すべてのプロダクト
Search
ドキュメントセンター

Identity as a Service:CreateIdentityProvider

最終更新日:Jun 24, 2026

IDプロバイダーを作成します。

今すぐお試しください

この API を OpenAPI Explorer でお試しください。手作業による署名は必要ありません。呼び出しに成功すると、入力したパラメーターに基づき、資格情報が組み込まれた SDK コードが自動的に生成されます。このコードをダウンロードしてローカルで使用できます。

テスト

RAM 認証

この操作の認証情報はありません。問題が発生した場合は、アカウントマネージャーにご連絡ください。

リクエストパラメーター

パラメーター

必須 / 任意

説明

InstanceId

string

必須

インスタンスID。

idaas_ue2jvisn35ea5lmthk267xxxxx

IdentityProviderName

string

必須

IDプロバイダー名。

test

IdentityProviderType

string

必須

IDプロバイダーの同期タイプ。有効な値:

  • urn:alibaba:idaas:idp:alibaba:dingtalk:pull:DingTalkインバウンド

  • urn:alibaba:idaas:idp:alibaba:dingtalk:push:DingTalkアウトバウンド

  • urn:alibaba:idaas:idp:tencent:wecom:pull:WeComインバウンド

  • urn:alibaba:idaas:idp:bytedance:lark:pull:Larkインバウンド

  • urn:alibaba:idaas:idp:microsoft:ad:pull:ADインバウンド

  • urn:alibaba:idaas:idp:unknown:ldap:pull:LDAPインバウンド

  • urn:alibaba:idaas:idp:standard:oidc:標準 OIDC

  • urn:alibaba:idaas:idp:alibaba:sase:SASEカスタムOIDC。

urn:alibaba:idaas:idp:alibaba:dingtalk:push

UdPushConfig

object

任意

アウトバウンド同期設定。

IncrementalCallbackStatus

string

任意

増分コールバックステータス。このフィールドはまだ有効になっていません。無視してください。

disabled

PeriodicSyncStatus

string

任意

定期検証ステータス。このフィールドはまだ有効になっていません。無視してください。

disabled

UdSyncScopeConfigs

array<object>

任意

アウトバウンド同期設定。

object

任意

SourceScopes

array

任意

ソース同期ノードリスト。

string

任意

ソース同期ノード。組織 IDを入力します。

ou_lyhyy6p7yf7mdrdiq5xxxx

TargetScope

string

任意

ターゲット同期ノード。

ou_lyhyy6p7yf7mdrdiq5xxxx

PeriodicSyncConfig

object

任意

定期検証設定。

PeriodicSyncType

string

任意

タイプ。

列挙値:

  • cron :

    cron

  • time :

    time

cron

PeriodicSyncCron

string

任意

Cron 式。

0 45 1 * * ?

PeriodicSyncTimes

array

任意

実行時刻のセット。

integer

任意

実行時刻。

3

UdPullConfig

object

任意

インバウンド同期設定。

GroupSyncStatus

string

任意

グループ同期がサポートされているかどうか。デフォルト:disabled。有効な値:

  • Disabled:無効

  • Enabled:有効

disabled

IncrementalCallbackStatus

string

任意

増分コールバックステータス。IdPからの増分コールバックデータを処理するかどうかを指定します。有効な値:

  • Disabled:無効

  • Enabled:有効

disabled

PeriodicSyncStatus

string

任意

定期検証ステータス。EIAMとIDプロバイダー間のデータ差異を定期的に検証するかどうかを指定します。有効な値:

  • Disabled:無効

  • Enabled:有効

disabled

UdSyncScopeConfig

object

任意

同期スコープ設定。

SourceScopes

array

任意

ソース同期ノードリスト。

string

任意

ソース同期ノード。

ou_lyhyy6p7yf7mdrdiq5xxxx

TargetScope

string

任意

ターゲット同期ノード。IDaaS 組織 IDを入力します。

ou_lyhyy6p7yf7mdrdiq5xxxx

PeriodicSyncConfig

object

任意

定期検証設定。

PeriodicSyncType

string

任意

タイプ。

cron

PeriodicSyncCron

string

任意

Cron 式。

0 45 1 * * ?

PeriodicSyncTimes

array

任意

実行時刻のセット。

integer

任意

実行時刻。

3

AuthnConfig

object

任意

認証設定。

AuthnStatus

string

任意

対応するIdPが認証をサポートしているかどうか。有効な値:

  • Disabled:無効

  • Enabled:有効

enabled

AutoUpdatePasswordStatus

string

任意

自動パスワード更新がサポートされているかどうか。有効な値:

  • Disabled:無効

  • Enabled:有効

enabled

BindingConfig

object

任意

OIDC IDプロバイダーのアカウントバインディングルール設定。

AutoMatchUserProfileExpressions

array<object>

任意

自動アカウントマッチングルールのリスト。

object

任意

ExpressionMappingType

string

任意

式タイプ。有効な値:

  • Field:フィールド

  • Expression:式

field

SourceValueExpression

string

任意

マッピング属性値の式。

idpUser.phoneNumber

TargetField

string

任意

マッピングターゲット属性名。

user.username

TargetFieldDescription

string

任意

マッピングターゲット属性の説明。

username

AutoMatchUserStatus

string

任意

自動アカウントマッチングが有効かどうか。有効な値:

  • Disabled:無効

  • Enabled:有効

disabled

MappingBindingStatus

string

任意

手動アカウントバインディング機能が有効かどうか。有効な値:

  • Disabled:無効

  • Enabled:有効

enabled

DingtalkAppConfig

object

任意

DingTalk 設定。

AppKey

string

任意

DingTalkファーストパーティアプリケーションのAppKey。

Xczngvfemo4e

AppSecret

string

任意

DingTalkファーストパーティアプリケーションのAppSecret。

5d405a12a6f84ad4ab05ee09axxxx

CorpId

string

任意

DingTalkファーストパーティアプリケーションのCorpId。

307568042478613xxxx

DingtalkVersion

string

任意

DingTalkバージョン。有効な値:

  • 標準 DingTalk:public_dingtalk

  • 専用 DingTalk:private_dingtalk

public_dingtalk

EncryptKey

string

任意

DingTalkアプリケーションのEncryptKey。

VkdWw91mdkrjVFr3ObNwefap21dfxxxx

VerificationToken

string

任意

DingTalkアプリケーションのVerificationToken。

myDingApp_VerifyTokenxxxxx

LdapConfig

object

任意

AD/LDAP 設定。

AdministratorPassword

string

任意

管理者パスワード。

xxxx

AdministratorUsername

string

任意

管理者アカウント。

DC=example,DC=com

CertificateFingerprintStatus

string

任意

証明書フィンガープリントを検証するかどうか。有効な値:

  • Disabled:無効

  • Enabled:有効

enabled

CertificateFingerprints

array

任意

証明書フィンガープリントリスト。

string

任意

SHA256 公開鍵形式の証明書フィンガープリント。

asdasd2221asdawqeda

GroupMemberAttributeName

string

任意

グループメンバー属性。

member

GroupObjectClass

string

任意

グループObjectClass。

group

GroupObjectClassCustomFilter

string

任意

グループカスタムフィルター。

(|(cn=test)(group=test@test.com))

LdapProtocol

string

任意

通信プロトコル。

ldap

LdapServerHost

string

任意

AD/LDAPサーバーアドレス。

123.xx.xx.89

LdapServerPort

integer

任意

AD/LDAPポート番号。

636

OrganizationUnitObjectClass

string

任意

組織 ObjectClass。

organizationUnit,top

StartTlsStatus

string

任意

startTLSが有効かどうか。有効な値:

  • Disabled:無効

  • Enabled:有効

enabled

UserLoginIdentifier

string

任意

ユーザーログイン識別子。

userPrincipalName, mail

UserObjectClass

string

任意

ユーザーObjectClass。

person,user

UserObjectClassCustomFilter

string

任意

ユーザーカスタムフィルター。

(|(cn=test)(mail=test@test.com))

PasswordSyncStatus

string

任意

パスワード同期スイッチ。

enabled

UserRdn

string

任意

ユーザーRDN。

cn

OrganizationalUnitRdn

string

任意

組織 RDN。

ou

WeComConfig

object

任意

WeCom 設定。

AgentId

string

任意

WeCom 自社構築アプリケーションのAgentId。

278231941749863339

AuthorizeCallbackDomain

string

任意

認可コールバックドメイン。

https://xxx.aliyunidaas.com/xxxx

CorpId

string

任意

WeCom 自社構築アプリケーションのCorpId。

3756043633237690761

CorpSecret

string

任意

WeCom 自社構築アプリケーションのCorpSecret。

CSEHDddddddxxxxuxkJEHPveWRXBGqVqRsxxxx

TrustableDomain

string

任意

信頼済みドメイン。

https://xxx.aliyunidaas.com/

OidcConfig

object

任意

OIDC IdP 設定。

AuthnParam

object

任意

OIDCクライアント認証設定。

AuthnMethod

string

任意

OIDC 認証方式。有効な値:

  • client_secret_basic

  • client_secret_post

client_secret_post

ClientId

string

任意

OIDCクライアントID。

mkv7rgt4d7i4u7zqtzev2mxxxx

ClientSecret

string

任意

OIDCクライアントシークレット。

CSEHDddddddxxxxuxkJEHPveWRXBGqVqRsxxxx

EndpointConfig

object

任意

OIDCエンドポイント設定。

AuthorizationEndpoint

string

任意

OIDC 認可エンドポイント。

https://example.com/auth/authorize

Issuer

string

任意

OIDC 発行者。

https://example.com/auth

JwksUri

string

任意

OIDC JWKS URI。

https://example.com/auth/jwks

TokenEndpoint

string

任意

OIDCトークンエンドポイント。

https://example.com/auth/token

UserinfoEndpoint

string

任意

OIDC UserInfoエンドポイント。

https://example.com/auth/userinfo

GrantScopes

array

任意

OIDC 付与スコープ。

openid

string

任意

OIDC 付与スコープ、組織 IDまたはグループID。

ou_lyhyy6p7yf7mdrdiq5xxxx

GrantType

string

任意

OIDC 付与タイプ。

authorization_code

PkceChallengeMethod

string

任意

PKCEアルゴリズム。有効な値:

  • SHA256:S256

  • プレーンテキスト:plain

S256

PkceRequired

boolean

任意

認可コード付与モードでPKCEを使用するかどうか。

true

NetworkAccessEndpointId

string

任意

ネットワークアクセスエンドポイントID。

nae_examplexxxx

AutoCreateUserConfig

object

任意

自動アカウント作成ルール設定。

AutoCreateUserStatus

string

任意

自動アカウント作成が有効かどうか。有効な値:

  • Disabled:無効

  • Enabled:有効

disabled

TargetOrganizationalUnitIds

array

任意

ターゲット組織単位 IDのセット。

string

任意

ターゲット組織単位 ID。

ou_lyhyy6p7yf7mdrdiq5xxxx

AutoUpdateUserConfig

object

任意

自動アカウント更新ルール設定。

AutoUpdateUserStatus

string

任意

自動アカウント更新が有効かどうか。有効な値:

  • Disabled:無効

  • Enabled:有効

disabled

LarkConfig

object

任意

Lark 設定。

AppId

string

任意

LarkアプリケーションのAppId。

cli_xxxx

AppSecret

string

任意

LarkアプリケーションのSecret。

KiiLzh5Dueh4wbLxxxx

EnterpriseNumber

string

任意

Larkエンタープライズコード。

FSX123111xxx

EncryptKey

string

任意

Lark 自社構築アプリケーションのEncryptKey。

VkdWw91mdkrjVFr3ObNwefap21dfxxxx

VerificationToken

string

任意

Lark 自社構築アプリケーションのVerificationToken。

feishuVerifyTokenxxxxx

LogoUrl

string

任意

アプリケーションロゴのURL。

xxxx-image://xxxx_23aqr2ye554csg33dqpch5eu3q/tmp/d17d9adc-a943-45e7-ba0c-2838dddea678

ClientToken

string

任意

リクエストのべき等性を保証するために使用されるクライアントトークン。異なるリクエスト間で値が一意になるように、クライアントから値を生成します。ClientTokenの値はASCII 文字のみをサポートしています。このパラメーターを指定しない場合、システムはAPIリクエストのRequestIdをClientTokenとして自動的に使用します。RequestIdはAPIリクエストごとに異なる場合があります。

clientToken_20250704_Axxxxx

SamlConfig

object

任意

IdPEntityId

string

任意

http://dc.test.com/adfs/services/trust

IdPSsoUrl

string

任意

https://dc.test.com/adfs/ls/

Certificates

array<object>

任意

object

任意

Content

string

任意

-----BEGIN CERTIFICATE----- MIIC0jCCAbqgAwIBAgIQXXXXX-----END CERTIFICATE-----

RequireRequestSigned

boolean

任意

true

BindingMethod

string

任意

HTTP-REDIRECT

MaxClockSkew

integer

任意

180

WantResponseSigned

boolean

任意

WantAssertionsSigned

boolean

任意

レスポンスフィールド

フィールド

説明

object

レスポンスパラメーター。

RequestId

string

リクエストID。

0441BD79-92F3-53AA-8657-F8CE4A2B912A

IdentityProviderId

string

IDプロバイダーID。

idp_mwpcwnhrimlr2horxXXXX

成功レスポンス

JSONJSON

{
  "RequestId": "0441BD79-92F3-53AA-8657-F8CE4A2B912A",
  "IdentityProviderId": "idp_mwpcwnhrimlr2horxXXXX"
}

エラーコード

HTTP ステータスコード

エラーコード

エラーメッセージ

説明

400 InvalidParameter.OidcIssuer OidcIssuer format check failed, it must be an address that starts with http or https.

完全なリストについては、「エラーコード」をご参照ください。

変更履歴

完全なリストについては、「変更履歴」をご参照ください。