All Products
Search
Document Center

Identity as a Service:API overview

Last Updated:Sep 22, 2026

API standards and multilingual preset SDKs

The OpenAPI of this product (Eiam-developerapi/2022-02-25) uses the ROA signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.

Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.

Custom signature scenarios

If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.

Account and security preparation

Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.

Authentication token API

API

Title

Description

ObtainJwtAuthenticationToken ObtainJwtAuthenticationToken Obtains a JWT authentication token.
FetchOAuthAuthenticationToken Retrieve a valid oAuth authentication token Retrieves a valid OAuth authentication token.
GenerateJwtAuthenticationToken GenerateJwtAuthenticationToken Generates a JSON Web Token (JWT) authentication token.
ListAuthenticationTokens ListAuthenticationTokens Lists authentication tokens.
ObtainJwtAuthenticationTokenByDerivedShortToken ObtainJwtAuthenticationTokenByDerivedShortToken Obtain a JWT authentication token using a derived short token.
ReinstateAuthenticationToken ReinstateAuthenticationToken Reinstate an authentication token.
ReinstateAuthenticationTokenByConsumer ReinstateAuthenticationTokenByConsumer Reinstate an authentication token for a consumer.
RevokeAuthenticationToken RevokeAuthenticationToken Revokes an authentication token.
RevokeAuthenticationTokenByConsumer RevokeAuthenticationTokenByConsumer Revokes an authentication token for a consumer.
ValidateAuthenticationToken ValidateAuthenticationToken Validates an authentication token.

Credential API

API

Title

Description

CreateUserExclusiveCredential Create an account-specific credential Creates an account-specific credential.
ObtainCredential Query a credential that contains sensitive information Queries credential information and retrieves the credential plaintext.

Cloud role access credential API

API

Title

Description

ObtainCloudAccountRoleAccessCredential Obtain temporary access credentials for a cloud account role Retrieves temporary access credentials for a cloud account role (CloudAccountRole).

OIDC API

API

Title

Description

GenerateTokenByAuthorizationServer GenerateTokenByAuthorizationServer The token endpoint for an instance-level authorization server.
GenerateToken GenerateToken Generates an access token for an application in a specified IDaaS instance based on credential information.
GenerateDeviceCode GenerateDeviceCode Generates a device code.
GetUserInfo GetUserInfo Retrieves the information about a user by using the user token.
RevokeToken RevokeToken Revokes an access token or refresh token.

Authorization scope API

API

Title

Description

GetApplicationProvisioningScope GetApplicationProvisioningScope The GetApplicationProvisioningScope operation retrieves the synchronization scope of an application in a specific instance.

Organization management API

API

Title

Description

CreateOrganizationalUnit CreateOrganizationalUnit Creates an organizational unit.
PatchOrganizationalUnit PatchOrganizationalUnit Modifies an EIAM organizational unit.
GetOrganizationalUnit GetOrganizationalUnit Retrieves the information about an organizational unit.
DeleteOrganizationalUnit DeleteOrganizationalUnit Deletes an organizational unit.
ListOrganizationalUnits ListOrganizationalUnits Performs a paged query to retrieve organization information from EIAM.
ListOrganizationalUnitParentIds ListOrganizationalUnitParentIds Retrieves the information about all the parent organizational units of an organizational unit.
GetOrganizationalUnitIdByExternalId GetOrganizationalUnitIdByExternalId Obtains the ID of an organizational unit based on the external ID

Account management API

API

Title

Description

CreateUser CreateUser Creates a new EIAM account in a specified organization.
PatchUser PatchUser Modifies an Employee Identity and Access Management (EIAM) account.
GetUser GetUser Retrieves the details of an Employee Identity and Access Management (EIAM) account.
UpdateUserPassword UpdateUserPassword Updates the password for a specified EIAM account.
DeleteUser DeleteUser Deletes an Employee Identity and Access Management (EIAM) account.
ListUsers ListUsers Performs a paged query for EIAM account information.
EnableUser EnableUser Enables an Employee Identity and Access Management (EIAM) account.
DisableUser DisableUser Disables an Employee Identity and Access Management (EIAM) account.
GetUserIdByEmail GetUserIdByEmail Queries the ID of an Employee Identity and Access Management (EIAM) account by email address.
GetUserIdByPhoneNumber GetUserIdByPhoneNumber Queries the ID of an Employee Identity and Access Management (EIAM) account based on the mobile number.
GetUserIdByUserExternalId GetUserIdByUserExternalId Queries the ID of an Employee Identity and Access Management (EIAM) account based on the external ID.
GetUserIdByUsername GetUserIdByUsername Queries the ID of an Employee Identity and Access Management (EIAM) account based on the username.
SetUserPrimaryOrganizationalUnit SetUserPrimaryOrganizationalUnit Sets the primary organization for an EIAM account. This operation removes the account from the old primary organization and adds it to the new one.
AddUserToOrganizationalUnits AddUserToOrganizationalUnits Adds an EIAM account to one or more EIAM organizations. These organizations serve as subordinate organizations for the account. If the account is already a member of a specified organization, no update is performed.
RemoveUserFromOrganizationalUnits RemoveUserFromOrganizationalUnits Removes an EIAM account from one or more EIAM organizational units. The operation succeeds even if the account is not in the specified organizational units.
ListGroupsForUser ListGroupsForUser Lists the groups that an EIAM user is a member of.

Account group management API

API

Title

Description

GetGroup GetGroup Retrieves the details of a group.
CreateGroup CreateGroup Creates a group.
PatchGroup PatchGroup Modifies information about an Employee Identity and Access Management (EIAM) group.
DeleteGroup DeleteGroup Deletes a group.
ListGroups ListGroups Retrieves information about Employee Identity and Access Management (EIAM) groups by page.
AddUsersToGroup AddUsersToGroup Adds multiple Employee Identity and Access Management (EIAM) accounts to an EIAM group. If the accounts are already added to the specified group, no update is performed.
RemoveUsersFromGroup RemoveUsersFromGroup Removes multiple Employee Identity and Access Management (EIAM) accounts from an EIAM group. If an account does not belong to the group, the removal succeeds by default.
ListUsersForGroup ListUsersForGroup Queries accounts in an Employee Identity and Access Management (EIAM) group.

Others

API

Title

Description

GetOAuthAuthorizationSession Query oAuth authorization session Queries the current status and authorization result of an OAuth authorization session.