AWS SSO Identity Store¶
Description¶
IAM Identity Center uses the sso, sso-directory, and identitystore API namespaces. The sso-directory and identitystore namespaces authorize access to data in the Identity Store. Make sure your policies with IAM actions from these two namespaces are consistent to avoid conflicting authorization to the same data.
The Identity Store service used by IAM Identity Center provides a single place to retrieve all of your identities (users and groups). You can use the identity store API operations in this guide to manage your identity data programmatically. The scope of these APIs allows you to create, read, update, delete, and list users, groups, and memberships.
This guide also describes identity store operations that you can call and includes detailed information about data types and errors.
If you use an external identity provider or Active Directory as your identity source, we recommend that you use the Create, Update, and Delete APIs with caution. Because IAM Identity Center doesn't support outbound synchronization, your identity source won't automatically update with the changes that you make to users or groups using these APIs.
Amazon Web Services provides SDKs that consist of libraries and sample code for various programming languages and platforms (Java, Ruby, .Net, iOS, Android, and more). The SDKs provide a convenient way to programmatically access the identity store and other Amazon Web Services services. For more information about the Amazon Web Services SDKs, including how to download and install them, see Amazon Web Services Builder Center Toolbox.
Usage¶
Arguments¶
-
configOptional configuration of credentials, endpoint, and/or region.
- credentials:
- creds:
- access_key_id: AWS access key ID
- secret_access_key: AWS secret access key
- session_token: AWS temporary session token
- profile: The name of a profile to use. If not given, then the default profile is used.
- anonymous: Set anonymous credentials.
- creds:
- endpoint: The complete URL to use for the constructed client.
- region: The AWS Region used in instantiating the client.
- close_connection: Immediately close all HTTP connections.
- timeout: The time in seconds till a timeout exception is thrown when attempting to make a connection. The default is 60 seconds.
- s3_force_path_style: Set this to
trueto force the request to use path-style addressing, i.e.http://s3.amazonaws.com/BUCKET/KEY. - sts_regional_endpoint: Set sts regional endpoint resolver to regional or legacy https://docs.aws.amazon.com/sdkref/latest/guide/feature-sts-regionalized-endpoints.html
- use_dual_stack: Set this to
trueto use the dualstack (IPv4 and IPv6) endpoint for a service, where available, falling back to the regular endpoint when it isn't. Defaults to theAWS_USE_DUALSTACK_ENDPOINTenvironment variable when unset.
- credentials:
-
credentialsOptional credentials shorthand for the config parameter
- creds:
- access_key_id: AWS access key ID
- secret_access_key: AWS secret access key
- session_token: AWS temporary session token
- profile: The name of a profile to use. If not given, then the default profile is used.
- anonymous: Set anonymous credentials.
- creds:
-
endpointOptional shorthand for complete URL to use for the constructed client.
-
regionOptional shorthand for AWS Region used in instantiating the client.
Value¶
A client for the service. You can call the service's operations using syntax like svc$operation(...), where svc is the name you've assigned to the client. The available operations are listed in the Operations section.
Service syntax¶
svc <- identitystore(
config = list(
credentials = list(
creds = list(
access_key_id = "string",
secret_access_key = "string",
session_token = "string"
),
profile = "string",
anonymous = "logical"
),
endpoint = "string",
region = "string",
close_connection = "logical",
timeout = "numeric",
s3_force_path_style = "logical",
sts_regional_endpoint = "string",
use_dual_stack = "logical"
),
credentials = list(
creds = list(
access_key_id = "string",
secret_access_key = "string",
session_token = "string"
),
profile = "string",
anonymous = "logical"
),
endpoint = "string",
region = "string"
)
Operations¶
create_group |
Creates a group within the specified identity store |
|---|---|
create_group_membership |
Creates a relationship between a member and a group |
create_user |
Creates a user within the specified identity store |
delete_group |
Delete a group within an identity store given GroupId |
delete_group_membership |
Delete a membership within a group given MembershipId |
delete_user |
Deletes a user within an identity store given UserId |
describe_group |
Retrieves the group metadata and attributes from GroupId in an identity store |
describe_group_membership |
Retrieves membership metadata and attributes from MembershipId in an identity store |
describe_identity_store |
Retrieves details about the specified identity store, including its Amazon Resource Name (ARN) and network configuration |
describe_user |
Retrieves the user metadata and attributes from the UserId in an identity store |
get_group_id |
Retrieves GroupId in an identity store |
get_group_membership_id |
Retrieves the MembershipId in an identity store |
get_user_id |
Retrieves the UserId in an identity store |
is_member_in_groups |
Checks the user's membership in all requested groups and returns if the member exists in all queried groups |
list_group_memberships |
For the specified group in the specified identity store, returns the list of all GroupMembership objects and returns results in paginated form |
list_group_memberships_for_member |
For the specified member in the specified identity store, returns the list of all GroupMembership objects and returns results in paginated form |
list_groups |
Lists all groups in the identity store |
list_identity_stores |
Lists the identity stores that you have access to |
list_users |
Lists all users in the identity store |
update_group |
Updates the specified group metadata and attributes in the specified identity store |
update_identity_store |
Updates the configuration of the specified identity store, including its network configuration |
update_user |
Updates the specified user metadata and attributes in the specified identity store |