Updates the basic configuration of an identity provider.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
eiam:UpdateIdentityProvider |
update |
*IdentityProvider
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| InstanceId |
string |
Yes |
The instance ID. |
idaas_ue2jvisn35ea5lmthk267xxxxx |
| IdentityProviderId |
string |
Yes |
The identity provider ID. |
idp_my664lwkhpicbyzirog3xxxxx |
| IdentityProviderName |
string |
No |
The identity provider name. |
test |
| LdapConfig |
object |
No |
The AD/LDAP basic information. |
|
| AdministratorPassword |
string |
No |
The administrator password. |
xxxxxx |
| AdministratorUsername |
string |
No |
The administrator account. |
DC=example,DC=com |
| CertificateFingerprintStatus |
string |
No |
Specifies whether to verify the certificate fingerprint. Valid values:
|
enabled |
| CertificateFingerprints |
array |
No |
The list of certificate fingerprints. |
|
|
string |
No |
The certificate fingerprint in public key SHA-256 format. |
ahshssakjdhaksjdhasjdha |
|
| LdapProtocol |
string |
No |
The communication protocol. |
ldap |
| LdapServerHost |
string |
No |
The server address. |
123.xx.xx.89 |
| LdapServerPort |
integer |
No |
The port number. |
636 |
| StartTlsStatus |
string |
No |
Specifies whether StartTLS is enabled. Valid values:
|
enabled |
| DingtalkAppConfig |
object |
No |
The DingTalk configuration basic information. |
|
| AppKey |
string |
No |
The AppKey of the DingTalk first-party application. |
49nyeaqumk7f |
| AppSecret |
string |
No |
The AppSecret of the DingTalk first-party application. |
86nozWFL2CxgwnhKiXaG8dN4keLPkUNc5xxxx |
| DingtalkLoginVersion |
string |
No |
The DingTalk QR code login version. |
new_version |
| EncryptKey |
string |
No |
The EncryptKey of the DingTalk application. |
VkdWw91mdkrjVFr3ObNwefap21dfxxxx |
| VerificationToken |
string |
No |
The VerificationToken of the DingTalk application. |
myDingApp_VerifyTokenxxxxx |
| WeComConfig |
object |
No |
The WeCom basic information. |
|
| AgentId |
string |
No |
The AgentId of the WeCom self-built application. |
1237403 |
| AuthorizeCallbackDomain |
string |
No |
The authorization callback domain. |
https://xxx.aliyunidaas.com/xxxxx |
| ContactSecret |
string |
No |
The WeCom contacts secret. |
mPLLiWv-_9witxxxEJCpk1xkF5hOgBzpRt4kBkxxx |
| CorpSecret |
string |
No |
The CorpSecret of the WeCom self-built application. |
CSEHDddddddxxxxuxkJEHPveWRXBGqVqRsxxxx |
| TrustableDomain |
string |
No |
The trusted domain. |
https://xxx.aliyunidaas.com |
| OidcConfig |
object |
No |
The OIDC-related configuration. |
|
| AuthnParam |
object |
No |
The OIDC client authentication configuration. |
|
| AuthnMethod |
string |
No |
The OIDC authentication method. Valid values:
|
client_secret_post |
| ClientSecret |
string |
No |
The OIDC client secret. |
CSEHDddddddxxxxuxkJEHPveWRXBGqVqRsxxxx |
| EndpointConfig |
object |
No |
The OIDC endpoint configuration. |
|
| AuthorizationEndpoint |
string |
No |
The OIDC authorization endpoint. |
https://example.com/oauth/authorize |
| Issuer |
string |
No |
The OIDC issuer information. |
https://example.com/oauth |
| JwksUri |
string |
No |
The OIDC JWKS URI. |
https://example.com/oauth/jwks |
| TokenEndpoint |
string |
No |
The OIDC token endpoint. |
https://example.com/oauth/token |
| UserinfoEndpoint |
string |
No |
The OIDC UserInfo endpoint. |
https://example.com/oauth/userinfo |
| GrantScopes |
array |
No |
The list of OIDC grant scopes. |
openid |
|
string |
No |
The OIDC grant scope. |
ou_asdaq1addsxzdq1xxxx |
|
| GrantType |
string |
No |
The OIDC grant type. |
authorization_code |
| PkceChallengeMethod |
string |
No |
The PKCE algorithm. Valid values:
|
S256 |
| PkceRequired |
boolean |
No |
Specifies whether to use PKCE in the AuthorizationCode grant mode. |
true |
| NetworkAccessEndpointId |
string |
No |
The network endpoint ID. |
nae_examplexxxx |
| LarkConfig |
object |
No |
The Lark configuration information. |
|
| AppId |
string |
No |
The AppId of the Lark application. |
cli_xxxx |
| AppSecret |
string |
No |
The AppSecret of the Lark application. |
KiiLzh5Dueh4wbLxxxx |
| EncryptKey |
string |
No |
The encryptKey of the custom Lark application. |
VkdWw91mdkrjVFr3ObNwefap21dfbZbKxxxx |
| VerificationToken |
string |
No |
The verificationToken of the custom Lark application. |
feishuVerifyTokenxxxxx |
| LogoUrl |
string |
No |
The URL of the application logo. |
idaas-image://idaas_23aqr2ye554csg33dqpch5exxxx/tmp/d17d9adc-a943-45e7-ba0c-2838dddea678xxxx |
| ClientToken |
string |
No |
The client token that is used to ensure the idempotence of the request. The value is generated by the client and must be unique across different requests. |
client-examplexxx |
| SamlConfig |
object |
No |
The SAML IdP configuration. |
|
| BindingMethod |
string |
No |
The binding type. Valid values:
|
HTTP-REDIRECT |
| Certificates |
array<object> |
No |
The list of IdP certificates. |
|
|
object |
No |
The certificate information. |
||
| Content |
string |
No |
The content of the certificate. |
-----BEGIN CERTIFICATE----- MIIC0jCCAbqgAwIBAgIQXXXXX-----END CERTIFICATE----- |
| IdPEntityId |
string |
No |
The EntityId of the IdP. |
http://dc.test.com/adfs/services/trust |
| IdPSsoUrl |
string |
No |
The logon URL of the IdP. |
https://dc.test.com/adfs/ls/ |
| MaxClockSkew |
integer |
No |
The maximum clock skew. |
180 |
| RequireRequestSigned |
boolean |
No |
Specifies whether the request must be signed. |
true |
| WantAssertionsSigned |
boolean |
No |
Specifies whether the external IdP is required to sign the Assertion. |
true |
| WantResponseSigned |
boolean |
No |
Specifies whether the external IdP is required to sign the Response. |
false |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID. |
0441BD79-92F3-53AA-8657-F8CE4A2B912A |
Examples
Success response
JSON format
{
"RequestId": "0441BD79-92F3-53AA-8657-F8CE4A2B912A"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | InvalidParameter.OidcIssuer | OidcIssuer format check failed, it must be an address that starts with http or https. | OidcIssuer format check failed, it must be an address that starts with http or https. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.