identity_providers
Creates, updates, deletes, gets or lists an identity_providers resource.
Overview​
| Name | identity_providers |
| Type | Resource |
| Id | oci.identity.identity_providers |
Fields​
The following fields are returned by SELECT queries:
- get
- list
The user was found.
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the IdentityProvider. |
name | string | The name you assign to the IdentityProvider during creation. The name must be unique across all IdentityProvider objects in the tenancy and cannot be changed. This is the name federated users see when choosing which identity provider to use when signing in to the Oracle Cloud Infrastructure Console. |
compartmentId | string | The OCID of the tenancy containing the IdentityProvider. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
description | string | The description you assign to the IdentityProvider during creation. Does not have to be unique, and it's changeable. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
inactiveStatus | integer (int64) | The detailed status of INACTIVE lifecycleState. |
lifecycleState | string | The current state. After creating an IdentityProvider, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED) |
productType | string | The identity provider service or product. Supported identity providers are Oracle Identity Cloud Service (IDCS) and Microsoft Active Directory Federation Services (ADFS). Allowed values are: - ADFS - IDCS Example: IDCS |
protocol | string | The protocol used for federation. Allowed value: SAML2. Example: SAML2 |
timeCreated | string (date-time) | Date and time the IdentityProvider was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z |
The resulting base object when you add an identity provider to your tenancy. A<br />[Saml2IdentityProvider](#/en/identity/20160918/Saml2IdentityProvider/)<br />is a specific type of IdentityProvider that supports the SAML 2.0 protocol. Each<br />IdentityProvider object has its own OCID. For more information, see<br />[Identity Providers and Federation](/Content/Identity/Concepts/federation.htm).<br /><br />To use any of the API operations, you must be authorized in an IAM policy. If you're not authorized,<br />talk to an administrator. If you're an administrator who needs to write policies to give users access,<br />see [Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm).<br /><br />Warning: Oracle recommends that you avoid using any confidential information when you supply string<br />values using the API.<br />
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the IdentityProvider. |
name | string | The name you assign to the IdentityProvider during creation. The name must be unique across all IdentityProvider objects in the tenancy and cannot be changed. This is the name federated users see when choosing which identity provider to use when signing in to the Oracle Cloud Infrastructure Console. |
compartmentId | string | The OCID of the tenancy containing the IdentityProvider. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
description | string | The description you assign to the IdentityProvider during creation. Does not have to be unique, and it's changeable. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
inactiveStatus | integer (int64) | The detailed status of INACTIVE lifecycleState. |
lifecycleState | string | The current state. After creating an IdentityProvider, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED) |
productType | string | The identity provider service or product. Supported identity providers are Oracle Identity Cloud Service (IDCS) and Microsoft Active Directory Federation Services (ADFS). Allowed values are: - ADFS - IDCS Example: IDCS |
protocol | string | The protocol used for federation. Allowed value: SAML2. Example: SAML2 |
timeCreated | string (date-time) | Date and time the IdentityProvider was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | identityProviderId, region | Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Gets the specified identity provider's information.<br /> | |
list | select | protocol, compartmentId, region | page, limit, name, sortBy, sortOrder, lifecycleState | Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Lists all the identity providers in your tenancy. You must specify the identity provider type (e.g., SAML2 for<br />identity providers using the SAML2.0 protocol). You must specify your tenancy's OCID as the value for the<br />compartment ID (remember that the tenancy is simply the root compartment).<br />See [Where to Get the Tenancy's OCID and User's OCID](/Content/API/Concepts/apisigningkey.htm#five).<br /> |
create | insert | region, name, compartmentId, productType, description, protocol | opc-retry-token | Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Creates a new identity provider in your tenancy. For more information, see<br />[Identity Providers and Federation](/Content/Identity/Concepts/federation.htm).<br /><br />You must specify your tenancy's OCID as the compartment ID in the request object.<br />Remember that the tenancy is simply the root compartment. For information about<br />OCIDs, see [Resource Identifiers](/Content/General/Concepts/identifiers.htm).<br /><br />You must also specify a name for the IdentityProvider, which must be unique<br />across all IdentityProvider objects in your tenancy and cannot be changed.<br /><br />You must also specify a description for the IdentityProvider (although<br />it can be an empty string). It does not have to be unique, and you can change<br />it anytime with<br />[UpdateIdentityProvider](#/en/identity/20160918/IdentityProvider/UpdateIdentityProvider).<br /><br />After you send your request, the new object's lifecycleState will temporarily<br />be CREATING. Before using the object, first make sure its lifecycleState has<br />changed to ACTIVE.<br /> |
update | update | identityProviderId, region, protocol | if-match | Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Updates the specified identity provider.<br /> |
delete | delete | identityProviderId, region | if-match | Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Deletes the specified identity provider. The identity provider must not have<br />any group mappings (see [IdpGroupMapping](#/en/identity/20160918/IdpGroupMapping/)).<br /> |
reset_idp_scim_client | exec | identityProviderId, region | Resets the OAuth2 client credentials for the SCIM client associated with this identity provider.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
compartmentId | string | The OCID of the compartment (remember that the tenancy is simply the root compartment). |
identityProviderId | string | The OCID of the identity provider. |
protocol | string | The protocol used for federation. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
lifecycleState | string | A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. |
limit | integer | The maximum number of items to return in a paginated "List" call. |
name | string | A filter to only return resources that match the given name exactly. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
page | string | The value of the opc-next-page response header from the previous "List" call. |
sortBy | string | The field to sort by. You can provide one sort order (sortOrder). Default order for TIMECREATED is descending. Default order for NAME is ascending. The NAME sort order is case sensitive. Note: In general, some "List" operations (for example, ListInstances) let you optionally filter by Availability Domain if the scope of the resource type is within a single Availability Domain. If you call one of these "List" operations without specifying an Availability Domain, the resources are grouped by Availability Domain, then sorted. |
sortOrder | string | The sort order to use, either ascending (ASC) or descending (DESC). The NAME sort order is case sensitive. |
SELECT examples​
- get
- list
Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Gets the specified identity provider's information.<br />
SELECT
id,
name,
compartmentId,
definedTags,
description,
freeformTags,
inactiveStatus,
lifecycleState,
productType,
protocol,
timeCreated
FROM oci.identity.identity_providers
WHERE identityProviderId = '{{ identityProviderId }}' -- required
AND region = '{{ region }}' -- required
;
Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Lists all the identity providers in your tenancy. You must specify the identity provider type (e.g., SAML2 for<br />identity providers using the SAML2.0 protocol). You must specify your tenancy's OCID as the value for the<br />compartment ID (remember that the tenancy is simply the root compartment).<br />See [Where to Get the Tenancy's OCID and User's OCID](/Content/API/Concepts/apisigningkey.htm#five).<br />
SELECT
id,
name,
compartmentId,
definedTags,
description,
freeformTags,
inactiveStatus,
lifecycleState,
productType,
protocol,
timeCreated
FROM oci.identity.identity_providers
WHERE protocol = '{{ protocol }}' -- required
AND compartmentId = '{{ compartmentId }}' -- required
AND region = '{{ region }}' -- required
AND page = '{{ page }}'
AND limit = '{{ limit }}'
AND name = '{{ name }}'
AND sortBy = '{{ sortBy }}'
AND sortOrder = '{{ sortOrder }}'
AND lifecycleState = '{{ lifecycleState }}'
;
INSERT examples​
- create
- Manifest
Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Creates a new identity provider in your tenancy. For more information, see<br />[Identity Providers and Federation](/Content/Identity/Concepts/federation.htm).<br /><br />You must specify your tenancy's OCID as the compartment ID in the request object.<br />Remember that the tenancy is simply the root compartment. For information about<br />OCIDs, see [Resource Identifiers](/Content/General/Concepts/identifiers.htm).<br /><br />You must also specify a name for the IdentityProvider, which must be unique<br />across all IdentityProvider objects in your tenancy and cannot be changed.<br /><br />You must also specify a description for the IdentityProvider (although<br />it can be an empty string). It does not have to be unique, and you can change<br />it anytime with<br />[UpdateIdentityProvider](#/en/identity/20160918/IdentityProvider/UpdateIdentityProvider).<br /><br />After you send your request, the new object's lifecycleState will temporarily<br />be CREATING. Before using the object, first make sure its lifecycleState has<br />changed to ACTIVE.<br />
INSERT INTO oci.identity.identity_providers (
compartmentId,
definedTags,
description,
freeformTags,
name,
productType,
protocol,
region,
opc-retry-token
)
SELECT
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ description }}' /* required */,
'{{ freeformTags }}',
'{{ name }}' /* required */,
'{{ productType }}' /* required */,
'{{ protocol }}' /* required */,
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
name,
compartmentId,
definedTags,
description,
freeformTags,
inactiveStatus,
lifecycleState,
productType,
protocol,
timeCreated
;
# Description fields are for documentation purposes
- name: identity_providers
props:
- name: region
value: "{{ region }}"
description: Required parameter for the identity_providers resource.
- name: compartmentId
value: "{{ compartmentId }}"
description: |
The OCID of your tenancy.
- name: definedTags
value: "{{ definedTags }}"
description: |
Defined tags for this resource. Each key is predefined and scoped to a namespace.
For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm).
Example: `{"Operations": {"CostCenter": "42"}}`
- name: description
value: "{{ description }}"
description: |
The description you assign to the `IdentityProvider` during creation.
Does not have to be unique, and it's changeable.
- name: freeformTags
value: "{{ freeformTags }}"
description: |
Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace.
For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm).
Example: `{"Department": "Finance"}`
- name: name
value: "{{ name }}"
description: |
The name you assign to the `IdentityProvider` during creation.
The name must be unique across all `IdentityProvider` objects in the
tenancy and cannot be changed.
- name: productType
value: "{{ productType }}"
description: |
The identity provider service or product.
Supported identity providers are Oracle Identity Cloud Service (IDCS) and Microsoft
Active Directory Federation Services (ADFS).
Example: `IDCS`
valid_values: ['IDCS', 'ADFS']
- name: protocol
value: "{{ protocol }}"
description: |
The protocol used for federation.
Example: `SAML2`
valid_values: ['SAML2', 'ADFS']
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
UPDATE examples​
- update
Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Updates the specified identity provider.<br />
UPDATE oci.identity.identity_providers
SET
definedTags = '{{ definedTags }}',
description = '{{ description }}',
freeformTags = '{{ freeformTags }}',
protocol = '{{ protocol }}'
WHERE
identityProviderId = '{{ identityProviderId }}' --required
AND region = '{{ region }}' --required
AND protocol = '{{ protocol }}' --required
AND if-match = '{{ if-match}}'
RETURNING
id,
name,
compartmentId,
definedTags,
description,
freeformTags,
inactiveStatus,
lifecycleState,
productType,
protocol,
timeCreated;
DELETE examples​
- delete
Deprecated. For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm).<br /><br />Deletes the specified identity provider. The identity provider must not have<br />any group mappings (see [IdpGroupMapping](#/en/identity/20160918/IdpGroupMapping/)).<br />
DELETE FROM oci.identity.identity_providers
WHERE identityProviderId = '{{ identityProviderId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;
Lifecycle Methods​
- reset_idp_scim_client
Resets the OAuth2 client credentials for the SCIM client associated with this identity provider.<br />
EXEC oci.identity.identity_providers.reset_idp_scim_client
@identityProviderId='{{ identityProviderId }}' --required,
@region='{{ region }}' --required
;