DisableAuthorizationRule Disable an authorization rule Disables an authorization rule.
DeleteAuthorizationRule Delete an authorization rule Deletes an authorization rule. The authorization rule can be deleted only when it is in the disabled state.
GetAuthorizationRule Query an authorization rule Queries the information about an authorization rule.
ListAuthorizationRules List authorization rules Lists authorization rules.
AddUserToAuthorizationRule Add an account to an authorization rule Adds an account to an authorization rule.
UpdateAuthorizationRuleUserAttachment Update relationship properties between an authorization rule and an account Updates the relationship properties between an authorization rule and an account.
RemoveUserFromAuthorizationRule Remove an account from an authorization rule Removes an account from an authorization rule.
ListAuthorizationRulesForUser List authorization rules associated with an account Lists the authorization rules associated with an account.
ListUsersForAuthorizationRule List accounts associated with an authorization rule Lists the accounts associated with an authorization rule.
AddGroupToAuthorizationRule Add a group to an authorization rule Adds a group to an authorization rule.
UpdateAuthorizationRuleGroupAttachment Update relationship properties between an authorization rule and a group Updates the relationship properties between an authorization rule and a group.
RemoveGroupFromAuthorizationRule Remove a group from an authorization rule Removes a group from an authorization rule.
ListAuthorizationRulesForGroup List authorization rules associated with a group Lists the authorization rules associated with a group.
ListGroupsForAuthorizationRule ListGroupsForAuthorizationRule Lists the groups associated with an authorization rule.
AddApplicationToAuthorizationRule AddApplicationToAuthorizationRule Adds an application to an authorization rule.
UpdateAuthorizationRuleApplicationAttachment UpdateAuthorizationRuleApplicationAttachment Updates the properties of the relationship between an authorization rule and an application.
RemoveApplicationFromAuthorizationRule Remove an application from an authorization rule Removes an application from an authorization rule.
ListApplicationsForAuthorizationRule List applications associated with an authorization rule Lists the applications associated with an authorization rule.
ListAuthorizationRulesForApplication List authorization rules associated with an application Lists the authorization rules associated with an application.
CreateAuthorizationResource Create an authorization resource Creates an authorization resource.
DeleteAuthorizationResource Delete an authorized resource Deletes an authorized resource.
GetAuthorizationResource Query an authorization resource Queries the information about an authorization resource.
ListAuthorizationResources List authorized resource information Lists authorized resource information.

Import file

API

Title

Description

GenerateUploadAuth Get Upload Authentication Get Upload Authentication
GenerateFileImportTemplate Generate file import template Generates a file import template.
GenerateDownloadUrlForSynchronizationJob Generate file import result download URL Generates a download URL for file import results.

OAuth Token

API

Title

Description

GenerateOauthToken Generate oAuth token Obtains an access token for accessing a resource server by using a specified application as the client identity.

Extended attribute

API

Title

Description

GetCustomField Retrieve extended field information Retrieves the information about an extended field.
EnableCustomField Enable a field Enables a field.
DisableCustomField Disable a field Disables a field.
DeleteCustomField Delete an extended character field Deletes an extended character field.
CreateCustomField Create an extended field Creates an extended field.

Event

API

Title

Description

ListEventTypes Query event list Queries the event list.
ListActionTrackEventTypes ListActionTrackEventTypes View the list of invocation events.

Others

API

Title

Description

ListEiamInstances List iDaaS instances Queries the list of EIAM 2.0 and EIAM 1.0 instances.
ListEiamRegions ListEiamRegions Lists the regions available for EIAM 1.0 and EIAM 2.0.
ListApplicationSupportedProvisionProtocolTypes List account synchronization types supported by an application Queries the list of account synchronization types supported by an application.
GenerateWebAuthnAuthenticatorRegistrationUrl GenerateWebAuthnAuthenticatorRegistrationUrl Generates a WebAuthn authenticator registration URL.
GetAuthorizationServer Get authorization server information Queries an authorization server.
UpdateAuthorizationServerDescription Update authorization server description Updates the description of an authorization server.
ListAuthorizationServers Query authorization servers Retrieves a list of all authorization servers under an instance.
UpdateAuthorizationServer Update an authorization server Updates the configuration of an authorization server.
CreateTrustedOrigin Create a browser trusted origin Creates a trusted origin.
DisableTrustedOrigin Disable a trusted origin Disables a trusted origin in a specified EIAM instance.
EnableTrustedOrigin Enable a trusted origin Enables a trusted origin in a specified EIAM instance.
ExecuteInstanceFailover Instance disaster recovery switchover Performs a disaster recovery switchover.
GetTrustedOrigin Query a trusted origin Queries a trusted origin in a specified EIAM instance.