o_auth_client_credentials
Creates, updates, deletes, gets or lists an o_auth_client_credentials resource.
Overview​
| Name | o_auth_client_credentials |
| Type | Resource |
| Id | oci.identity.o_auth_client_credentials |
Fields​
The following fields are returned by SELECT queries:
- list
User can define Oauth clients in IAM, then use it to generate a token to grant access to app resources.<br />
| Name | Datatype | Description |
|---|---|---|
id | string | The OCID of the Oauth credential. |
name | string | The name of the Oauth credential. |
compartmentId | string | The OCID of the compartment containing the Oauth credential. |
description | string | The description of the Oauth credential. |
expiresOn | string (date-time) | Date and time when this credential will expire, in the format defined by RFC3339. Null if it never expires. Example: 2016-08-25T21:10:29.600Z |
lifecycleState | string | The credential's current state. After creating a Oauth credential, make sure its lifecycleState changes from CREATING to ACTIVE before using it. (CREATING, ACTIVE, INACTIVE, DELETING, DELETED) |
scopes | array | Allowed scopes for the given oauth credential. |
timeCreated | string (date-time) | Date and time the OAuth2ClientCredential object was created, in the format defined by RFC3339. Example: 2016-08-25T21:10:29.600Z |
userId | string | The OCID of the user the Oauth credential belongs to. |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
list | select | userId, region | page, limit, lifecycleState | List of Oauth tokens for the user<br /> |
create | insert | userId, region, name, description, scopes | opc-retry-token | Creates Oauth token for the user<br /> |
update | update | userId, oauth2ClientCredentialId, region, description, scopes, passwordReset | if-match | Updates Oauth token for the user<br /> |
delete | delete | userId, oauth2ClientCredentialId, region | if-match | Delete Oauth token for the user<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
oauth2ClientCredentialId | string | The ID of the Oauth credential. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
userId | string | The OCID of the user. |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
lifecycleState | string | A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. |
limit | integer | The maximum number of items to return in a paginated "List" call. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
page | string | The value of the opc-next-page response header from the previous "List" call. |
SELECT examples​
- list
List of Oauth tokens for the user<br />
SELECT
id,
name,
compartmentId,
description,
expiresOn,
lifecycleState,
scopes,
timeCreated,
userId
FROM oci.identity.o_auth_client_credentials
WHERE userId = '{{ userId }}' -- required
AND region = '{{ region }}' -- required
AND page = '{{ page }}'
AND limit = '{{ limit }}'
AND lifecycleState = '{{ lifecycleState }}'
;
INSERT examples​
- create
- Manifest
Creates Oauth token for the user<br />
INSERT INTO oci.identity.o_auth_client_credentials (
description,
name,
scopes,
userId,
region,
opc-retry-token
)
SELECT
'{{ description }}' /* required */,
'{{ name }}' /* required */,
'{{ scopes }}' /* required */,
'{{ userId }}',
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
name,
compartmentId,
description,
expiresOn,
lifecycleState,
password,
scopes,
timeCreated,
userId
;
# Description fields are for documentation purposes
- name: o_auth_client_credentials
props:
- name: userId
value: "{{ userId }}"
description: Required parameter for the o_auth_client_credentials resource.
- name: region
value: "{{ region }}"
description: Required parameter for the o_auth_client_credentials resource.
- name: description
value: "{{ description }}"
description: |
Description of the oauth credential to help user differentiate them.
- name: name
value: "{{ name }}"
description: |
Name of the oauth credential to help user differentiate them.
- name: scopes
description: |
Allowed scopes for the given oauth credential.
value:
- audience: "{{ audience }}"
scope: "{{ scope }}"
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
UPDATE examples​
- update
Updates Oauth token for the user<br />
UPDATE oci.identity.o_auth_client_credentials
SET
description = '{{ description }}',
isResetPassword = {{ isResetPassword }},
scopes = '{{ scopes }}'
WHERE
userId = '{{ userId }}' --required
AND oauth2ClientCredentialId = '{{ oauth2ClientCredentialId }}' --required
AND region = '{{ region }}' --required
AND description = '{{ description }}' --required
AND scopes = '{{ scopes }}' --required
AND if-match = '{{ if-match}}'
RETURNING
id,
name,
compartmentId,
description,
expiresOn,
lifecycleState,
password,
scopes,
timeCreated,
userId;
DELETE examples​
- delete
Delete Oauth token for the user<br />
DELETE FROM oci.identity.o_auth_client_credentials
WHERE userId = '{{ userId }}' --required
AND oauth2ClientCredentialId = '{{ oauth2ClientCredentialId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;