All Products
Search
Document Center

Resource Orchestration Service:ALIYUN::APIG::Consumer

更新時間:Jul 05, 2026

ALIYUN::APIG::Consumer creates a consumer.

Syntax

{
  "Type": "ALIYUN::APIG::Consumer",
  "Properties": {
    "ApikeyIdentityConfig": Map,
    "AkSkIdentityConfigs": List,
    "Description": String,
    "Enable": Boolean,
    "GatewayType": String,
    "JwtIdentityConfig": Map,
    "Name": String
  }
}

Attributes

Parameter

Type

Required

Editable

Description

Constraints

AkSkIdentityConfigs

List

No

Yes

A list of AK/SK identity configurations.

See AkSkIdentityConfigs attributes.

ApikeyIdentityConfig

Map

No

Yes

The API key identity configuration.

See ApikeyIdentityConfig attributes.

Description

String

No

Yes

A description of the consumer.

None

Enable

Boolean

No

Yes

Whether the consumer is enabled.

None

GatewayType

String

No

No

Specifies the gateway type.

None

JwtIdentityConfig

Map

No

Yes

The JWT identity configuration.

See JwtIdentityConfig attributes.

Name

String

No

No

The name of the consumer.

None

JwtIdentityConfig syntax

"JwtIdentityConfig": {
  "Type": String,
  "SecretType": String,
  "Jwks": String,
  "JwtPayloadConfig": Map,
  "JwtTokenConfig": Map
}

JwtIdentityConfig properties

Parameter

Type

Required

Editable

Description

Constraints

Jwks

String

No

Yes

Specifies the JWKS configuration.

None

JwtPayloadConfig

Map

No

Yes

Specifies the JWT payload configuration.

For more information, see JwtPayloadConfig properties.

JwtTokenConfig

Map

No

Yes

Specifies the JWT token configuration.

For more information, see JwtTokenConfig properties.

SecretType

String

No

Yes

Specifies the secret type.

Valid values:

  • Asymmetry: asymmetric encryption

  • Symmetry: symmetric encryption

Type

String

No

Yes

Specifies the identity configuration type.

Valid value:

  • Jwt

JwtPayloadConfig syntax

"JwtPayloadConfig": {
  "PayloadKeyName": String,
  "PayloadKeyValue": String
}

JwtPayloadConfig

Parameter

Type

Required

Editable

Description

Constraints

PayloadKeyName

String

No

Yes

The key name in the JWT payload.

None

PayloadKeyValue

String

No

Yes

The value in the JWT payload.

None

JwtTokenConfig syntax

"JwtTokenConfig": {
  "Pass": Boolean,
  "Position": String,
  "Prefix": String,
  "Key": String
}

JwtTokenConfig properties

Parameter

Type

Required

Editable

Description

Constraint

Key

String

No

Yes

The key name for the JWT.

None

Pass

Boolean

No

Yes

Whether to pass-through the JWT.

None

Position

String

No

Yes

The location of the JWT. Must be HEADER or QUERY.

None

Prefix

String

No

Yes

The prefix for the JWT.

None

ApikeyIdentityConfig syntax

"ApikeyIdentityConfig": {
  "ApikeySource": Map,
  "Type": String,
  "Credentials": List
}

ApikeyIdentityConfig properties

Parameter

Type

Required

Editable

Description

Constraints

ApikeySource

Map

No

Yes

The API key source configuration.

None

Credentials

List

No

Yes

The list of credentials.

None

Type

String

No

Yes

The identity configuration type.

allowed values:

  • Apikey

ApikeySource syntax

"ApikeySource": {
  "Value": String,
  "Source": String
}

ApikeySource properties

Parameter

Type

Required

Editable

Description

Constraints

Source

String

Yes

Yes

The API key source.

Valid values:

  • Header

  • QueryString

  • Default

Value

String

Yes

Yes

The name of the header or query parameter that contains the API key.

None

Credentials syntax

"Credentials": [
  {
    "Apikey": String,
    "GenerateMode": String
  }
]

Credentials attributes

Parameter

Type

Required

Editable

Description

Constraints

GenerateMode

String

Yes

Yes

Specifies the generation mode.

Valid values:

  • Custom

  • System

Apikey

String

No

Yes

The API key.

None

AkSkIdentityConfigs

"AkSkIdentityConfigs": [
  {
    "Type": String,
    "Sk": String,
    "Ak": String,
    "GenerateMode": String
  }
]

AkSkIdentityConfigs properties

Parameter

Type

Required

Editable

Description

Constraints

Ak

String

No

Yes

The access key.

None

GenerateMode

String

No

Yes

The generation mode.

Valid values:

  • Custom

  • System

Sk

String

No

Yes

The secret key.

None

Type

String

No

Yes

The identity configuration type.

Valid value:

  • AkSk

Return value

Fn::GetAtt

ConsumerId: The consumer ID.

Examples

ROSTemplateFormatVersion: '2015-09-01'
Parameters:
  Name:
    Type: String
    Description:
      en: The name of the consumer.
    Default: Null
    Required: false
  Description:
    Type: String
    Description:
      en: The description of the consumer.
    AssociationProperty: TextArea
    Default: Null
    Required: false
  JwtIdentityConfig:
    Description:
      en: JWT identity configuration.
    Required: false
    Default: Null
    Type: Json
    AssociationPropertyMetadata:
      Parameters:
        Type:
          Type: String
          Description:
            en: 'The type of the identity configuration. Valid value: Jwt.'
          AllowedValues:
            - Jwt
          Default: Null
          Required: false
        SecretType:
          Type: String
          Description:
            en: 'The secret type. Valid values: Asymmetry (asymmetric encryption), Symmetry (symmetric encryption).'
          Default: Null
          Required: false
        Jwks:
          Type: String
          Description:
            en: The JWKS configuration.
          Default: Null
          Required: false
        JwtTokenConfig:
          Description:
            en: The JWT token configuration.
          Required: false
          Default: Null
          Type: Json
          AssociationPropertyMetadata:
            Parameters:
              Position:
                Type: String
                Description:
                  en: 'The position where the JWT is stored. Valid values: HEADER, QUERY.'
                Default: Null
                Required: false
              Key:
                Type: String
                Description:
                  en: The key name for the JWT.
                Default: Null
                Required: false
              Prefix:
                Type: String
                Description:
                  en: The prefix for the JWT token.
                Default: Null
                Required: false
              Pass:
                Type: Boolean
                Description:
                  en: Whether to pass the JWT through.
                Default: Null
                Required: false
        JwtPayloadConfig:
          Description:
            en: The JWT payload configuration.
          Required: false
          Default: Null
          Type: Json
          AssociationPropertyMetadata:
            Parameters:
              PayloadKeyName:
                Type: String
                Description:
                  en: The key name of the JWT payload.
                Default: Null
                Required: false
              PayloadKeyValue:
                Type: String
                Description:
                  en: The value of the JWT payload.
                Default: Null
                Required: false
  AkSkIdentityConfigs:
    Description:
      en: A list of AK/SK identity configurations.
    Required: false
    Default: Null
    Type: Json
    AssociationProperty: List[Parameters]
    AssociationPropertyMetadata:
      Parameters:
        Type:
          Type: String
          Description:
            en: 'The type of the identity configuration. Valid value: AkSk.'
          AllowedValues:
            - AkSk
          Default: Null
          Required: false
        GenerateMode:
          Type: String
          Description:
            en: 'The generation mode. Valid values: Custom, System.'
          AllowedValues:
            - Custom
            - System
          Default: Null
          Required: false
        Ak:
          Type: String
          Description:
            en: The Access Key.
          Default: Null
          Required: false
        Sk:
          Type: String
          Description:
            en: The Secret Key.
          Default: Null
          Required: false
  ApikeyIdentityConfig:
    Description:
      en: API key identity configuration.
    Required: false
    Default: Null
    Type: Json
    AssociationPropertyMetadata:
      Parameters:
        Type:
          Type: String
          Description:
            en: 'The type of the identity configuration. Valid value: Apikey.'
          AllowedValues:
            - Apikey
          Default: Null
          Required: false
        ApikeySource:
          Description:
            en: The API key source configuration.
          Required: false
          Default: Null
          Type: Json
          AssociationPropertyMetadata:
            Parameters:
              Source:
                Type: String
                Description:
                  en: 'The source of the API key. Valid values: Header, QueryString, Default.'
                AllowedValues:
                  - Header
                  - QueryString
                  - Default
                Required: true
              Value:
                Type: String
                Description:
                  en: The value for the API key source.
                Required: true
        Credentials:
          Description:
            en: A list of credentials.
          Required: false
          Default: Null
          Type: Json
          AssociationProperty: List[Parameters]
          AssociationPropertyMetadata:
            Parameters:
              GenerateMode:
                Type: String
                Description:
                  en: 'The generation mode. Valid values: Custom, System.'
                AllowedValues:
                  - Custom
                  - System
                Required: true
              Apikey:
                Type: String
                Description:
                  en: The API key value.
                Default: Null
                Required: false
  Enable:
    Type: Boolean
    Description:
      en: Whether to enable the consumer.
    Default: Null
    Required: false
  GatewayType:
    Type: String
    Description:
      en: The type of the gateway.
    Default: Null
    Required: false
Resources:
  Consumer:
    Type: ALIYUN::APIG::Consumer
    Properties:
      Name:
        Ref: Name
      Description:
        Ref: Description
      JwtIdentityConfig:
        Ref: JwtIdentityConfig
      AkSkIdentityConfigs:
        Ref: AkSkIdentityConfigs
      ApikeyIdentityConfig:
        Ref: ApikeyIdentityConfig
      Enable:
        Ref: Enable
      GatewayType:
        Ref: GatewayType
Outputs:
  ConsumerId:
    Value:
      Fn::GetAtt:
        - Consumer
        - ConsumerId
    Description: The ID of the consumer.
{
  "ROSTemplateFormatVersion": "2015-09-01",
  "Parameters": {
    "Name": {
      "Type": "String",
      "Description": {
        "en": "The name of the consumer."
      },
      "Default": null,
      "Required": false
    },
    "Description": {
      "Type": "String",
      "Description": {
        "en": "The description of the consumer."
      },
      "AssociationProperty": "TextArea",
      "Default": null,
      "Required": false
    },
    "JwtIdentityConfig": {
      "Description": {
        "en": "JWT identity configuration."
      },
      "Required": false,
      "Default": null,
      "Type": "Json",
      "AssociationPropertyMetadata": {
        "Parameters": {
          "Type": {
            "Type": "String",
            "Description": {
              "en": "The type of the identity configuration. Valid value: Jwt."
            },
            "AllowedValues": [
              "Jwt"
            ],
            "Default": null,
            "Required": false
          },
          "SecretType": {
            "Type": "String",
            "Description": {
              "en": "The secret type. Valid values: Asymmetry (asymmetric encryption), Symmetry (symmetric encryption)."
            },
            "Default": null,
            "Required": false
          },
          "Jwks": {
            "Type": "String",
            "Description": {
              "en": "The JWKS configuration."
            },
            "Default": null,
            "Required": false
          },
          "JwtTokenConfig": {
            "Description": {
              "en": "The JWT token configuration."
            },
            "Required": false,
            "Default": null,
            "Type": "Json",
            "AssociationPropertyMetadata": {
              "Parameters": {
                "Position": {
                  "Type": "String",
                  "Description": {
                    "en": "The position where the JWT is stored. Valid values: HEADER, QUERY."
                  },
                  "Default": null,
                  "Required": false
                },
                "Key": {
                  "Type": "String",
                  "Description": {
                    "en": "The key name for the JWT."
                  },
                  "Default": null,
                  "Required": false
                },
                "Prefix": {
                  "Type": "String",
                  "Description": {
                    "en": "The prefix for the JWT token."
                  },
                  "Default": null,
                  "Required": false
                },
                "Pass": {
                  "Type": "Boolean",
                  "Description": {
                    "en": "Whether to pass the JWT through."
                  },
                  "Default": null,
                  "Required": false
                }
              }
            }
          },
          "JwtPayloadConfig": {
            "Description": {
              "en": "The JWT payload configuration."
            },
            "Required": false,
            "Default": null,
            "Type": "Json",
            "AssociationPropertyMetadata": {
              "Parameters": {
                "PayloadKeyName": {
                  "Type": "String",
                  "Description": {
                    "en": "The key name of the JWT payload."
                  },
                  "Default": null,
                  "Required": false
                },
                "PayloadKeyValue": {
                  "Type": "String",
                  "Description": {
                    "en": "The value of the JWT payload."
                  },
                  "Default": null,
                  "Required": false
                }
              }
            }
          }
        }
      }
    },
    "AkSkIdentityConfigs": {
      "Description": {
        "en": "A list of AK/SK identity configurations."
      },
      "Required": false,
      "Default": null,
      "Type": "Json",
      "AssociationProperty": "List[Parameters]",
      "AssociationPropertyMetadata": {
        "Parameters": {
          "Type": {
            "Type": "String",
            "Description": {
              "en": "The type of the identity configuration. Valid value: AkSk."
            },
            "AllowedValues": [
              "AkSk"
            ],
            "Default": null,
            "Required": false
          },
          "GenerateMode": {
            "Type": "String",
            "Description": {
              "en": "The generation mode. Valid values: Custom, System."
            },
            "AllowedValues": [
              "Custom",
              "System"
            ],
            "Default": null,
            "Required": false
          },
          "Ak": {
            "Type": "String",
            "Description": {
              "en": "The Access Key."
            },
            "Default": null,
            "Required": false
          },
          "Sk": {
            "Type": "String",
            "Description": {
              "en": "The Secret Key."
            },
            "Default": null,
            "Required": false
          }
        }
      }
    },
    "ApikeyIdentityConfig": {
      "Description": {
        "en": "API key identity configuration."
      },
      "Required": false,
      "Default": null,
      "Type": "Json",
      "AssociationPropertyMetadata": {
        "Parameters": {
          "Type": {
            "Type": "String",
            "Description": {
              "en": "The type of the identity configuration. Valid value: Apikey."
            },
            "AllowedValues": [
              "Apikey"
            ],
            "Default": null,
            "Required": false
          },
          "ApikeySource": {
            "Description": {
              "en": "The API key source configuration."
            },
            "Required": false,
            "Default": null,
            "Type": "Json",
            "AssociationPropertyMetadata": {
              "Parameters": {
                "Source": {
                  "Type": "String",
                  "Description": {
                    "en": "The source of the API key. Valid values: Header, QueryString, Default."
                  },
                  "AllowedValues": [
                    "Header",
                    "QueryString",
                    "Default"
                  ],
                  "Required": true
                },
                "Value": {
                  "Type": "String",
                  "Description": {
                    "en": "The value for the API key source."
                  },
                  "Required": true
                }
              }
            }
          },
          "Credentials": {
            "Description": {
              "en": "A list of credentials."
            },
            "Required": false,
            "Default": null,
            "Type": "Json",
            "AssociationProperty": "List[Parameters]",
            "AssociationPropertyMetadata": {
              "Parameters": {
                "GenerateMode": {
                  "Type": "String",
                  "Description": {
                    "en": "The generation mode. Valid values: Custom, System."
                  },
                  "AllowedValues": [
                    "Custom",
                    "System"
                  ],
                  "Required": true
                },
                "Apikey": {
                  "Type": "String",
                  "Description": {
                    "en": "The API key value."
                  },
                  "Default": null,
                  "Required": false
                }
              }
            }
          }
        }
      }
    },
    "Enable": {
      "Type": "Boolean",
      "Description": {
        "en": "Whether to enable the consumer."
      },
      "Default": null,
      "Required": false
    },
    "GatewayType": {
      "Type": "String",
      "Description": {
        "en": "The type of the gateway."
      },
      "Default": null,
      "Required": false
    }
  },
  "Resources": {
    "Consumer": {
      "Type": "ALIYUN::APIG::Consumer",
      "Properties": {
        "Name": {
          "Ref": "Name"
        },
        "Description": {
          "Ref": "Description"
        },
        "JwtIdentityConfig": {
          "Ref": "JwtIdentityConfig"
        },
        "AkSkIdentityConfigs": {
          "Ref": "AkSkIdentityConfigs"
        },
        "ApikeyIdentityConfig": {
          "Ref": "ApikeyIdentityConfig"
        },
        "Enable": {
          "Ref": "Enable"
        },
        "GatewayType": {
          "Ref": "GatewayType"
        }
      }
    }
  },
  "Outputs": {
    "ConsumerId": {
      "Value": {
        "Fn::GetAtt": [
          "Consumer",
          "ConsumerId"
        ]
      },
      "Description": "The ID of the consumer."
    }
  }
}