openapi: 3.0.0 info: version: 2020-06-15 x-release: v4 title: 'AWS SSO Identity Store #X Amz Target=AWSIdentityStore.CreateGroup #X Amz Target=AWSIdentityStore.CreateGroup #X Amz Target=SWBExternalService.AttachCustomerManagedPolicyReferenceToPermissionSet API' description:

The Identity Store service used by AWS IAM Identity Center (successor to AWS Single Sign-On) provides a single place to retrieve all of your identities (users and groups). For more information, see the IAM Identity Center User Guide.

 <note> <p>Although AWS Single Sign-On was renamed, the <code>sso</code> and <code>identitystore</code> API namespaces will continue to retain their original name for backward compatibility purposes. For more information, see <a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/what-is.html#renamed">IAM Identity Center rename</a>.</p> </note> <p>This reference guide describes the identity store operations that you can call programatically and includes detailed information about data types and errors.</p> 
x-logo: url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: identitystore x-aws-signingName: identitystore x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/identitystore-2020-06-15.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://identitystore.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The IdentityStore multi-region endpoint - url: https://identitystore.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The IdentityStore multi-region endpoint - url: http://identitystore.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The IdentityStore endpoint for China (Beijing) and China (Ningxia) - url: https://identitystore.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The IdentityStore endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: '#X Amz Target=SWBExternalService.AttachCustomerManagedPolicyReferenceToPermissionSet' paths: /#X-Amz-Target=SWBExternalService.AttachCustomerManagedPolicyReferenceToPermissionSet: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: AttachCustomerManagedPolicyReferenceToPermissionSet description: Attaches the specified customer managed policy to the specified PermissionSet. responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/AttachCustomerManagedPolicyReferenceToPermissionSetResponse' '480': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '481': description: InternalServerException content: application/json: schema: $ref: '#/components/schemas/InternalServerException' '482': description: ServiceQuotaExceededException content: application/json: schema: $ref: '#/components/schemas/ServiceQuotaExceededException' '483': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '484': description: ValidationException content: application/json: schema: $ref: '#/components/schemas/ValidationException' '485': description: AccessDeniedException content: application/json: schema: $ref: '#/components/schemas/AccessDeniedException' '486': description: ConflictException content: application/json: schema: $ref: '#/components/schemas/ConflictException' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/AttachCustomerManagedPolicyReferenceToPermissionSetRequest' parameters: - name: X-Amz-Target in: header required: true schema: type: string enum: - SWBExternalService.AttachCustomerManagedPolicyReferenceToPermissionSet summary: Amazon IAM Identity Center Attach Customer Managed Policy Reference to Permission Set x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - '#X Amz Target=SWBExternalService.AttachCustomerManagedPolicyReferenceToPermissionSet' components: parameters: X-Amz-Credential: name: X-Amz-Credential in: header schema: type: string required: false X-Amz-Security-Token: name: X-Amz-Security-Token in: header schema: type: string required: false X-Amz-Date: name: X-Amz-Date in: header schema: type: string required: false X-Amz-Algorithm: name: X-Amz-Algorithm in: header schema: type: string required: false X-Amz-SignedHeaders: name: X-Amz-SignedHeaders in: header schema: type: string required: false X-Amz-Content-Sha256: name: X-Amz-Content-Sha256 in: header schema: type: string required: false X-Amz-Signature: name: X-Amz-Signature in: header schema: type: string required: false schemas: ServiceQuotaExceededException: {} AttachCustomerManagedPolicyReferenceToPermissionSetResponse: type: object properties: {} AccessDeniedException: {} AttachCustomerManagedPolicyReferenceToPermissionSetRequest: type: object required: - InstanceArn - PermissionSetArn - CustomerManagedPolicyReference title: AttachCustomerManagedPolicyReferenceToPermissionSetRequest properties: InstanceArn: allOf: - $ref: '#/components/schemas/InstanceArn' - description: 'The ARN of the IAM Identity Center instance under which the operation will be executed. ' PermissionSetArn: allOf: - $ref: '#/components/schemas/PermissionSetArn' - description: The ARN of the PermissionSet. CustomerManagedPolicyReference: allOf: - $ref: '#/components/schemas/CustomerManagedPolicyReference' - description: Specifies the name and path of a customer managed policy. You must have an IAM policy that matches the name and path in each AWS account where you want to deploy your permission set. PermissionSetArn: type: string pattern: arn:(aws|aws-us-gov|aws-cn|aws-iso|aws-iso-b):sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16} minLength: 10 maxLength: 1224 ResourceNotFoundException: {} ManagedPolicyName: type: string pattern: '[\w+=,.@-]+' minLength: 1 maxLength: 128 ConflictException: {} CustomerManagedPolicyReference: type: object required: - Name properties: Name: allOf: - $ref: '#/components/schemas/ManagedPolicyName' - description: The name of the IAM policy that you have configured in each account where you want to deploy your permission set. Path: allOf: - $ref: '#/components/schemas/ManagedPolicyPath' - description: The path to the IAM policy that you have configured in each account where you want to deploy your permission set. The default is /. For more information, see Friendly names and paths in the IAM User Guide. description: Specifies the name and path of a customer managed policy. You must have an IAM policy that matches the name and path in each AWS account where you want to deploy your permission set. InstanceArn: type: string pattern: arn:(aws|aws-us-gov|aws-cn|aws-iso|aws-iso-b):sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16} minLength: 10 maxLength: 1224 ThrottlingException: {} ValidationException: {} ManagedPolicyPath: type: string pattern: ((/[A-Za-z0-9\.,\+@=_-]+)*)/ minLength: 1 maxLength: 512 InternalServerException: {} securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/identitystore/ x-hasEquivalentPaths: true