IDaaS supports bidirectional synchronization of organizations and accounts with applications. For more information, see Account data synchronization. You can push data to an application as a one-time full synchronization or as real-time incremental change notifications.
Account synchronization
Go to the Account Sync page, enable the feature, and configure the Sync Scope.
The synchronization toggle is in the Synchronize from IDaaS to Application section. After you complete the configuration, click Save.
After setting the Sync Scope, the application can only access organization and account information within the specified IDaaS node.
Push configuration
Go to the Push from IDaaS to application tab.
IDaaS supports two synchronization modes:
-
shortcut mode: An IDaaS-native event callback model. This is the recommended method for most applications and the focus of this topic.
-
SCIM mode: If your application supports System for Cross-domain Identity Management (SCIM), you can use SCIM mode. For more information, see Synchronize from IDaaS to application - SCIM.
Configure the basic push settings first. The following table describes the parameters.
|
Parameter |
Description |
Example |
|
Synchronization scope |
Pushes changes for principals within the specified IDaaS organization. API calls can only retrieve data from this organization. |
Select: Alibaba Cloud IDaaS |
|
Public key endpoint |
Your application must retrieve the public key from IDaaS to verify each request's signature. |
— |
|
Outbound IP address |
Add the IDaaS outbound IP addresses to your firewall allowlist so that IDaaS requests can reach your endpoint. |
— |
|
Synchronization receiving URL |
The URL of the endpoint in your application that receives synchronization requests. This endpoint must handle test connections and process account and organization events. For more information, see Account synchronization integration overview. |
https://www.example.com/accounts/provision |
|
Enable encryption |
If enabled, business data is encrypted with the encryption key before transmission. We recommend that you enable this option for data transmitted over the public internet. |
No |
|
Encryption key |
The key used to encrypt business data. IDaaS can generate a key for you, or you can provide your own. |
|
|
Enable password synchronization |
If enabled, plaintext passwords are included in the data payload for specific events, including:
If encryption is enabled, the password is also encrypted during transmission. |
No |
After you configure the push settings, subscribe to specific events to receive real-time notifications.
In the Callback events section, select the events to subscribe to. Account-related events include: account creation, account deletion, account basic information update, account password update, account disabled, account enabled, account locked, account unlocked, and account moved. Organization-related events include: organization creation, organization deletion, organization update, and organization moved.
IDaaS defines more than ten types of account and organization change events, categorized as incremental events and full events. For more information, see Directory events.
After you complete the configuration, you can perform the following actions while synchronization is enabled:
-
Test Connection: Verifies the connection, network connectivity, and request processing.
-
Push Now: Initiates a full synchronization.
Complete the integration development described in Account synchronization integration overview to correctly receive event requests from IDaaS.