openapi: 3.0.0 info: version: 2020-06-15 x-release: v4 title: 'AWS SSO Identity Store #X Amz Target=AWSIdentityStore.CreateGroup #X Amz Target=AWSIdentityStore.CreateGroup #X Amz Target=SWBExternalService.PutPermissionsBoundaryToPermissionSet API' description:

The Identity Store service used by AWS IAM Identity Center (successor to AWS Single Sign-On) provides a single place to retrieve all of your identities (users and groups). For more information, see the IAM Identity Center User Guide.

 <note> <p>Although AWS Single Sign-On was renamed, the <code>sso</code> and <code>identitystore</code> API namespaces will continue to retain their original name for backward compatibility purposes. For more information, see <a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/what-is.html#renamed">IAM Identity Center rename</a>.</p> </note> <p>This reference guide describes the identity store operations that you can call programatically and includes detailed information about data types and errors.</p> 
x-logo: url: https://api.apis.guru/v2/cache/logo/https_twitter.com_awscloud_profile_image.png backgroundColor: '#FFFFFF' termsOfService: https://aws.amazon.com/service-terms/ contact: name: Mike Ralphson email: mike.ralphson@gmail.com url: https://github.com/mermade/aws2openapi x-twitter: PermittedSoc license: name: Apache 2.0 License url: http://www.apache.org/licenses/ x-providerName: amazonaws.com x-serviceName: identitystore x-aws-signingName: identitystore x-origin: - contentType: application/json url: https://raw.githubusercontent.com/aws/aws-sdk-js/master/apis/identitystore-2020-06-15.normal.json converter: url: https://github.com/mermade/aws2openapi version: 1.0.0 x-apisguru-driver: external x-apiClientRegistration: url: https://portal.aws.amazon.com/gp/aws/developer/registration/index.html?nc2=h_ct x-apisguru-categories: - cloud x-preferred: true servers: - url: http://identitystore.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The IdentityStore multi-region endpoint - url: https://identitystore.{region}.amazonaws.com variables: region: description: The AWS region enum: - us-east-1 - us-east-2 - us-west-1 - us-west-2 - us-gov-west-1 - us-gov-east-1 - ca-central-1 - eu-north-1 - eu-west-1 - eu-west-2 - eu-west-3 - eu-central-1 - eu-south-1 - af-south-1 - ap-northeast-1 - ap-northeast-2 - ap-northeast-3 - ap-southeast-1 - ap-southeast-2 - ap-east-1 - ap-south-1 - sa-east-1 - me-south-1 default: us-east-1 description: The IdentityStore multi-region endpoint - url: http://identitystore.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The IdentityStore endpoint for China (Beijing) and China (Ningxia) - url: https://identitystore.{region}.amazonaws.com.cn variables: region: description: The AWS region enum: - cn-north-1 - cn-northwest-1 default: cn-north-1 description: The IdentityStore endpoint for China (Beijing) and China (Ningxia) security: - hmac: [] tags: - name: '#X Amz Target=SWBExternalService.PutPermissionsBoundaryToPermissionSet' paths: /#X-Amz-Target=SWBExternalService.PutPermissionsBoundaryToPermissionSet: parameters: - $ref: '#/components/parameters/X-Amz-Content-Sha256' - $ref: '#/components/parameters/X-Amz-Date' - $ref: '#/components/parameters/X-Amz-Algorithm' - $ref: '#/components/parameters/X-Amz-Credential' - $ref: '#/components/parameters/X-Amz-Security-Token' - $ref: '#/components/parameters/X-Amz-Signature' - $ref: '#/components/parameters/X-Amz-SignedHeaders' post: operationId: PutPermissionsBoundaryToPermissionSet description: Attaches an AWS managed or customer managed policy to the specified PermissionSet as a permissions boundary. responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/PutPermissionsBoundaryToPermissionSetResponse' '480': description: ResourceNotFoundException content: application/json: schema: $ref: '#/components/schemas/ResourceNotFoundException' '481': description: InternalServerException content: application/json: schema: $ref: '#/components/schemas/InternalServerException' '482': description: ThrottlingException content: application/json: schema: $ref: '#/components/schemas/ThrottlingException' '483': description: ValidationException content: application/json: schema: $ref: '#/components/schemas/ValidationException' '484': description: AccessDeniedException content: application/json: schema: $ref: '#/components/schemas/AccessDeniedException' '485': description: ConflictException content: application/json: schema: $ref: '#/components/schemas/ConflictException' requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/PutPermissionsBoundaryToPermissionSetRequest' parameters: - name: X-Amz-Target in: header required: true schema: type: string enum: - SWBExternalService.PutPermissionsBoundaryToPermissionSet summary: Amazon IAM Identity Center Put Permissions Boundary to Permission Set x-microcks-operation: delay: 0 dispatcher: FALLBACK tags: - '#X Amz Target=SWBExternalService.PutPermissionsBoundaryToPermissionSet' components: parameters: X-Amz-Credential: name: X-Amz-Credential in: header schema: type: string required: false X-Amz-Security-Token: name: X-Amz-Security-Token in: header schema: type: string required: false X-Amz-Date: name: X-Amz-Date in: header schema: type: string required: false X-Amz-Algorithm: name: X-Amz-Algorithm in: header schema: type: string required: false X-Amz-SignedHeaders: name: X-Amz-SignedHeaders in: header schema: type: string required: false X-Amz-Content-Sha256: name: X-Amz-Content-Sha256 in: header schema: type: string required: false X-Amz-Signature: name: X-Amz-Signature in: header schema: type: string required: false schemas: PutPermissionsBoundaryToPermissionSetRequest: type: object required: - InstanceArn - PermissionSetArn - PermissionsBoundary title: PutPermissionsBoundaryToPermissionSetRequest properties: InstanceArn: allOf: - $ref: '#/components/schemas/InstanceArn' - description: 'The ARN of the IAM Identity Center instance under which the operation will be executed. ' PermissionSetArn: allOf: - $ref: '#/components/schemas/PermissionSetArn' - description: The ARN of the PermissionSet. PermissionsBoundary: allOf: - $ref: '#/components/schemas/PermissionsBoundary' - description: The permissions boundary that you want to attach to a PermissionSet. PutPermissionsBoundaryToPermissionSetResponse: type: object properties: {} AccessDeniedException: {} PermissionsBoundary: type: object properties: CustomerManagedPolicyReference: allOf: - $ref: '#/components/schemas/CustomerManagedPolicyReference' - description: Specifies the name and path of a customer managed policy. You must have an IAM policy that matches the name and path in each AWS account where you want to deploy your permission set. ManagedPolicyArn: allOf: - $ref: '#/components/schemas/ManagedPolicyArn' - description: The AWS managed policy ARN that you want to attach to a permission set as a permissions boundary. description:

Specifies the configuration of the AWS managed or customer managed policy that you want to set as a permissions boundary. Specify either CustomerManagedPolicyReference to use the name and path of a customer managed policy, or ManagedPolicyArn to use the ARN of an AWS managed policy. A permissions boundary represents the maximum permissions that any policy can grant your role. For more information, see Permissions boundaries for IAM entities in the IAM User Guide.

Policies used as permissions boundaries don't provide permissions. You must also attach an IAM policy to the role. To learn how the effective permissions for a role are evaluated, see IAM JSON policy evaluation logic in the IAM User Guide.

PermissionSetArn: type: string pattern: arn:(aws|aws-us-gov|aws-cn|aws-iso|aws-iso-b):sso:::permissionSet/(sso)?ins-[a-zA-Z0-9-.]{16}/ps-[a-zA-Z0-9-./]{16} minLength: 10 maxLength: 1224 ResourceNotFoundException: {} ManagedPolicyName: type: string pattern: '[\w+=,.@-]+' minLength: 1 maxLength: 128 ConflictException: {} CustomerManagedPolicyReference: type: object required: - Name properties: Name: allOf: - $ref: '#/components/schemas/ManagedPolicyName' - description: The name of the IAM policy that you have configured in each account where you want to deploy your permission set. Path: allOf: - $ref: '#/components/schemas/ManagedPolicyPath' - description: The path to the IAM policy that you have configured in each account where you want to deploy your permission set. The default is /. For more information, see Friendly names and paths in the IAM User Guide. description: Specifies the name and path of a customer managed policy. You must have an IAM policy that matches the name and path in each AWS account where you want to deploy your permission set. InstanceArn: type: string pattern: arn:(aws|aws-us-gov|aws-cn|aws-iso|aws-iso-b):sso:::instance/(sso)?ins-[a-zA-Z0-9-.]{16} minLength: 10 maxLength: 1224 ThrottlingException: {} ManagedPolicyArn: type: string pattern: arn:(aws|aws-us-gov|aws-cn|aws-iso|aws-iso-b):iam::aws:policy/[\p{L}\p{M}\p{Z}\p{S}\p{N}\p{P}]+ minLength: 20 maxLength: 2048 ValidationException: {} ManagedPolicyPath: type: string pattern: ((/[A-Za-z0-9\.,\+@=_-]+)*)/ minLength: 1 maxLength: 512 InternalServerException: {} securitySchemes: hmac: type: apiKey name: Authorization in: header description: Amazon Signature authorization v4 x-amazon-apigateway-authtype: awsSigv4 externalDocs: description: Amazon Web Services documentation url: https://docs.aws.amazon.com/identitystore/ x-hasEquivalentPaths: true