All Products
Search
Document Center

PolarDB:DescribeInstanceAccounts

Last Updated:Jul 10, 2026

Queries the account information of an instance by calling the DescribeInstanceAccounts operation.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

drds:DescribeInstanceAccounts

get

*instance

acs:drds:{#regionId}:{#accountId}:instance/{#instanceId}/db/*

None None

Request parameters

Parameter

Type

Required

Description

Example

DrdsInstanceId

string

Yes

The instance ID.

drds*********

Response elements

Element

Type

Description

Example

object

Success

boolean

Indicates whether the request was successful.

true

RequestId

string

The request ID.

E2E4056D-57EB-4353-8355-2E6284******

InstanceAccounts

object

InstanceAccount

array<object>

The list of instance accounts.

array<object>

Host

string

Indicates an IP address that is allowed to access the database. The value % indicates that each IP address is allowed to access the database. </note>

%

Description

string

Indicates the description of an account. By default, if 0 is the value of the AccountType parameter, Created by DRDS is returned as the value of the Description parameter. If 1 is the value of the AccountType parameter, an empty string is returned as the value of the Description parameter. You can modify the description of an account on the Accounts page in the PolarDB-X console.

Created by DRDS

AccountType

integer

Indicates the type of an instance account. Valid values:

  • 0: The instance account is a privileged account.

  • 1: The instance account is a standard account.

1

AccountName

string

Indicates the username of an instance account.

test_rds3

DbPrivileges

object

DbPrivilege

array<object>

Indicates the information about the permissions of an account on a database.

object

DbName

string

Indicates the name of a database.

test_rds3

Privilege

string

Indicates the permissions that an account is granted on the database. Valid values:

  • R: The account is granted the permissions that are required to read the data of the database.

  • W: The account is granted the permissions that are required to write data to the database.

  • DDL: The account is granted the permissions that are required to perform DDL operations on the database.

  • DML: The account is granted the permissions that are required to perform DML operations on the database.

R

Examples

Success response

JSON format

{
  "Success": true,
  "RequestId": "E2E4056D-57EB-4353-8355-2E6284******",
  "InstanceAccounts": {
    "InstanceAccount": [
      {
        "Host": "%",
        "Description": "Created by DRDS",
        "AccountType": 1,
        "AccountName": "test_rds3",
        "DbPrivileges": {
          "DbPrivilege": [
            {
              "DbName": "test_rds3",
              "Privilege": "R"
            }
          ]
        }
      }
    ]
  }
}

Error codes

HTTP status code

Error code

Error message

Description

400 ActionUnauthorized The specified action is not available for you
500 InternalError The request processing has failed due to some unknown error.
404 InvalidDRDSInstanceId.NotFound The DrdsInstanceId provided does not exist in our records.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.