Skip to main content

customer_secret_keys

Creates, updates, deletes, gets or lists a customer_secret_keys resource.

Overview​

Namecustomer_secret_keys
TypeResource
Idoci.identity.customer_secret_keys

Fields​

The following fields are returned by SELECT queries:

As the name suggests, a CustomerSecretKeySummary object contains information about a CustomerSecretKey.<br />A CustomerSecretKey is an Oracle-provided key for using the Object Storage Service's Amazon S3 compatible API.<br />

NameDatatypeDescription
idstringThe OCID of the secret key.
displayNamestringThe displayName you assign to the secret key. Does not have to be unique, and it's changeable.
inactiveStatusinteger (int64)The detailed status of INACTIVE lifecycleState.
lifecycleStatestringThe secret key's current state. After creating a secret key, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED)
timeCreatedstring (date-time)Date and time the CustomerSecretKey object was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z
timeExpiresstring (date-time)Date and time when this password will expire, in the format defined by RFC3339. Null if it never expires. Example: 2016-08-25T21:10:29.600Z
userIdstringThe OCID of the user the password belongs to.

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
listselectuserId, regionLists the secret keys for the specified user. The returned object contains the secret key's OCID, but not<br />the secret key itself. The actual secret key is returned only upon creation.<br />
createinsertuserId, region, displayNameopc-retry-tokenCreates a new secret key for the specified user. Secret keys are used for authentication with the Object Storage Service's Amazon S3<br />compatible API. The secret key consists of an Access Key/Secret Key pair. For information, see<br />[Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm).<br /><br />You must specify a description for the secret key (although it can be an empty string). It does not<br />have to be unique, and you can change it anytime with<br />[UpdateCustomerSecretKey](#/en/identity/20160918/CustomerSecretKeySummary/UpdateCustomerSecretKey).<br /><br />Every user has permission to create a secret key for their own user ID. An administrator in your organization<br />does not need to write a policy to give users this ability. To compare, administrators who have permission to the<br />tenancy can use this operation to create a secret key for any user, including themselves.<br />
updateupdateuserId, customerSecretKeyId, regionif-matchUpdates the specified secret key's description.<br />
deletedeleteuserId, customerSecretKeyId, regionif-matchDeletes the specified secret key for the specified user.<br />

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
customerSecretKeyIdstringThe access token of the secret key.
regionstringOCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION)
userIdstringThe OCID of the user.
if-matchstringFor optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value.
opc-retry-tokenstringA token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).

SELECT examples​

Lists the secret keys for the specified user. The returned object contains the secret key's OCID, but not<br />the secret key itself. The actual secret key is returned only upon creation.<br />

SELECT
id,
displayName,
inactiveStatus,
lifecycleState,
timeCreated,
timeExpires,
userId
FROM oci.identity.customer_secret_keys
WHERE userId = '{{ userId }}' -- required
AND region = '{{ region }}' -- required
;

INSERT examples​

Creates a new secret key for the specified user. Secret keys are used for authentication with the Object Storage Service's Amazon S3<br />compatible API. The secret key consists of an Access Key/Secret Key pair. For information, see<br />[Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm).<br /><br />You must specify a description for the secret key (although it can be an empty string). It does not<br />have to be unique, and you can change it anytime with<br />[UpdateCustomerSecretKey](#/en/identity/20160918/CustomerSecretKeySummary/UpdateCustomerSecretKey).<br /><br />Every user has permission to create a secret key for their own user ID. An administrator in your organization<br />does not need to write a policy to give users this ability. To compare, administrators who have permission to the<br />tenancy can use this operation to create a secret key for any user, including themselves.<br />

INSERT INTO oci.identity.customer_secret_keys (
displayName,
userId,
region,
opc-retry-token
)
SELECT
'{{ displayName }}' /* required */,
'{{ userId }}',
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
displayName,
inactiveStatus,
key,
lifecycleState,
timeCreated,
timeExpires,
userId
;

UPDATE examples​

Updates the specified secret key's description.<br />

UPDATE oci.identity.customer_secret_keys
SET
displayName = '{{ displayName }}'
WHERE
userId = '{{ userId }}' --required
AND customerSecretKeyId = '{{ customerSecretKeyId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
RETURNING
id,
displayName,
inactiveStatus,
lifecycleState,
timeCreated,
timeExpires,
userId;

DELETE examples​

Deletes the specified secret key for the specified user.<br />

DELETE FROM oci.identity.customer_secret_keys
WHERE userId = '{{ userId }}' --required
AND customerSecretKeyId = '{{ customerSecretKeyId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;