All Products
Search
Document Center

Quick BI:CreateTicket

Last Updated:Jul 02, 2026

Generates a ticket required for embedded report access.

Operation description

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

quickbi-public:CreateTicket

create

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

WorksId

string

Yes

The ID of the report for which embedding is enabled. Dashboards, workbooks, data screens, ad hoc queries, ad hoc analyses, and data entry forms are supported.

a206f5f3-****-e9b17c835b03

CmptId

string

No

The component ID. This is the ID of a specific component in the dashboard. Other report types are not supported. To obtain the component ID, see QueryWorksBloodRelationship.

0fc6a275c7f64f17b1****a306ce0f31

TicketNum

integer

No

The number of times the ticket can be used. Each time the ticket is used for access, the count decreases by 1.

  • Default value: 1.

  • Recommended value: 1.

  • Maximum value: 99999.

1

UserId

string

No

The Quick BI user ID, not your Alibaba Cloud account ID. You can call the QueryUserInfoByAccount operation to obtain the user ID. Example: fe67f61a35a94b7da1a34ba174a7****.

Note

Specify either UserId or AccountName. If neither is specified, the report owner is used by default, and the report is accessed under that user's identity. To configure row-level permissions for data, see Row-level permissions.

46e537466****92704c8

AccountName deprecated

string

No

The account name of the user.

  • If the user is an Alibaba Cloud account wangwu, the format is [primary account], for example, wangwu.

  • If the user is a Resource Access Management (RAM) users account zhangsan@aliyun.cn**, the format is [primary account:RAM user], for example, wangwu:zhangsan.

Note

Specify either UserId or AccountName. If neither is specified, the report owner is attached by default, and the report is accessed under that user's identity. To configure row-level permissions for data, see Row-level permissions.

test

AccountType deprecated

integer

No

The account type of the user. Valid values:

  • 1: Alibaba Cloud account

  • 3: Quick BI custom account

  • 4: DingTalk

  • 5: RAM user

  • 9: WeCom

  • 10: Lark

Note

If AccountName is specified, AccountType must also be specified.

1

ExpireTime

integer

No

The expiration time.

  • Unit: minutes.

  • Default value: 240.

200

WatermarkParam

string

No

The watermark parameter for the report.

  • The value cannot exceed 50 characters.

  • Watermark parameters are not supported when the report type is data screen.

ticket embed

GlobalParam

string

No

The global parameter.

[{"paramKey":"price","joinType":"and","conditionList":[{"operate":">","value":"0"}]}]

Response elements

Element

Type

Description

Example

object

RequestId

string

The request ID.

D787E1A3-A93C-424A-B626-C2B05DF8D885

Result

string

The generated ticket value.

ccd3428c-****-****-a608-26bae29dffee

Success

boolean

Indicates whether the request was successful. Valid values:

  • true: The request was successful.

  • false: The request failed.

true

Examples

Success response

JSON format

{
  "RequestId": "D787E1A3-A93C-424A-B626-C2B05DF8D885",
  "Result": "ccd3428c-****-****-a608-26bae29dffee",
  "Success": true
}

Error codes

HTTP status code

Error code

Error message

Description

400 Authorize3rdTicket.BindedWorks.Mismatch The report bound by the ticket mismatches the actual report.
400 Authorize3rdTicket.Expired Ticket [%s] has expired.
400 Authorize3rdTicket.HasNo.LoginToken The request [%s] has no token.
400 Authorize3rdTicket.NotExist Ticket %s does not exist.
400 Authorize3rdTicket.Num.Exceed The number of tickets %s is invalid.
400 Authorize3rdTicket.Num.HasNoLeft There is no ticket number left, please generate new ticket.
400 Report.NotExist.Error This work does not exist. It may have been deleted. Work ID is %s. This work does not exist. It may have been deleted. Work ID is %s.
400 Authorize3Rd.Report.Unauthorized The report is not enabled for third party embedding. This report is not enabled for 3rd party embedding.
400 Cube.Not.Exist The Cube does not exist. The Cube does not exist.
400 Datasource.NotFound.Error The specified data source does not exist: %s. The specified data source does not exist: %s.
400 Report.NotExist The dashboard does not exist. The current work does not exist.
400 Organization.Workspace.Inconformity The workspace does not match the organization. workspace inconformity with organization.
400 Parameter.Length.Exceed Parameter length exceeds maximum limit: [%s].
400 GlobalParam.Restricted.Use The global parameter function is restricted in your version.
400 Authorize3rdTicket.Unsupport.ScreenWatermark Screen embed does not support watermark parameters. Screen embed does not support watermark parameters.
400 NoPermissionTo.Operate.Object You are not authorized to operate the objects. You are not authorized to do this.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.