Obtains a Security Token Service (STS) token for assuming a RAM role during OIDC-based role SSO by calling the AssumeRoleWithOIDC operation.
Operation description
Before you begin
Make sure that you have obtained an OIDC token from an external identity provider (IdP).
Make sure that you have created an OIDC IdP in RAM. For more information, see Create an OIDC IdP or CreateOIDCProvider.
Make sure that you have created a RAM role whose trusted entity is the OIDC IdP. For more information, see Create a RAM role for a trusted IdP or CreateRole.
Try it now
Test
RAM authorization
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| OIDCProviderArn |
string |
No |
The Alibaba Cloud Resource Name (ARN) of the OIDC IdP. You can view the ARN of the OIDC IdP in the Resource Access Management (RAM) console or by calling an API operation:
|
acs:ram::113511544585****:oidc-provider/TestOidcIdp |
| RoleArn |
string |
No |
The ARN of the RAM role to assume. You can view the role ARN in the Resource Access Management (RAM) console or by calling an API operation:
|
acs:ram::113511544585****:role/testoidc |
| OIDCToken |
string |
No |
The OIDC token issued by the external IdP. Length: 4 to 20,000 characters. Note
Provide the original OIDC token without Base64 decoding. |
eyJraWQiOiJKQzl3eHpyaHFKMGd0**** |
| Policy |
string |
No |
An additional permission policy attached to the STS token to further restrict its permissions:
Length: 1 to 2,048 characters. |
{"Statement": [{"Action": ["*"],"Effect": "Allow","Resource": ["*"]}],"Version":"1"} |
| DurationSeconds |
integer |
No |
The validity period of the token. Unit: seconds. Default value: 3600. Minimum value: 900. Maximum value: the value specified by To set the maximum session duration |
3600 |
| RoleSessionName |
string |
Yes |
The role session name. This is a user-defined parameter. Set this parameter to the identity of the API caller, such as a username. In ActionTrail logs, you can use different values of RoleSessionName to distinguish actual operators even when the same RAM role is used, enabling user-level access auditing. Format: The value can contain letters, digits, periods (.), at signs (@), hyphens (-), and underscores (_). Length: 2 to 64 characters. |
TestOidcAssumedRoleSession |
Because the AssumeRoleWithOIDC operation uses an OIDC token for authentication and supports anonymous access, you do not need to provide the Signature, SignatureMethod, SignatureVersion, or AccessKeyId common request parameters. For more information about common request parameters, see Common request parameters.
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| RequestId |
string |
The request ID. |
3D57EAD2-8723-1F26-B69C-F8707D8B565D |
| OIDCTokenInfo |
object |
The parsed OIDC token information. |
|
| Subject |
string |
The OIDC subject. This corresponds to the |
KryrkIdjylZb7agUgCEf**** |
| Issuer |
string |
The OIDC issuer URL. This corresponds to the |
https://dev-xxxxxx.okta.com |
| ClientIds |
string |
The OIDC audience. Multiple values are separated by commas (,). This corresponds to the |
496271242565057**** |
| ExpirationTime |
string |
The expiration time of the OIDC token (UTC). |
2021-10-20T04:27:09Z |
| IssuanceTime |
string |
The issuance time of the OIDC token (UTC). |
2021-10-20T03:27:09Z |
| VerificationInfo |
string |
The verification information of the OIDC token. For more information, see Manage an OIDC IdP. |
Success |
| AssumedRoleUser |
object |
The temporary identity for role assumption. |
|
| AssumedRoleId |
string |
The ID of the temporary identity. |
33157794895460**** |
| Arn |
string |
The ARN of the temporary identity. |
acs:ram::113511544585****:role/testoidc/TestOidcAssumedRoleSession |
| Credentials |
object |
The temporary access credentials (STS token). |
|
| SecurityToken |
string |
The security token. Note
The length of the security token is not fixed. Do not impose any maximum length limit on the security token. |
CAIShwJ1q6Ft5B2yfSjIr5bSEsj4g7BihPWGWHz**** |
| Expiration |
string |
The time when the token expires (UTC). |
2021-10-20T04:27:09Z |
| AccessKeySecret |
string |
The AccessKey secret. |
CVwjCkNzTMupZ8NbTCxCBRq3K16jtcWFTJAyBEv2**** |
| AccessKeyId |
string |
The AccessKey ID. |
STS.NUgYrLnoC37mZZCNnAbez**** |
| SourceIdentity |
string |
The source identity information. When assuming a role, you can specify a source identity (SourceIdentity) as the initial identity of the session. The source identity value persists throughout chained role assumption sessions and cannot be changed, ensuring traceability and security of operations. If no source identity is specified, this field is not returned. |
Alice |
Examples
Success response
JSON format
{
"RequestId": "3D57EAD2-8723-1F26-B69C-F8707D8B565D",
"OIDCTokenInfo": {
"Subject": "KryrkIdjylZb7agUgCEf****",
"Issuer": "https://dev-xxxxxx.okta.com",
"ClientIds": "496271242565057****",
"ExpirationTime": "2021-10-20T04:27:09Z",
"IssuanceTime": "2021-10-20T03:27:09Z",
"VerificationInfo": "Success"
},
"AssumedRoleUser": {
"AssumedRoleId": "33157794895460****",
"Arn": "acs:ram::113511544585****:role/testoidc/TestOidcAssumedRoleSession"
},
"Credentials": {
"SecurityToken": "CAIShwJ1q6Ft5B2yfSjIr5bSEsj4g7BihPWGWHz****",
"Expiration": "2021-10-20T04:27:09Z",
"AccessKeySecret": "CVwjCkNzTMupZ8NbTCxCBRq3K16jtcWFTJAyBEv2****",
"AccessKeyId": "STS.NUgYrLnoC37mZZCNnAbez****"
},
"SourceIdentity": "Alice"
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.