Skip to main content

api_keys

Creates, updates, deletes, gets or lists an api_keys resource.

Overview​

Nameapi_keys
TypeResource
Idoci.identity.api_keys

Fields​

The following fields are returned by SELECT queries:

A PEM-format RSA credential for securing requests to the Oracle Cloud Infrastructure REST API. Also known<br />as an API signing key. Specifically, this is the public key from the key pair. The private key remains with<br />the user calling the API. For information about generating a key pair<br />in the required PEM format, see [Required Keys and OCIDs](/Content/API/Concepts/apisigningkey.htm).<br /><br />Important: This is not the SSH key for accessing compute instances.<br /><br />Each user can have a maximum of three API signing keys.<br /><br />For more information about user credentials, see [User Credentials](/Content/Identity/Concepts/usercredentials.htm).<br />

NameDatatypeDescription
fingerprintstringThe key's fingerprint (e.g., 12:34:56:78:90🆎cd:ef:12:34:56:78:90🆎cd:ef).
inactiveStatusinteger (int64)The detailed status of INACTIVE lifecycleState.
keyIdstringAn Oracle-assigned identifier for the key, in this format: TENANCY_OCID/USER_OCID/KEY_FINGERPRINT.
keyValuestringThe key's value.
lifecycleStatestringThe API key's current state. After creating an ApiKey object, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED)
timeCreatedstring (date-time)Date and time the ApiKey object was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z
userIdstringThe OCID of the user the key belongs to.

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
listselectuserId, regionLists the API signing keys for the specified user. A user can have a maximum of three keys.<br /><br />Every user has permission to use this API call for their own user ID. An administrator in your<br />organization does not need to write a policy to give users this ability.<br />
deletedeleteuserId, fingerprint, regionif-matchDeletes the specified API signing key for the specified user.<br /><br />Every user has permission to use this operation to delete a key for their own user ID. An<br />administrator in your organization does not need to write a policy to give users this ability.<br />To compare, administrators who have permission to the tenancy can use this operation to delete<br />a key for any user, including themselves.<br />
upload_api_keyexecuserId, region, keyopc-retry-tokenUploads an API signing key for the specified user.<br /><br />Every user has permission to use this operation to upload a key for their own user ID. An<br />administrator in your organization does not need to write a policy to give users this ability.<br />To compare, administrators who have permission to the tenancy can use this operation to upload a<br />key for any user, including themselves.<br /><br />Important: Even though you have permission to upload an API key, you might not yet<br />have permission to do much else. If you try calling an operation unrelated to your own credential<br />management (e.g., ListUsers, LaunchInstance) and receive an "unauthorized" error,<br />check with an administrator to confirm which IAM Service group(s) you're in and what access<br />you have. Also confirm you're working in the correct compartment.<br /><br />After you send your request, the new object's lifecycleState will temporarily be CREATING. Before using<br />the object, first make sure its lifecycleState has changed to ACTIVE.<br />

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
fingerprintstringThe key's fingerprint.
regionstringOCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION)
userIdstringThe OCID of the user.
if-matchstringFor optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value.
opc-retry-tokenstringA token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).

SELECT examples​

Lists the API signing keys for the specified user. A user can have a maximum of three keys.<br /><br />Every user has permission to use this API call for their own user ID. An administrator in your<br />organization does not need to write a policy to give users this ability.<br />

SELECT
fingerprint,
inactiveStatus,
keyId,
keyValue,
lifecycleState,
timeCreated,
userId
FROM oci.identity.api_keys
WHERE userId = '{{ userId }}' -- required
AND region = '{{ region }}' -- required
;

DELETE examples​

Deletes the specified API signing key for the specified user.<br /><br />Every user has permission to use this operation to delete a key for their own user ID. An<br />administrator in your organization does not need to write a policy to give users this ability.<br />To compare, administrators who have permission to the tenancy can use this operation to delete<br />a key for any user, including themselves.<br />

DELETE FROM oci.identity.api_keys
WHERE userId = '{{ userId }}' --required
AND fingerprint = '{{ fingerprint }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;

Lifecycle Methods​

Uploads an API signing key for the specified user.<br /><br />Every user has permission to use this operation to upload a key for their own user ID. An<br />administrator in your organization does not need to write a policy to give users this ability.<br />To compare, administrators who have permission to the tenancy can use this operation to upload a<br />key for any user, including themselves.<br /><br />Important: Even though you have permission to upload an API key, you might not yet<br />have permission to do much else. If you try calling an operation unrelated to your own credential<br />management (e.g., ListUsers, LaunchInstance) and receive an "unauthorized" error,<br />check with an administrator to confirm which IAM Service group(s) you're in and what access<br />you have. Also confirm you're working in the correct compartment.<br /><br />After you send your request, the new object's lifecycleState will temporarily be CREATING. Before using<br />the object, first make sure its lifecycleState has changed to ACTIVE.<br />

EXEC oci.identity.api_keys.upload_api_key
@userId='{{ userId }}' --required,
@region='{{ region }}' --required,
@opc-retry-token='{{ opc-retry-token }}'
@@json=
'{
"key": "{{ key }}"
}'
;