api_keys
Creates, updates, deletes, gets or lists an api_keys resource.
Overview​
| Name | api_keys |
| Type | Resource |
| Id | oci.identity.api_keys |
Fields​
The following fields are returned by SELECT queries:
- list
A PEM-format RSA credential for securing requests to the Oracle Cloud Infrastructure REST API. Also known<br />as an API signing key. Specifically, this is the public key from the key pair. The private key remains with<br />the user calling the API. For information about generating a key pair<br />in the required PEM format, see [Required Keys and OCIDs](/Content/API/Concepts/apisigningkey.htm).<br /><br />Important: This is not the SSH key for accessing compute instances.<br /><br />Each user can have a maximum of three API signing keys.<br /><br />For more information about user credentials, see [User Credentials](/Content/Identity/Concepts/usercredentials.htm).<br />
| Name | Datatype | Description |
|---|---|---|
fingerprint | string | The key's fingerprint (e.g., 12:34:56:78:90🆎cd:ef:12:34:56:78:90🆎cd:ef). |
inactiveStatus | integer (int64) | The detailed status of INACTIVE lifecycleState. |
keyId | string | An Oracle-assigned identifier for the key, in this format: TENANCY_OCID/USER_OCID/KEY_FINGERPRINT. |
keyValue | string | The key's value. |
lifecycleState | string | The API key's current state. After creating an ApiKey object, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED) |
timeCreated | string (date-time) | Date and time the ApiKey object was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z |
userId | string | The OCID of the user the key belongs to. |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list | select | userId, region | Lists the API signing keys for the specified user. A user can have a maximum of three keys.<br /><br />Every user has permission to use this API call for their own user ID. An administrator in your<br />organization does not need to write a policy to give users this ability.<br /> | |
delete | delete | userId, fingerprint, region | if-match | Deletes the specified API signing key for the specified user.<br /><br />Every user has permission to use this operation to delete a key for their own user ID. An<br />administrator in your organization does not need to write a policy to give users this ability.<br />To compare, administrators who have permission to the tenancy can use this operation to delete<br />a key for any user, including themselves.<br /> |
upload_api_key | exec | userId, region, key | opc-retry-token | Uploads an API signing key for the specified user.<br /><br />Every user has permission to use this operation to upload a key for their own user ID. An<br />administrator in your organization does not need to write a policy to give users this ability.<br />To compare, administrators who have permission to the tenancy can use this operation to upload a<br />key for any user, including themselves.<br /><br />Important: Even though you have permission to upload an API key, you might not yet<br />have permission to do much else. If you try calling an operation unrelated to your own credential<br />management (e.g., ListUsers, LaunchInstance) and receive an "unauthorized" error,<br />check with an administrator to confirm which IAM Service group(s) you're in and what access<br />you have. Also confirm you're working in the correct compartment.<br /><br />After you send your request, the new object's lifecycleState will temporarily be CREATING. Before using<br />the object, first make sure its lifecycleState has changed to ACTIVE.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
fingerprint | string | The key's fingerprint. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
userId | string | The OCID of the user. |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
SELECT examples​
- list
Lists the API signing keys for the specified user. A user can have a maximum of three keys.<br /><br />Every user has permission to use this API call for their own user ID. An administrator in your<br />organization does not need to write a policy to give users this ability.<br />
SELECT
fingerprint,
inactiveStatus,
keyId,
keyValue,
lifecycleState,
timeCreated,
userId
FROM oci.identity.api_keys
WHERE userId = '{{ userId }}' -- required
AND region = '{{ region }}' -- required
;
DELETE examples​
- delete
Deletes the specified API signing key for the specified user.<br /><br />Every user has permission to use this operation to delete a key for their own user ID. An<br />administrator in your organization does not need to write a policy to give users this ability.<br />To compare, administrators who have permission to the tenancy can use this operation to delete<br />a key for any user, including themselves.<br />
DELETE FROM oci.identity.api_keys
WHERE userId = '{{ userId }}' --required
AND fingerprint = '{{ fingerprint }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;
Lifecycle Methods​
- upload_api_key
Uploads an API signing key for the specified user.<br /><br />Every user has permission to use this operation to upload a key for their own user ID. An<br />administrator in your organization does not need to write a policy to give users this ability.<br />To compare, administrators who have permission to the tenancy can use this operation to upload a<br />key for any user, including themselves.<br /><br />Important: Even though you have permission to upload an API key, you might not yet<br />have permission to do much else. If you try calling an operation unrelated to your own credential<br />management (e.g., ListUsers, LaunchInstance) and receive an "unauthorized" error,<br />check with an administrator to confirm which IAM Service group(s) you're in and what access<br />you have. Also confirm you're working in the correct compartment.<br /><br />After you send your request, the new object's lifecycleState will temporarily be CREATING. Before using<br />the object, first make sure its lifecycleState has changed to ACTIVE.<br />
EXEC oci.identity.api_keys.upload_api_key
@userId='{{ userId }}' --required,
@region='{{ region }}' --required,
@opc-retry-token='{{ opc-retry-token }}'
@@json=
'{
"key": "{{ key }}"
}'
;