openapi: 3.0.0 info: version: 2020-06-15 x-release: v4 title: 'AWS SSO Identity Store #X Amz Target=AWSIdentityStore.CreateGroup #X Amz Target=AWSIdentityStore.CreateGroup #X Amz Target=SWBExternalService.AttachCustomerManagedPolicyReferenceToPermissionSet API' description:
The Identity Store service used by AWS IAM Identity Center (successor to AWS Single Sign-On) provides a single place to retrieve all of your identities (users and groups). For more information, see the IAM Identity Center User Guide.
<note> <p>Although AWS Single Sign-On was renamed, the <code>sso</code> and <code>identitystore</code> API namespaces will continue to retain their original name for backward compatibility purposes. For more information, see <a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/what-is.html#renamed">IAM Identity Center rename</a>.</p> </note> <p>This reference guide describes the identity store operations that you can call programatically and includes detailed information about data types and errors.</p>
x-logo:
url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png
backgroundColor: '#FFFFFF'
termsOfService: https://aws.amazon.com/service-terms/
contact:
name: Mike Ralphson
email: mike.ralphson@gmail.com
url: https://github.com/mermade/aws2openapi
x-twitter: PermittedSoc
license:
name: Apache 2.0 License
url: http://www.apache.org/licenses/
x-providerName: amazonaws.com
x-serviceName: identitystore
x-aws-signingName: identitystore
x-origin:
- contentType: application/json
url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/identitystore-2020-06-15.normal.json
converter:
url: https://github.com/mermade/aws2openapi
version: 1.0.0
x-apisguru-driver: external
x-apiClientRegistration:
url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct
x-apisguru-categories:
- cloud
x-preferred: true
servers:
- url: http://identitystore.{region}.amazonaws.com
variables:
region:
description: The AWS region
enum:
- us-east-1
- us-east-2
- us-west-1
- us-west-2
- us-gov-west-1
- us-gov-east-1
- ca-central-1
- eu-north-1
- eu-west-1
- eu-west-2
- eu-west-3
- eu-central-1
- eu-south-1
- af-south-1
- ap-northeast-1
- ap-northeast-2
- ap-northeast-3
- ap-southeast-1
- ap-southeast-2
- ap-east-1
- ap-south-1
- sa-east-1
- me-south-1
default: us-east-1
description: The IdentityStore multi-region endpoint
- url: https://identitystore.{region}.amazonaws.com
variables:
region:
description: The AWS region
enum:
- us-east-1
- us-east-2
- us-west-1
- us-west-2
- us-gov-west-1
- us-gov-east-1
- ca-central-1
- eu-north-1
- eu-west-1
- eu-west-2
- eu-west-3
- eu-central-1
- eu-south-1
- af-south-1
- ap-northeast-1
- ap-northeast-2
- ap-northeast-3
- ap-southeast-1
- ap-southeast-2
- ap-east-1
- ap-south-1
- sa-east-1
- me-south-1
default: us-east-1
description: The IdentityStore multi-region endpoint
- url: http://identitystore.{region}.amazonaws.com.cn
variables:
region:
description: The AWS region
enum:
- cn-north-1
- cn-northwest-1
default: cn-north-1
description: The IdentityStore endpoint for China (Beijing) and China (Ningxia)
- url: https://identitystore.{region}.amazonaws.com.cn
variables:
region:
description: The AWS region
enum:
- cn-north-1
- cn-northwest-1
default: cn-north-1
description: The IdentityStore endpoint for China (Beijing) and China (Ningxia)
security:
- hmac: []
tags:
- name: '#X Amz Target=SWBExternalService.AttachCustomerManagedPolicyReferenceToPermissionSet'
paths:
/#X-Amz-Target=SWBExternalService.AttachCustomerManagedPolicyReferenceToPermissionSet:
parameters:
- $ref: '#/components/parameters/X-Amz-Content-Sha256'
- $ref: '#/components/parameters/X-Amz-Date'
- $ref: '#/components/parameters/X-Amz-Algorithm'
- $ref: '#/components/parameters/X-Amz-Credential'
- $ref: '#/components/parameters/X-Amz-Security-Token'
- $ref: '#/components/parameters/X-Amz-Signature'
- $ref: '#/components/parameters/X-Amz-SignedHeaders'
post:
operationId: AttachCustomerManagedPolicyReferenceToPermissionSet
description: Attaches the specified customer managed policy to the specified PermissionSet.
responses:
'200':
description: Success
content:
application/json:
schema:
$ref: '#/components/schemas/AttachCustomerManagedPolicyReferenceToPermissionSetResponse'
'480':
description: ResourceNotFoundException
content:
application/json:
schema:
$ref: '#/components/schemas/ResourceNotFoundException'
'481':
description: InternalServerException
content:
application/json:
schema:
$ref: '#/components/schemas/InternalServerException'
'482':
description: ServiceQuotaExceededException
content:
application/json:
schema:
$ref: '#/components/schemas/ServiceQuotaExceededException'
'483':
description: ThrottlingException
content:
application/json:
schema:
$ref: '#/components/schemas/ThrottlingException'
'484':
description: ValidationException
content:
application/json:
schema:
$ref: '#/components/schemas/ValidationException'
'485':
description: AccessDeniedException
content:
application/json:
schema:
$ref: '#/components/schemas/AccessDeniedException'
'486':
description: ConflictException
content:
application/json:
schema:
$ref: '#/components/schemas/ConflictException'
requestBody:
required: true
content:
application/json:
schema:
$ref: '#/components/schemas/AttachCustomerManagedPolicyReferenceToPermissionSetRequest'
parameters:
- name: X-Amz-Target
in: header
required: true
schema:
type: string
enum:
- SWBExternalService.AttachCustomerManagedPolicyReferenceToPermissionSet
summary: Amazon IAM Identity Center Attach Customer Managed Policy Reference to Permission Set
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
tags:
- '#X Amz Target=SWBExternalService.AttachCustomerManagedPolicyReferenceToPermissionSet'
components:
parameters:
X-Amz-Credential:
name: X-Amz-Credential
in: header
schema:
type: string
required: false
X-Amz-Security-Token:
name: X-Amz-Security-Token
in: header
schema:
type: string
required: false
X-Amz-Date:
name: X-Amz-Date
in: header
schema:
type: string
required: false
X-Amz-Algorithm:
name: X-Amz-Algorithm
in: header
schema:
type: string
required: false
X-Amz-SignedHeaders:
name: X-Amz-SignedHeaders
in: header
schema:
type: string
required: false
X-Amz-Content-Sha256:
name: X-Amz-Content-Sha256
in: header
schema:
type: string
required: false
X-Amz-Signature:
name: X-Amz-Signature
in: header
schema:
type: string
required: false
schemas:
ServiceQuotaExceededException: {}
AttachCustomerManagedPolicyReferenceToPermissionSetResponse:
type: object
properties: {}
AccessDeniedException: {}
AttachCustomerManagedPolicyReferenceToPermissionSetRequest:
type: object
required:
- InstanceArn
- PermissionSetArn
- CustomerManagedPolicyReference
title: AttachCustomerManagedPolicyReferenceToPermissionSetRequest
properties:
InstanceArn:
allOf:
- $ref: '#/components/schemas/InstanceArn'
- description: 'The ARN of the IAM Identity Center instance under which the operation will be executed. '
PermissionSetArn:
allOf:
- $ref: '#/components/schemas/PermissionSetArn'
- description: The ARN of the PermissionSet.
CustomerManagedPolicyReference:
allOf:
- $ref: '#/components/schemas/CustomerManagedPolicyReference'
- description: Specifies the name and path of a customer managed policy. You must have an IAM policy that matches the name and path in each AWS account where you want to deploy your permission set.
PermissionSetArn:
type: string
pattern: arn:(aws|aws-us-gov|aws-cn|aws-iso|aws-iso-b):sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16}
minLength: 10
maxLength: 1224
ResourceNotFoundException: {}
ManagedPolicyName:
type: string
pattern: '[\w+=,.@-]+'
minLength: 1
maxLength: 128
ConflictException: {}
CustomerManagedPolicyReference:
type: object
required:
- Name
properties:
Name:
allOf:
- $ref: '#/components/schemas/ManagedPolicyName'
- description: The name of the IAM policy that you have configured in each account where you want to deploy your permission set.
Path:
allOf:
- $ref: '#/components/schemas/ManagedPolicyPath'
- description: The path to the IAM policy that you have configured in each account where you want to deploy your permission set. The default is /. For more information, see Friendly names and paths in the IAM User Guide.
description: Specifies the name and path of a customer managed policy. You must have an IAM policy that matches the name and path in each AWS account where you want to deploy your permission set.
InstanceArn:
type: string
pattern: arn:(aws|aws-us-gov|aws-cn|aws-iso|aws-iso-b):sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16}
minLength: 10
maxLength: 1224
ThrottlingException: {}
ValidationException: {}
ManagedPolicyPath:
type: string
pattern: ((/[A-Za-z0-9\.,\+@=_-]+)*)/
minLength: 1
maxLength: 512
InternalServerException: {}
securitySchemes:
hmac:
type: apiKey
name: Authorization
in: header
description: Amazon Signature authorization v4
x-amazon-apigateway-authtype: awsSigv4
externalDocs:
description: Amazon Web Services documentation
url: https://docs.aws.amazon.com/identitystore/
x-hasEquivalentPaths: true