All Products
Search
Document Center

Identity as a Service:Create a federated credential

Last Updated:Aug 29, 2026

Create a PCA, OIDC, or PKCS#7 federated credential for an M2M application in Alibaba Cloud IDaaS. Each credential uses one authentication type and carries the verification condition that a client request must meet before IDaaS issues an access token.

Credential types

Credential type What the credential verifies Value to prepare
PCA The content of the client certificate. The common name (CN) of the client certificate, or the certificate fields that your expression references.
OIDC The claims in the service account token that the client passes to the token endpoint. The namespace and service account of your Kubernetes cluster, or the sub value of the service account token.
PKCS#7 The fields in the PKCS#7 signature. The instance ID of an Alibaba Cloud ECS or ECI instance, or of an Amazon EC2 instance.
Note

For the features and scenarios of each provider type, see Introduction to federated credential providers.

Prerequisites

Procedure

  1. Log on to the IDaaS console. In the left-side navigation pane, choose EIAM. Find your IDaaS instance and click Console in the Actions column.

  2. Choose Application Management > M2M Application > Add Application to create an M2M application. To use an existing application, open it from the M2M application list instead.

  3. On the General tab of the application, go to the Certificate Management section. Under Authentication Type, add a PCA, OIDC, or PKCS#7 federated credential.

  4. Click Add Application Federated Credential. Configure the common parameters and the parameters for your credential type as described in the following sections, and then click Confirm.

Common parameters

These parameters apply to all three credential types.

Parameter Description
Federated Credential Provider Select an existing provider whose type matches the credential type. If none is available, create one as described in Prerequisites.
Application Federated Credential Type Select PCA, OIDC, or PKCS#7. The type determines the available verification modes.
Application Federated Credential Name The name of the federated credential cannot be changed once saved. Please enter it carefully. Supported characters: lowercase letters, digits, underscores (_), and hyphens (-).
Verification Expression Required if you select an expression verification mode. The expression verifies the parameters that a client submits to the token endpoint of the M2M authorization server, so that only requests that meet the verification condition receive an access token. Maximum length: 10,240 characters.
Description Optional. Describes the purpose of the credential. Maximum length: 128 characters.
Attribute Mapping An advanced feature that customizes the sub field in the access token. After the resource server enables a custom principal ID, the system replaces the original sub field value with the attribute mapping expression, which is the unique client identity. The format changes from <clientId> to <clientId>:<client:activeSubjectUrn>, where <client:activeSubjectUrn> is the result of that expression.
Note

Both Verification Expression and Attribute Mapping accept federated credential expressions. For the syntax, see Use federated credential expressions.

PCA verification parameters

Configure the following parameters when Application Federated Credential Type is set to PCA.

Verification determines how IDaaS generates the verification condition. Select one of the following modes:

  • Certificate: a shortcut mode for verifying only the common name (CN) of the client certificate. Enter the CN value, and IDaaS generates the verification condition automatically.

  • Expression Verification for Client Certificate Field : an advanced mode. Customize expressions to verify multiple client certificate fields.

The mode determines which additional field to configure:

  • Client Certificate Common Name (CN): required if you select Certificate.

  • Verification Expression: required if you select Expression Verification for Client Certificate Field. The expression verifies the client certificate content.

Note

IDaaS validates the trust condition on the PCA federated credential provider first, and the verification condition on the credential only after that condition passes.

OIDC verification parameters

Configure the following parameters when Application Federated Credential Type is set to OIDC.

Verification determines how IDaaS generates the verification condition. Select one of the following modes:

  • Kubernetes: specify the Namespace, Service Account, and Principal ID of your Kubernetes cluster. IDaaS generates the principal ID in the system:serviceaccount:<namespace>:<serviceaccount> format.

  • Principal ID: enter the sub field from the service account token of your Kubernetes cluster.

  • Expression Verification for Claims Field: an advanced mode. Customize expressions to verify multiple claims in the service account token.

If you select Expression Verification for Claims Field, Verification Expression is required. The expression verifies the claims in the service account token.

PKCS#7 verification parameters

Configure the following parameters when Application Federated Credential Type is set to PKCS#7.

Verification determines how IDaaS generates the verification condition. Select one of the following modes:

  • Cloud Server: enter the instance ID of an Alibaba Cloud ECS or ECI instance, or an Amazon EC2 instance. IDaaS generates the expression automatically.

  • Expression Verification for Signature Value Field: an advanced mode. Customize expressions to verify fields in the PKCS#7 signature.

The mode determines which additional field to configure:

  • Instance ID: required if you select the cloud server mode. Enter the instance ID of the cloud server to verify.

  • Verification Expression: required if you select Expression Verification for Signature Value Field. The expression verifies the fields in the PKCS#7 signature.

Next steps