All Products
Search
Document Center

Resource Access Management:AssumeRoleWithOIDC

Last Updated:Sep 02, 2026

Obtains a Security Token Service (STS) token for assuming a RAM role during OIDC-based role SSO by calling the AssumeRoleWithOIDC operation.

Operation description

Before you begin

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

No authorization for this operation. If you encounter issues with this operation, contact technical support.

Request parameters

Parameter

Type

Required

Description

Example

OIDCProviderArn

string

No

The Alibaba Cloud Resource Name (ARN) of the OIDC IdP.

You can view the ARN of the OIDC IdP in the Resource Access Management (RAM) console or by calling an API operation:

acs:ram::113511544585****:oidc-provider/TestOidcIdp

RoleArn

string

No

The ARN of the RAM role to assume.

You can view the role ARN in the Resource Access Management (RAM) console or by calling an API operation:

acs:ram::113511544585****:role/testoidc

OIDCToken

string

No

The OIDC token issued by the external IdP.

Length: 4 to 20,000 characters.

Note

Provide the original OIDC token without Base64 decoding.

eyJraWQiOiJKQzl3eHpyaHFKMGd0****

Policy

string

No

An additional permission policy attached to the STS token to further restrict its permissions:

  • If you specify access policy, the final permissions of the STS token are the intersection of the RAM role permissions and access policy.

  • If you do not specify access policy, the final permissions of the STS token are the permissions of the RAM role.

Length: 1 to 2,048 characters.

{"Statement": [{"Action": ["*"],"Effect": "Allow","Resource": ["*"]}],"Version":"1"}

DurationSeconds

integer

No

The validity period of the token. Unit: seconds.

Default value: 3600. Minimum value: 900. Maximum value: the value specified by MaxSessionDuration.

To set the maximum session duration MaxSessionDuration for a role, see CreateRole or UpdateRole.

3600

RoleSessionName

string

Yes

The role session name.

This is a user-defined parameter. Set this parameter to the identity of the API caller, such as a username. In ActionTrail logs, you can use different values of RoleSessionName to distinguish actual operators even when the same RAM role is used, enabling user-level access auditing.

Format: The value can contain letters, digits, periods (.), at signs (@), hyphens (-), and underscores (_).

Length: 2 to 64 characters.

TestOidcAssumedRoleSession

Note

Because the AssumeRoleWithOIDC operation uses an OIDC token for authentication and supports anonymous access, you do not need to provide the Signature, SignatureMethod, SignatureVersion, or AccessKeyId common request parameters. For more information about common request parameters, see Common request parameters.

Response elements

Element

Type

Description

Example

object

The response parameters.

RequestId

string

The request ID.

3D57EAD2-8723-1F26-B69C-F8707D8B565D

OIDCTokenInfo

object

The parsed OIDC token information.

Subject

string

The OIDC subject.

This corresponds to the sub field in the OIDC token.

KryrkIdjylZb7agUgCEf****

Issuer

string

The OIDC issuer URL.

This corresponds to the iss field in the OIDC token.

https://dev-xxxxxx.okta.com

ClientIds

string

The OIDC audience. Multiple values are separated by commas (,).

This corresponds to the aud field in the OIDC token.

496271242565057****

ExpirationTime

string

The expiration time of the OIDC token (UTC).

2021-10-20T04:27:09Z

IssuanceTime

string

The issuance time of the OIDC token (UTC).

2021-10-20T03:27:09Z

VerificationInfo

string

The verification information of the OIDC token. For more information, see Manage an OIDC IdP.

Success

AssumedRoleUser

object

The temporary identity for role assumption.

AssumedRoleId

string

The ID of the temporary identity.

33157794895460****

Arn

string

The ARN of the temporary identity.

acs:ram::113511544585****:role/testoidc/TestOidcAssumedRoleSession

Credentials

object

The temporary access credentials (STS token).

SecurityToken

string

The security token.

Note

The length of the security token is not fixed. Do not impose any maximum length limit on the security token.

CAIShwJ1q6Ft5B2yfSjIr5bSEsj4g7BihPWGWHz****

Expiration

string

The time when the token expires (UTC).

2021-10-20T04:27:09Z

AccessKeySecret

string

The AccessKey secret.

CVwjCkNzTMupZ8NbTCxCBRq3K16jtcWFTJAyBEv2****

AccessKeyId

string

The AccessKey ID.

STS.NUgYrLnoC37mZZCNnAbez****

SourceIdentity

string

The source identity information.

When assuming a role, you can specify a source identity (SourceIdentity) as the initial identity of the session. The source identity value persists throughout chained role assumption sessions and cannot be changed, ensuring traceability and security of operations.

If no source identity is specified, this field is not returned.

Alice

Examples

Success response

JSON format

{
  "RequestId": "3D57EAD2-8723-1F26-B69C-F8707D8B565D",
  "OIDCTokenInfo": {
    "Subject": "KryrkIdjylZb7agUgCEf****",
    "Issuer": "https://dev-xxxxxx.okta.com",
    "ClientIds": "496271242565057****",
    "ExpirationTime": "2021-10-20T04:27:09Z",
    "IssuanceTime": "2021-10-20T03:27:09Z",
    "VerificationInfo": "Success"
  },
  "AssumedRoleUser": {
    "AssumedRoleId": "33157794895460****",
    "Arn": "acs:ram::113511544585****:role/testoidc/TestOidcAssumedRoleSession"
  },
  "Credentials": {
    "SecurityToken": "CAIShwJ1q6Ft5B2yfSjIr5bSEsj4g7BihPWGWHz****",
    "Expiration": "2021-10-20T04:27:09Z",
    "AccessKeySecret": "CVwjCkNzTMupZ8NbTCxCBRq3K16jtcWFTJAyBEv2****",
    "AccessKeyId": "STS.NUgYrLnoC37mZZCNnAbez****"
  },
  "SourceIdentity": "Alice"
}

Error codes

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.