All Products
Search
Document Center

Security Center:AddCloudVendorAccountAK

Last Updated:Sep 17, 2026

Adds multi-cloud asset configuration information.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:AddCloudVendorAccountAK

create

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

Vendor

string

Yes

The cloud asset vendor. Valid values:

  • Tencent: Tencent Cloud

  • HUAWEICLOUD: Huawei Cloud

  • Azure: Azure

  • AWS: AWS

  • VOLCENGINE: Volcengine

  • google: Google Cloud

  • CHAITIN: Chaitin Technology

  • FORTINET: Fortinet

  • THREATBOOK: ThreatBook

  • KingsoftCloud: Kingsoft Cloud

  • UCloud: UCloud

  • BaiduCloud: Baidu AI Cloud

  • WIZ: Wiz Security

AWS

AkType

string

Yes

The AccessKey (AK) type. Valid values:

  • primary: Primary account.

  • sub: Sub-account.

  • ctdr: Agentic SOC.
    Warning If the vendor is CHAITIN, FORTINET, THREATBOOK, or WIZ, set this parameter to ctdr.

primary

SecretId

string

Yes

The AK parameter ID. Valid values:

  1. If AkType is set to primary:

  • Tencent: AccessKeyId of the primary account

  • HUAWEICLOUD: AccessKeyId of the primary account

  • Azure: ClientId

  • AWS: AccessKeyId of the primary account

  • VOLCENGINE: AccessKeyId of the primary account

  1. If AkType is set to sub:

  • Tencent: AccessKeyId of the sub-account

  • HUAWEICLOUD: AccessKeyId of the sub-account

  • Azure: ClientId

  • AWS: AccessKeyId of the sub-account

  • VOLCENGINE: AccessKeyId of the sub-account

  • google: private_key_id

Note

If AkType is set to primary, this value is the SecretID of the primary account on the third-party cloud. If AkType is set to sub, this value is the Access Key ID of the sub-account on the third-party cloud. For Azure, no distinction is made. This value is the appId in the authentication information. Google Cloud is connected through a service account. AkType defaults to sub, and this value is the private_key_id property value from the JSON-formatted service key file.

45GLRV4SOT0YFB****

SecretKey

string

Yes

The AK parameter secret. Valid values:

  1. If AkType is set to primary:

  • Tencent: SecretAccessKey of the primary account

  • HUAWEICLOUD: SecretAccessKey of the primary account

  • Azure: ClientSecret

  • AWS: SecretAccessKey of the primary account

  1. If AkType is set to sub:

  • Tencent: SecretAccessKey of the sub-account

  • HUAWEICLOUD: SecretAccessKey of the sub-account

  • Azure: ClientSecret

  • AWS: SecretAccessKey of the sub-account

  • google: private_key

Note

If AkType is set to primary, this value is the Secret Access Key of the primary account on the third-party cloud. If AkType is set to sub, this value is the Secret Access Key of the sub-account on the third-party cloud. For Azure, no distinction is made. This value is the password in the authentication information. Google Cloud is connected through a service account. AkType defaults to sub, and this value is the private_key property value from the JSON-formatted service key file.

AE6SLd****

Regions

array

No

The list of regions used for AK information verification. This parameter is valid only when Vendor is set to AWS.

Note

Call the ListCloudVendorRegions operation to obtain this parameter.

string

No

The region used for AK information verification.

ap-south-1

SubscriptionIds

array

No

The list of subscription IDs.

Note

This parameter is no longer valid.

string

No

The subscription ID.

Note

This parameter is no longer valid.

9b41e7ae-fcbf-4983-aa32-6fb2e*****

TenantId

string

No

The tenant ID. This parameter is valid only when Vendor is set to Azure.

95304a97-339b-4de5-9a7d-cdbffaf****

Domain

string

No

The account domain for connection. Valid values:

  • china: China

  • global: Global

  • europe: Huawei Cloud Europe

Note

This parameter is valid only when Vendor is set to HUAWEICLOUD, Azure, AWS, VOLCENGINE, KingsoftCloud, UCloud, or BaiduCloud, and is required. For KingsoftCloud and BaiduCloud, set this parameter to china. For UCloud, set this parameter to global.

global

AuthModules

array

No

The list of AK-associated modules.

If AkType is set to ctdr, this parameter is required. Specify at least one module, such as SIEM, HOST, or CSPM. If this parameter is not specified, the API returns HTTP 400 with error code -101.

string

No

The AK-associated module code. Valid values:

  • HOST: Host

  • CSPM: Cloud product configuration check

  • SIEM: CloudSiem

  • TRIAL: Log audit

HOST

Lang

string

No

The language type for the request and response messages. Default value: zh. Valid values:

  • zh: Chinese

  • en: English

zh

VendorAuthAlias

string

No

The AK account name.

Note

Used to identify the account to which third-party host assets belong.

test

ExtendInfo

string

No

The extended information.

Note

Used to store extended information for different vendors. Google Cloud is connected through a service account. ExtendInfo stores the JSON-formatted service key file, excluding the private_key_id and private_key fields. The file contains the following fields: type, project_id, client_email, client_id, auth_uri, token_uri, auth_provider_x509_cert_url, client_x509_cert_url, and universe_domain.

{\"product\":\"webFirewall\",\"remark\":\"remark\"}

CtdrCloudUserId

string

No

The account ID.

Note

The account ID of the connected cloud vendor. This parameter is required when the permission description includes Cloud Threat Detection and Response (CTDR).

azure_demo_1

Response elements

Element

Type

Description

Example

object

RequestId

string

The request ID.

A60DA4EC-7CD8-577D-AD73-***

Data

object

The AK information that is added.

Status

integer

The AK status. Valid values:

  • 0: Enabled.

  • 1: Not enabled.

0

AuthId

integer

The unique ID of the AK.

2158

AkType

string

The AK type. Valid values:

  • primary: Primary account.

  • sub: Sub-account.

sub

SecretId

string

The AK parameter ID.

AE6SLd****

ServiceStatus

integer

The AK usage status. Valid values:

  • 0: In use.

  • 1: Abnormal.

  • 2: Validity verification in progress.

  • 3: Validity verification timed out.

0

Vendor

string

The cloud asset vendor. Valid values:

  • Tencent: Tencent Cloud

  • HUAWEICLOUD: Huawei Cloud

  • Azure: Azure

  • AWS: AWS

  • VOLCENGINE: Volcengine

  • google: Google Cloud

  • CHAITIN: Chaitin Technology

  • FORTINET: Fortinet

  • THREATBOOK: ThreatBook

Tencent

Message

string

The AK exception information.

The IAM user is forbidden in the currently selected region

AuthModules

array<object>

The list of AK-associated modules.

object

ModuleDisp

string

The display name of the module.

Host Assets

ModuleStatement

string

The associate permission description for the module.

Read permission of the cloud server or virtual machine

Module

string

The module code. Valid values:

  • HOST: Host

  • CSPM: Cloud product configuration check

  • SIEM: CloudSiem

  • TRIAL: Log audit

HOST

ModuleAssetType

string

The cloud asset description associated with the module.

Cloud server or virtual machine

ModuleServiceStatus

integer

The module status. Valid values:

  • 0: In use.

  • 1: Abnormal.

  • 2: Validity verification in progress.

  • 3: Validity verification timed out.

0

Message

string

The module exception information.

ak_domain_error

VendorAuthAlias

string

The AK account name.

Note

Used to identify the account to which third-party host assets belong.

test

CtdrCloudUserId

string

The account ID.

Note

The account ID of the connected cloud vendor.

azure_demo_1

Examples

Success response

JSON format

{
  "RequestId": "A60DA4EC-7CD8-577D-AD73-***",
  "Data": {
    "Status": 0,
    "AuthId": 2158,
    "AkType": "sub",
    "SecretId": "AE6SLd****",
    "ServiceStatus": 0,
    "Vendor": "Tencent",
    "Message": "The IAM user is forbidden in the currently selected region",
    "AuthModules": [
      {
        "ModuleDisp": "Host Assets",
        "ModuleStatement": "Read permission of the cloud server or virtual machine",
        "Module": "HOST",
        "ModuleAssetType": "Cloud server or virtual machine",
        "ModuleServiceStatus": 0,
        "Message": "ak_domain_error"
      }
    ],
    "VendorAuthAlias": "test",
    "CtdrCloudUserId": "azure_demo_1"
  }
}

Error codes

HTTP status code

Error code

Error message

Description

400 CreateAkError Failed to create an AK. Failed to create an AK.
500 ServerError ServerError
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.