auth_tokens
Creates, updates, deletes, gets or lists an auth_tokens resource.
Overview​
| Name | auth_tokens |
| Type | Resource |
| Id | oci.identity.auth_tokens |
Fields​
The following fields are returned by SELECT queries:
- list
An AuthToken is an Oracle-generated token string that you can use to authenticate with third-party APIs<br />that do not support Oracle Cloud Infrastructure's signature-based authentication. For example, use an AuthToken<br />to authenticate with a Swift client with the Object Storage Service.<br /><br />The auth token is associated with the user's Console login. Auth tokens never expire. A user can have up to two<br />auth tokens at a time.<br /><br />Note: The token is always an Oracle-generated string; you can't change it to a string of your choice.<br /><br />For more information, see [Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm).<br />
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the auth token. |
description | string | The description you assign to the auth token. Does not have to be unique, and it's changeable. (For tenancies that support identity domains) You can have an empty description. |
inactiveStatus | integer (int64) | The detailed status of INACTIVE lifecycleState. |
lifecycleState | string | The token's current state. After creating an auth token, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED) |
timeCreated | string (date-time) | Date and time the AuthToken object was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z |
timeExpires | string (date-time) | Date and time when this auth token will expire, in the format defined by RFC3339. Null if it never expires. Example: 2016-08-25T21:10:29.600Z |
token | string (password) | The auth token. The value is available only in the response for CreateAuthToken, and not for ListAuthTokens or UpdateAuthToken. |
userId | string | The OCID of the user the auth token belongs to. |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list | select | userId, region | Lists the auth tokens for the specified user. The returned object contains the token's OCID, but not<br />the token itself. The actual token is returned only upon creation.<br /> | |
create | insert | userId, region, description | opc-retry-token | Creates a new auth token for the specified user. For information about what auth tokens are for, see<br />[Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm).<br /><br />You must specify a description for the auth token (although it can be an empty string). It does not<br />have to be unique, and you can change it anytime with<br />[UpdateAuthToken](#/en/identity/20160918/AuthToken/UpdateAuthToken).<br /><br />Every user has permission to create an auth token for their own user ID. An administrator in your organization<br />does not need to write a policy to give users this ability. To compare, administrators who have permission to the<br />tenancy can use this operation to create an auth token for any user, including themselves.<br /> |
update | update | userId, authTokenId, region | if-match | Updates the specified auth token's description.<br /> |
delete | delete | userId, authTokenId, region | if-match | Deletes the specified auth token for the specified user.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
authTokenId | string | The OCID of the auth token. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
userId | string | The OCID of the user. |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
SELECT examples​
- list
Lists the auth tokens for the specified user. The returned object contains the token's OCID, but not<br />the token itself. The actual token is returned only upon creation.<br />
SELECT
id,
description,
inactiveStatus,
lifecycleState,
timeCreated,
timeExpires,
token,
userId
FROM oci.identity.auth_tokens
WHERE userId = '{{ userId }}' -- required
AND region = '{{ region }}' -- required
;
INSERT examples​
- create
- Manifest
Creates a new auth token for the specified user. For information about what auth tokens are for, see<br />[Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm).<br /><br />You must specify a description for the auth token (although it can be an empty string). It does not<br />have to be unique, and you can change it anytime with<br />[UpdateAuthToken](#/en/identity/20160918/AuthToken/UpdateAuthToken).<br /><br />Every user has permission to create an auth token for their own user ID. An administrator in your organization<br />does not need to write a policy to give users this ability. To compare, administrators who have permission to the<br />tenancy can use this operation to create an auth token for any user, including themselves.<br />
INSERT INTO oci.identity.auth_tokens (
description,
userId,
region,
opc-retry-token
)
SELECT
'{{ description }}' /* required */,
'{{ userId }}',
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
description,
inactiveStatus,
lifecycleState,
timeCreated,
timeExpires,
token,
userId
;
# Description fields are for documentation purposes
- name: auth_tokens
props:
- name: userId
value: "{{ userId }}"
description: Required parameter for the auth_tokens resource.
- name: region
value: "{{ region }}"
description: Required parameter for the auth_tokens resource.
- name: description
value: "{{ description }}"
description: |
The description you assign to the auth token during creation. Does not have to be unique, and it's changeable.
(For tenancies that support identity domains) You can have an empty description.
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
UPDATE examples​
- update
Updates the specified auth token's description.<br />
UPDATE oci.identity.auth_tokens
SET
description = '{{ description }}'
WHERE
userId = '{{ userId }}' --required
AND authTokenId = '{{ authTokenId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
RETURNING
id,
description,
inactiveStatus,
lifecycleState,
timeCreated,
timeExpires,
token,
userId;
DELETE examples​
- delete
Deletes the specified auth token for the specified user.<br />
DELETE FROM oci.identity.auth_tokens
WHERE userId = '{{ userId }}' --required
AND authTokenId = '{{ authTokenId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;