API standards and multilingual preset SDKs
The OpenAPI of this product (Eiam-developerapi/2022-02-25) uses the ROA signature style. We have encapsulated SDKs for common programming languages for developers. Developers can download the SDK to directly call this product's OpenAPI without worrying about technical details. If the existing SDK does not meet your needs, you can use the signature mechanism for self-signing integration. Since the details of self-signing are very complex, it may take around 5 business days. Therefore, we recommend joining our DingTalk service group (147535001692) and conducting signature integration under expert guidance.
Before using the API, you need to prepare your identity account and access key (AccessKey) to effectively access the API through client tools (such as SDK and CLI). For details, see Obtain an AccessKey.
Custom signature scenarios
If your business scenario has special requirements and you need to integrate the API through self-signing, we recommend consulting our technical support team first (DingTalk service group: 147535001692) to obtain professional guidance and ensure efficient integration.
Account and security preparation
Alibaba Cloud accounts have full administrative permissions over all resources. Once an AccessKey is compromised, all associated resources will be at risk of unauthorized access. To ensure security, it is recommended to create a RAM user with only API access permissions and configure its AccessKey, while configuring RAM policies based on the principle of least privilege (PoLP). Use the Alibaba Cloud account only in specific scenarios where Alibaba Cloud account permissions are explicitly required.
Authentication token API
|
API |
Title |
Description |
| ObtainJwtAuthenticationToken | ObtainJwtAuthenticationToken | Obtains a JWT authentication token. |
| FetchOAuthAuthenticationToken | Retrieve a valid oAuth authentication token | Retrieves a valid OAuth authentication token. |
| GenerateJwtAuthenticationToken | GenerateJwtAuthenticationToken | Generates a JSON Web Token (JWT) authentication token. |
| ListAuthenticationTokens | ListAuthenticationTokens | Lists authentication tokens. |
| ObtainJwtAuthenticationTokenByDerivedShortToken | ObtainJwtAuthenticationTokenByDerivedShortToken | Obtain a JWT authentication token using a derived short token. |
| ReinstateAuthenticationToken | ReinstateAuthenticationToken | Reinstate an authentication token. |
| ReinstateAuthenticationTokenByConsumer | ReinstateAuthenticationTokenByConsumer | Reinstate an authentication token for a consumer. |
| RevokeAuthenticationToken | RevokeAuthenticationToken | Revokes an authentication token. |
| RevokeAuthenticationTokenByConsumer | RevokeAuthenticationTokenByConsumer | Revokes an authentication token for a consumer. |
| ValidateAuthenticationToken | ValidateAuthenticationToken | Validates an authentication token. |
Credential API
|
API |
Title |
Description |
| CreateUserExclusiveCredential | Create an account-specific credential | Creates an account-specific credential. |
| ObtainCredential | Query a credential that contains sensitive information | Queries credential information and retrieves the credential plaintext. |
Cloud role access credential API
|
API |
Title |
Description |
| ObtainCloudAccountRoleAccessCredential | Obtain temporary access credentials for a cloud account role | Retrieves temporary access credentials for a cloud account role (CloudAccountRole). |
OIDC API
|
API |
Title |
Description |
| GenerateTokenByAuthorizationServer | GenerateTokenByAuthorizationServer | The token endpoint for an instance-level authorization server. |
| GenerateToken | GenerateToken | Generates an access token for an application in a specified IDaaS instance based on credential information. |
| GenerateDeviceCode | GenerateDeviceCode | Generates a device code. |
| GetUserInfo | GetUserInfo | Retrieves the information about a user by using the user token. |
| RevokeToken | RevokeToken | Revokes an access token or refresh token. |
Authorization scope API
|
API |
Title |
Description |
| GetApplicationProvisioningScope | GetApplicationProvisioningScope | The GetApplicationProvisioningScope operation retrieves the synchronization scope of an application in a specific instance. |
Organization management API
|
API |
Title |
Description |
| CreateOrganizationalUnit | CreateOrganizationalUnit | Creates an organizational unit. |
| PatchOrganizationalUnit | PatchOrganizationalUnit | Modifies an EIAM organizational unit. |
| GetOrganizationalUnit | GetOrganizationalUnit | Retrieves the information about an organizational unit. |
| DeleteOrganizationalUnit | DeleteOrganizationalUnit | Deletes an organizational unit. |
| ListOrganizationalUnits | ListOrganizationalUnits | Performs a paged query to retrieve organization information from EIAM. |
| ListOrganizationalUnitParentIds | ListOrganizationalUnitParentIds | Retrieves the information about all the parent organizational units of an organizational unit. |
| GetOrganizationalUnitIdByExternalId | GetOrganizationalUnitIdByExternalId | Obtains the ID of an organizational unit based on the external ID |
Account management API
|
API |
Title |
Description |
| CreateUser | CreateUser | Creates a new EIAM account in a specified organization. |
| PatchUser | PatchUser | Modifies an Employee Identity and Access Management (EIAM) account. |
| GetUser | GetUser | Retrieves the details of an Employee Identity and Access Management (EIAM) account. |
| UpdateUserPassword | UpdateUserPassword | Updates the password for a specified EIAM account. |
| DeleteUser | DeleteUser | Deletes an Employee Identity and Access Management (EIAM) account. |
| ListUsers | ListUsers | Performs a paged query for EIAM account information. |
| EnableUser | EnableUser | Enables an Employee Identity and Access Management (EIAM) account. |
| DisableUser | DisableUser | Disables an Employee Identity and Access Management (EIAM) account. |
| GetUserIdByEmail | GetUserIdByEmail | Queries the ID of an Employee Identity and Access Management (EIAM) account by email address. |
| GetUserIdByPhoneNumber | GetUserIdByPhoneNumber | Queries the ID of an Employee Identity and Access Management (EIAM) account based on the mobile number. |
| GetUserIdByUserExternalId | GetUserIdByUserExternalId | Queries the ID of an Employee Identity and Access Management (EIAM) account based on the external ID. |
| GetUserIdByUsername | GetUserIdByUsername | Queries the ID of an Employee Identity and Access Management (EIAM) account based on the username. |
| SetUserPrimaryOrganizationalUnit | SetUserPrimaryOrganizationalUnit | Sets the primary organization for an EIAM account. This operation removes the account from the old primary organization and adds it to the new one. |
| AddUserToOrganizationalUnits | AddUserToOrganizationalUnits | Adds an EIAM account to one or more EIAM organizations. These organizations serve as subordinate organizations for the account. If the account is already a member of a specified organization, no update is performed. |
| RemoveUserFromOrganizationalUnits | RemoveUserFromOrganizationalUnits | Removes an EIAM account from one or more EIAM organizational units. The operation succeeds even if the account is not in the specified organizational units. |
| ListGroupsForUser | ListGroupsForUser | Lists the groups that an EIAM user is a member of. |
Account group management API
|
API |
Title |
Description |
| GetGroup | GetGroup | Retrieves the details of a group. |
| CreateGroup | CreateGroup | Creates a group. |
| PatchGroup | PatchGroup | Modifies information about an Employee Identity and Access Management (EIAM) group. |
| DeleteGroup | DeleteGroup | Deletes a group. |
| ListGroups | ListGroups | Retrieves information about Employee Identity and Access Management (EIAM) groups by page. |
| AddUsersToGroup | AddUsersToGroup | Adds multiple Employee Identity and Access Management (EIAM) accounts to an EIAM group. If the accounts are already added to the specified group, no update is performed. |
| RemoveUsersFromGroup | RemoveUsersFromGroup | Removes multiple Employee Identity and Access Management (EIAM) accounts from an EIAM group. If an account does not belong to the group, the removal succeeds by default. |
| ListUsersForGroup | ListUsersForGroup | Queries accounts in an Employee Identity and Access Management (EIAM) group. |
Others
|
API |
Title |
Description |
| GetOAuthAuthorizationSession | Query oAuth authorization session | Queries the current status and authorization result of an OAuth authorization session. |