All Products
Search
Document Center

Identity as a Service:UpdateIdentityProvider

Last Updated:Sep 10, 2026

Updates the basic configuration of an identity provider.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

eiam:UpdateIdentityProvider

update

*IdentityProvider

acs:eiam:{#regionId}:{#accountId}:instance/{#InstanceId}/identityprovider/{#IdentityProviderId}

None None

Request parameters

Parameter

Type

Required

Description

Example

InstanceId

string

Yes

The instance ID.

idaas_ue2jvisn35ea5lmthk267xxxxx

IdentityProviderId

string

Yes

The identity provider ID.

idp_my664lwkhpicbyzirog3xxxxx

IdentityProviderName

string

No

The identity provider name.

test

LdapConfig

object

No

The AD/LDAP basic information.

AdministratorPassword

string

No

The administrator password.

xxxxxx

AdministratorUsername

string

No

The administrator account.

DC=example,DC=com

CertificateFingerprintStatus

string

No

Specifies whether to verify the certificate fingerprint. Valid values:

  • disabled: Disabled.

  • enabled: Enabled.

enabled

CertificateFingerprints

array

No

The list of certificate fingerprints.

string

No

The certificate fingerprint in public key SHA-256 format.

ahshssakjdhaksjdhasjdha

LdapProtocol

string

No

The communication protocol.

ldap

LdapServerHost

string

No

The server address.

123.xx.xx.89

LdapServerPort

integer

No

The port number.

636

StartTlsStatus

string

No

Specifies whether StartTLS is enabled. Valid values:

  • disabled: Disabled.

  • enabled: Enabled.

enabled

DingtalkAppConfig

object

No

The DingTalk configuration basic information.

AppKey

string

No

The AppKey of the DingTalk first-party application.

49nyeaqumk7f

AppSecret

string

No

The AppSecret of the DingTalk first-party application.

86nozWFL2CxgwnhKiXaG8dN4keLPkUNc5xxxx

DingtalkLoginVersion

string

No

The DingTalk QR code login version.

new_version

EncryptKey

string

No

The EncryptKey of the DingTalk application.

VkdWw91mdkrjVFr3ObNwefap21dfxxxx

VerificationToken

string

No

The VerificationToken of the DingTalk application.

myDingApp_VerifyTokenxxxxx

WeComConfig

object

No

The WeCom basic information.

AgentId

string

No

The AgentId of the WeCom self-built application.

1237403

AuthorizeCallbackDomain

string

No

The authorization callback domain.

https://xxx.aliyunidaas.com/xxxxx

ContactSecret

string

No

The WeCom contacts secret.

mPLLiWv-_9witxxxEJCpk1xkF5hOgBzpRt4kBkxxx

CorpSecret

string

No

The CorpSecret of the WeCom self-built application.

CSEHDddddddxxxxuxkJEHPveWRXBGqVqRsxxxx

TrustableDomain

string

No

The trusted domain.

https://xxx.aliyunidaas.com

OidcConfig

object

No

The OIDC-related configuration.

AuthnParam

object

No

The OIDC client authentication configuration.

AuthnMethod

string

No

The OIDC authentication method. Valid values:

  • client_secret_basic

  • client_secret_post

client_secret_post

ClientSecret

string

No

The OIDC client secret.

CSEHDddddddxxxxuxkJEHPveWRXBGqVqRsxxxx

EndpointConfig

object

No

The OIDC endpoint configuration.

AuthorizationEndpoint

string

No

The OIDC authorization endpoint.

https://example.com/oauth/authorize

Issuer

string

No

The OIDC issuer information.

https://example.com/oauth

JwksUri

string

No

The OIDC JWKS URI.

https://example.com/oauth/jwks

TokenEndpoint

string

No

The OIDC token endpoint.

https://example.com/oauth/token

UserinfoEndpoint

string

No

The OIDC UserInfo endpoint.

https://example.com/oauth/userinfo

GrantScopes

array

No

The list of OIDC grant scopes.

openid

string

No

The OIDC grant scope.

ou_asdaq1addsxzdq1xxxx

GrantType

string

No

The OIDC grant type.

authorization_code

PkceChallengeMethod

string

No

The PKCE algorithm. Valid values:

  • S256: SHA-256.

  • plain: Plaintext.

S256

PkceRequired

boolean

No

Specifies whether to use PKCE in the AuthorizationCode grant mode.

true

NetworkAccessEndpointId

string

No

The network endpoint ID.

nae_examplexxxx

LarkConfig

object

No

The Lark configuration information.

AppId

string

No

The AppId of the Lark application.

cli_xxxx

AppSecret

string

No

The AppSecret of the Lark application.

KiiLzh5Dueh4wbLxxxx

EncryptKey

string

No

The encryptKey of the custom Lark application.

VkdWw91mdkrjVFr3ObNwefap21dfbZbKxxxx

VerificationToken

string

No

The verificationToken of the custom Lark application.

feishuVerifyTokenxxxxx

LogoUrl

string

No

The URL of the application logo.

idaas-image://idaas_23aqr2ye554csg33dqpch5exxxx/tmp/d17d9adc-a943-45e7-ba0c-2838dddea678xxxx

ClientToken

string

No

The client token that is used to ensure the idempotence of the request. The value is generated by the client and must be unique across different requests.

client-examplexxx

SamlConfig

object

No

The SAML IdP configuration.

BindingMethod

string

No

The binding type.

Valid values:

  • HTTP-POST :

    POST request method.

  • HTTP-REDIRECT :

    REDIRECT request method.

HTTP-REDIRECT

Certificates

array<object>

No

The list of IdP certificates.

object

No

The certificate information.

Content

string

No

The content of the certificate.

-----BEGIN CERTIFICATE----- MIIC0jCCAbqgAwIBAgIQXXXXX-----END CERTIFICATE-----

IdPEntityId

string

No

The EntityId of the IdP.

http://dc.test.com/adfs/services/trust

IdPSsoUrl

string

No

The logon URL of the IdP.

https://dc.test.com/adfs/ls/

MaxClockSkew

integer

No

The maximum clock skew.

180

RequireRequestSigned

boolean

No

Specifies whether the request must be signed.

true

WantAssertionsSigned

boolean

No

Specifies whether the external IdP is required to sign the Assertion.

true

WantResponseSigned

boolean

No

Specifies whether the external IdP is required to sign the Response.

false

Response elements

Element

Type

Description

Example

object

RequestId

string

The request ID.

0441BD79-92F3-53AA-8657-F8CE4A2B912A

Examples

Success response

JSON format

{
  "RequestId": "0441BD79-92F3-53AA-8657-F8CE4A2B912A"
}

Error codes

HTTP status code

Error code

Error message

Description

400 InvalidParameter.OidcIssuer OidcIssuer format check failed, it must be an address that starts with http or https. OidcIssuer format check failed, it must be an address that starts with http or https.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.