Skip to main content

auth_tokens

Creates, updates, deletes, gets or lists an auth_tokens resource.

Overview​

Nameauth_tokens
TypeResource
Idoci.identity.auth_tokens

Fields​

The following fields are returned by SELECT queries:

An AuthToken is an Oracle-generated token string that you can use to authenticate with third-party APIs<br />that do not support Oracle Cloud Infrastructure's signature-based authentication. For example, use an AuthToken<br />to authenticate with a Swift client with the Object Storage Service.<br /><br />The auth token is associated with the user's Console login. Auth tokens never expire. A user can have up to two<br />auth tokens at a time.<br /><br />Note: The token is always an Oracle-generated string; you can't change it to a string of your choice.<br /><br />For more information, see [Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm).<br />

NameDatatypeDescription
idstringThe OCID of the auth token.
descriptionstringThe description you assign to the auth token. Does not have to be unique, and it's changeable. (For tenancies that support identity domains) You can have an empty description.
inactiveStatusinteger (int64)The detailed status of INACTIVE lifecycleState.
lifecycleStatestringThe token's current state. After creating an auth token, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED)
timeCreatedstring (date-time)Date and time the AuthToken object was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z
timeExpiresstring (date-time)Date and time when this auth token will expire, in the format defined by RFC3339. Null if it never expires. Example: 2016-08-25T21:10:29.600Z
tokenstring (password)The auth token. The value is available only in the response for CreateAuthToken, and not for ListAuthTokens or UpdateAuthToken.
userIdstringThe OCID of the user the auth token belongs to.

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
listselectuserId, regionLists the auth tokens for the specified user. The returned object contains the token's OCID, but not<br />the token itself. The actual token is returned only upon creation.<br />
createinsertuserId, region, descriptionopc-retry-tokenCreates a new auth token for the specified user. For information about what auth tokens are for, see<br />[Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm).<br /><br />You must specify a description for the auth token (although it can be an empty string). It does not<br />have to be unique, and you can change it anytime with<br />[UpdateAuthToken](#/en/identity/20160918/AuthToken/UpdateAuthToken).<br /><br />Every user has permission to create an auth token for their own user ID. An administrator in your organization<br />does not need to write a policy to give users this ability. To compare, administrators who have permission to the<br />tenancy can use this operation to create an auth token for any user, including themselves.<br />
updateupdateuserId, authTokenId, regionif-matchUpdates the specified auth token's description.<br />
deletedeleteuserId, authTokenId, regionif-matchDeletes the specified auth token for the specified user.<br />

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
authTokenIdstringThe OCID of the auth token.
regionstringOCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION)
userIdstringThe OCID of the user.
if-matchstringFor optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value.
opc-retry-tokenstringA token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).

SELECT examples​

Lists the auth tokens for the specified user. The returned object contains the token's OCID, but not<br />the token itself. The actual token is returned only upon creation.<br />

SELECT
id,
description,
inactiveStatus,
lifecycleState,
timeCreated,
timeExpires,
token,
userId
FROM oci.identity.auth_tokens
WHERE userId = '{{ userId }}' -- required
AND region = '{{ region }}' -- required
;

INSERT examples​

Creates a new auth token for the specified user. For information about what auth tokens are for, see<br />[Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm).<br /><br />You must specify a description for the auth token (although it can be an empty string). It does not<br />have to be unique, and you can change it anytime with<br />[UpdateAuthToken](#/en/identity/20160918/AuthToken/UpdateAuthToken).<br /><br />Every user has permission to create an auth token for their own user ID. An administrator in your organization<br />does not need to write a policy to give users this ability. To compare, administrators who have permission to the<br />tenancy can use this operation to create an auth token for any user, including themselves.<br />

INSERT INTO oci.identity.auth_tokens (
description,
userId,
region,
opc-retry-token
)
SELECT
'{{ description }}' /* required */,
'{{ userId }}',
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
description,
inactiveStatus,
lifecycleState,
timeCreated,
timeExpires,
token,
userId
;

UPDATE examples​

Updates the specified auth token's description.<br />

UPDATE oci.identity.auth_tokens
SET
description = '{{ description }}'
WHERE
userId = '{{ userId }}' --required
AND authTokenId = '{{ authTokenId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
RETURNING
id,
description,
inactiveStatus,
lifecycleState,
timeCreated,
timeExpires,
token,
userId;

DELETE examples​

Deletes the specified auth token for the specified user.<br />

DELETE FROM oci.identity.auth_tokens
WHERE userId = '{{ userId }}' --required
AND authTokenId = '{{ authTokenId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;