basePath: /20160918 consumes: - application/json definitions: AddLockDetails: description: 'Request payload to add lock to the resource. ' properties: message: description: 'A message added by the creator of the lock. This is typically used to give an indication of why the resource is locked. ' type: string relatedResourceId: description: 'The ID of the resource that is locking this resource. Indicates that deleting this resource will remove the lock. ' type: string type: description: Type of the lock. enum: - FULL - DELETE type: string required: - type type: object AddPolicyLockDetails: description: 'Request payload to add lock to the resource. ' properties: message: description: 'A message added by the creator of the lock. This is typically used to give an indication of why the resource is locked. ' type: string relatedResourceId: description: 'The ID of the resource that is locking this resource. Indicates that deleting this resource will remove the lock. ' type: string type: description: Type of the lock. enum: - FULL - DELETE type: string required: - type type: object AddUserToGroupDetails: properties: groupId: description: The OCID of the group. type: string userId: description: The OCID of the user. type: string required: - userId - groupId AllowedDomainLicenseTypeSummary: description: '(For tenancies that support identity domains) The ''AllowedDomainLicenseTypeSummary'' object contains information about the license type of the identity domain. ' properties: description: description: The license type description. maxLength: 4000 minLength: 1 type: string licenseType: description: 'The license type identifier. Example: "oracle-apps-premium" ' maxLength: 64 minLength: 1 type: string name: description: 'The license type name. Example: "Oracle Apps Premium" ' maxLength: 4000 minLength: 1 type: string required: - name - licenseType - description ApiKey: description: 'A PEM-format RSA credential for securing requests to the Oracle Cloud Infrastructure REST API. Also known as an *API signing key*. Specifically, this is the public key from the key pair. The private key remains with the user calling the API. For information about generating a key pair in the required PEM format, see [Required Keys and OCIDs](/Content/API/Concepts/apisigningkey.htm). **Important:** This is **not** the SSH key for accessing compute instances. Each user can have a maximum of three API signing keys. For more information about user credentials, see [User Credentials](/Content/Identity/Concepts/usercredentials.htm). ' properties: fingerprint: description: The key's fingerprint (e.g., 12:34:56:78:90:ab:cd:ef:12:34:56:78:90:ab:cd:ef). type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer keyId: description: 'An Oracle-assigned identifier for the key, in this format: TENANCY_OCID/USER_OCID/KEY_FINGERPRINT. ' type: string keyValue: description: The key's value. type: string lifecycleState: description: 'The API key''s current state. After creating an `ApiKey` object, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string timeCreated: description: 'Date and time the `ApiKey` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user the key belongs to. type: string AuthToken: description: 'An `AuthToken` is an Oracle-generated token string that you can use to authenticate with third-party APIs that do not support Oracle Cloud Infrastructure''s signature-based authentication. For example, use an `AuthToken` to authenticate with a Swift client with the Object Storage Service. The auth token is associated with the user''s Console login. Auth tokens never expire. A user can have up to two auth tokens at a time. **Note:** The token is always an Oracle-generated string; you can''t change it to a string of your choice. For more information, see [Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm). ' properties: description: description: 'The description you assign to the auth token. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' type: string id: description: The OCID of the auth token. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The token''s current state. After creating an auth token, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string timeCreated: description: 'Date and time the `AuthToken` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeExpires: description: 'Date and time when this auth token will expire, in the format defined by RFC3339. Null if it never expires. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string token: description: 'The auth token. The value is available only in the response for `CreateAuthToken`, and not for `ListAuthTokens` or `UpdateAuthToken`. ' format: password type: string userId: description: The OCID of the user the auth token belongs to. type: string AuthenticationPolicy: description: 'Authentication policy, currently set for the given compartment. ' properties: compartmentId: description: Compartment OCID. type: string networkPolicy: $ref: '#/definitions/NetworkPolicy' passwordPolicy: $ref: '#/definitions/PasswordPolicy' AvailabilityDomain: description: 'One or more isolated, fault-tolerant Oracle data centers that host cloud resources such as instances, volumes, and subnets. A region contains several Availability Domains. For more information, see [Regions and Availability Domains](/Content/General/Concepts/regions.htm). ' properties: compartmentId: description: The OCID of the tenancy. type: string id: description: The OCID of the Availability Domain. type: string name: description: The name of the Availability Domain. type: string BaseTagDefinitionValidator: description: 'Validates a definedTag value. Each validator performs validation steps in addition to the standard validation for definedTag values. For more information, see [Limits on Tags](/Content/Tagging/Concepts/taggingoverview.htm#limits). If you define a validator after a value has been set for a defined tag, then any updates that attempt to change the value must pass the additional validation defined by the current rule. Previously set values (even those that would fail the current validation) are not updated. You can still update other attributes to resources that contain a non-valid defined tag. To clear the validator call UpdateTag with [DefaultTagDefinitionValidator](/api/#/en/identity/latest/datatypes/DefaultTagDefinitionValidator). ' discriminator: validatorType properties: validatorType: description: 'Specifies the type of validation: a static value (no validation) or a list. ' enum: - ENUM - DEFAULT type: string required: - validatorType BulkActionResource: description: 'The bulk action resource entity. ' properties: entityType: description: 'The resource-type. To get the list of supported resource-types use [ListBulkActionResourceTypes API](#/en/identity/20160918/BulkActionResourceTypeCollection/ListBulkActionResourceTypes/). ' type: string identifier: description: The resource OCID. type: string metadata: additionalProperties: type: string description: "Additional information that helps to identity the resource for\ \ bulk action.\n\nThe APIs to delete and move most resource types only require\ \ the resource identifier (ocid).\nBut some resource-types require additional\ \ identifying information.\n\nThis information is provided in the resource's\ \ public API document. It is also\navailable through the\n[ListBulkActionResourceTypes\ \ API](#/en/identity/20160918/BulkActionResourceTypeCollection/ListBulkActionResourceTypes/).\n\ \n**Example**:\nThe APIs to delete or move the `buckets` resource-type require\ \ `namespaceName` and `bucketName` to identify the resource, as\nshown in\ \ the APIs, [DeleteBucket](#/en/objectstorage/20160918/Bucket/DeleteBucket)\ \ and\n[UpdateBucket](#/en/objectstorage/20160918/Bucket/UpdateBucket).\n\ \nTo add a bucket for bulk actions, specify `namespaceName` and `bucketName`\ \ in\nthe metadata property as shown in this example\n\n {\n \"\ identifier\": \"\"\n \"entityType\": \"bucket\",\n\ \ \"metadata\":\n {\n \"namespaceName\": \"sampleNamespace\"\ ,\n \"bucketName\": \"sampleBucket\"\n }\n }\n" type: object required: - identifier - entityType BulkActionResourceType: properties: metadataKeys: description: 'List of metadata keys required to identify a specific resource. Some resource-types require information besides an OCID to identify a specific resource. For example, the resource-type `buckets` requires metadataKeys ["namespaceName", "bucketName"] to identify a specific bucket. The required information to identify a resource is in the API documentation for the resource-type. For example, the required information for `buckets` is found in the [DeleteBucket API](#/en/objectstorage/20160918/Bucket/DeleteBucket). ' items: maxLength: 255 minLength: 1 type: string type: array name: description: 'The unique name of the resource-type. ' maxLength: 255 minLength: 1 type: string required: - name type: object BulkActionResourceTypeCollection: description: 'Collection of resource-types supported by a compartment bulk action. ' properties: items: description: Collection of the resource-types supported by a compartment bulk action. items: $ref: '#/definitions/BulkActionResourceType' type: array required: - items type: object BulkDeleteResourcesDetails: properties: resources: description: 'The resources to be deleted. ' items: $ref: '#/definitions/BulkActionResource' type: array required: - resources type: object BulkDeleteTagsDetails: description: Properties for deleting tags in bulk properties: tagDefinitionIds: description: The OCIDs of the tag definitions to delete items: type: string type: array uniqueItems: true required: - tagDefinitionIds BulkEditOperationDetails: properties: definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object operationType: description: 'An enum-like description of the type of operation. * `ADD_WHERE_ABSENT` adds a defined tag only if the tag does not already exist on the resource. * `SET_WHERE_PRESENT` updates the value for a defined tag only if the tag is present on the resource. * `ADD_OR_SET` combines the first two operations to add a defined tag if it does not already exist on the resource or update the value for a defined tag only if the tag is present on the resource. * `REMOVE` removes the defined tag from the resource. The tag is removed from the resource regardless of the tag value. ' enum: - ADD_WHERE_ABSENT - SET_WHERE_PRESENT - ADD_OR_SET - REMOVE type: string required: - operationType - definedTags type: object BulkEditResource: properties: id: description: The unique OCID of the resource. type: string metadata: additionalProperties: description: Additional information that helps to identify the resource. type: string description: 'Additional information that identifies the resource for bulk editing of tags. This information is provided in the resource''s API documentation. ' example: "UPDATE API for bucket require 'namespaceName' and 'bucketName'.\n\ https://docs.cloud.oracle.com/en-us/iaas/api/#/en/objectstorage/20160918/Bucket/DeleteBucket\n\ https://docs.cloud.oracle.com/en-us/iaas/api/#/en/objectstorage/20160918/Bucket/UpdateBucket\n\ \nTo add a bucket for bulk actions, specify 'namespaceName' and 'bucketName'\ \ in\nthe metadata property:\n{\n \"identifier\": \"ocid_of_bucket\"\n\ \ \"entityType\": \"bucket\",\n \"metadata\":\n {\n \"namespaceName\"\ : \"sampleNamespace\",\n \"bucketName\": \"sampleBucket\"\n }\n}\n" type: object resourceType: description: The type of resource. See [BulkEditResourceTypes](#/en/identity/latest/BulkEditTagsResourceTypeCollection/ListBulkEditTagsResourceTypes). type: string required: - id - resourceType type: object BulkEditTagsDetails: properties: bulkEditOperations: description: 'The operations associated with the request to bulk edit tags. ' items: $ref: '#/definitions/BulkEditOperationDetails' type: array compartmentId: description: 'The OCID of the compartment where the bulk tag edit request is submitted. ' type: string resources: description: 'The resources to be updated. ' items: $ref: '#/definitions/BulkEditResource' type: array uniqueItems: true required: - compartmentId - resources - bulkEditOperations type: object BulkEditTagsResourceType: properties: metadataKeys: description: 'The metadata keys required to identify the resource. For example, for a bucket, the value of `metadataKeys` will be ["namespaceName", "bucketName"]. This information will match the API documentation. See [UpdateBucket](/api/#/en/objectstorage/latest/Bucket/UpdateBucket) and [DeleteBucket](/api/#/en/objectstorage/latest/Bucket/DeleteBucket). ' items: maxLength: 255 minLength: 1 type: string type: array resourceType: description: 'The unique name of the resource type. ' maxLength: 255 minLength: 1 type: string required: - resourceType type: object BulkEditTagsResourceTypeCollection: description: 'The list of resource types that support bulk editing of tags. ' properties: items: description: The collection of resource types that support bulk editing of tags. items: $ref: '#/definitions/BulkEditTagsResourceType' type: array required: - items type: object BulkMoveResourcesDetails: properties: resources: description: 'The resources to be moved. ' items: $ref: '#/definitions/BulkActionResource' type: array targetCompartmentId: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the destination compartment into which to move the resources. ' maxLength: 255 minLength: 1 type: string required: - resources - targetCompartmentId type: object ChangeDomainCompartmentDetails: properties: compartmentId: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the destination compartment into which to move the identity domain. ' maxLength: 100 minLength: 1 type: string required: - compartmentId type: object ChangeDomainFaPodBaseUrlDetails: description: (For tenancies that support identity domains) Details for updating the fa pod base url of the identity domain. properties: faPodBaseUrl: description: The fa pod base url of the identity domain. maxLength: 256 minLength: 5 type: string ChangeDomainLicenseTypeDetails: description: (For tenancies that support identity domains) Details for updating the license type of the identity domain. properties: licenseType: description: The license type of the identity domain. maxLength: 64 minLength: 1 type: string ChangeTagNamespaceCompartmentDetail: description: 'Details of the compartment the resource is being moved to. ' properties: compartmentId: description: The Oracle Cloud ID (OCID) of the destination compartment. maxLength: 255 minLength: 1 type: string required: - compartmentId ChangeTasDomainLicenseTypeDetails: description: (For tenancies that support identity domains) Update the identity domain license type. properties: licenseType: description: The license type of the identity domain. maxLength: 64 minLength: 1 type: string Compartment: description: 'A collection of related resources. Compartments are a fundamental component of Oracle Cloud Infrastructure for organizing and isolating your cloud resources. You use them to clearly separate resources for the purposes of measuring usage and billing, access (through the use of IAM Service policies), and isolation (separating the resources for one project or business unit from another). A common approach is to create a compartment for each major part of your organization. For more information, see [Overview of IAM](//Content/Identity/getstarted/identity-domains.htm) and also [Setting Up Your Tenancy](/Content/GSG/Concepts/settinguptenancy.htm). To place a resource in a compartment, simply specify the compartment ID in the "Create" request object when initially creating the resource. For example, to launch an instance into a particular compartment, specify that compartment''s OCID in the `LaunchInstance` request. You can''t move an existing resource from one compartment to another. To use any of the API operations, you must be authorized in an IAM policy. If you''re not authorized, talk to an administrator. If you''re an administrator who needs to write policies to give users access, see [Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm). **Warning:** Oracle recommends that you avoid using any confidential information when you supply string values using the API. ' properties: compartmentId: description: The OCID of the parent compartment containing the compartment. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the compartment. Does not have to be unique, and it's changeable. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object id: description: The OCID of the compartment. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer isAccessible: description: 'Indicates whether or not the compartment is accessible for the user making the request. Returns true when the user has INSPECT permissions directly on a resource in the compartment or indirectly (permissions can be on a resource in a subcompartment). ' type: boolean lifecycleState: description: 'The compartment''s current state. After creating a compartment, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string name: description: 'The name you assign to the compartment during creation. The name must be unique across all compartments in the parent. Avoid entering confidential information. ' maxLength: 100 minLength: 1 type: string timeCreated: description: 'Date and time the compartment was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - compartmentId - name - description - timeCreated - lifecycleState CreateApiKeyDetails: properties: key: description: The public key. Must be an RSA key in PEM format. type: string required: - key CreateAuthTokenDetails: properties: description: description: 'The description you assign to the auth token during creation. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' maxLength: 400 minLength: 1 type: string required: - description CreateCompartmentDetails: properties: compartmentId: description: The OCID of the parent compartment containing the compartment. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the compartment during creation. Does not have to be unique, and it''s changeable. ' maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object name: description: 'The name you assign to the compartment during creation. The name must be unique across all compartments in the parent compartment. Avoid entering confidential information. ' maxLength: 100 minLength: 1 type: string required: - name - compartmentId - description CreateCustomerSecretKeyDetails: properties: displayName: description: 'The name you assign to the secret key during creation. Does not have to be unique, and it''s changeable. ' maxLength: 200 minLength: 1 type: string required: - displayName CreateDbCredentialDetails: properties: description: description: 'The description you assign to the DB credentials during creation. (For tenancies that support identity domains) You can have an empty description. ' type: string password: description: 'The password for the DB credentials during creation. ' type: string required: - password - description CreateDomainDetails: description: (For tenancies that support identity domains) Details for creating an identity domain. properties: adminEmail: description: The administrator's email address. maxLength: 256 minLength: 5 type: string adminFirstName: description: The administrator's first name. maxLength: 150 minLength: 1 type: string adminLastName: description: The administrator's last name. maxLength: 150 minLength: 1 type: string adminUserName: description: The administrator's user name. maxLength: 256 minLength: 1 type: string compartmentId: description: The OCID of the compartment where the identity domain is created. maxLength: 100 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The identity domain description. You can have an empty description. maxLength: 400 minLength: 1 type: string displayName: description: The mutable display name of the identity domain. maxLength: 100 minLength: 1 type: string faPodBaseUrl: description: The fa pod base url of the identity domain. maxLength: 256 minLength: 5 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object homeRegion: description: 'The region''s name identifier. See [Regions and Availability Domains](/Content/General/Concepts/regions.htm) for the full list of supported region names. Example: `us-phoenix-1` ' maxLength: 50 minLength: 1 type: string isHiddenOnLogin: description: 'Indicates whether the identity domain is hidden on the sign-in screen or not. ' type: boolean isNotificationBypassed: description: 'Indicates whether or not the administrator user created in the IDCS stripe would like to receive notifications like a welcome email. This field is required only if admin information is provided. This field is otherwise optional. ' type: boolean isPrimaryEmailRequired: description: 'Optional field to indicate whether users in the identity domain are required to have a primary email address or not. The default is true. ' type: boolean licenseType: description: The license type of the identity domain. maxLength: 64 minLength: 1 type: string required: - compartmentId - displayName - description - homeRegion - licenseType CreateDynamicGroupDetails: description: Properties for creating a dynamic group. properties: compartmentId: description: The OCID of the tenancy containing the group. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the group during creation. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object matchingRule: description: 'The matching rule to dynamically match an instance certificate to this dynamic group. For rule syntax, see [Managing Dynamic Groups](/Content/Identity/dynamicgroups/managingdynamicgroups.htm). ' maxLength: 100000 minLength: 1 type: string name: description: 'The name you assign to the group during creation. The name must be unique across all groups in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string required: - name - compartmentId - matchingRule - description CreateGroupDetails: properties: compartmentId: description: The OCID of the tenancy containing the group. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the group during creation. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object name: description: 'The name you assign to the group during creation. The name must be unique across all groups in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string required: - name - compartmentId - description CreateIdentityProviderDetails: discriminator: protocol properties: compartmentId: description: The OCID of your tenancy. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the `IdentityProvider` during creation. Does not have to be unique, and it''s changeable. ' maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object name: description: 'The name you assign to the `IdentityProvider` during creation. The name must be unique across all `IdentityProvider` objects in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string productType: description: 'The identity provider service or product. Supported identity providers are Oracle Identity Cloud Service (IDCS) and Microsoft Active Directory Federation Services (ADFS). Example: `IDCS` ' enum: - IDCS - ADFS type: string protocol: description: 'The protocol used for federation. Example: `SAML2` ' enum: - SAML2 - ADFS type: string required: - name - compartmentId - productType - description - protocol CreateIdpGroupMappingDetails: properties: groupId: description: 'The OCID of the IAM Service [group](#/en/identity/20160918/Group/) you want to map to the IdP group. ' type: string idpGroupName: description: The name of the IdP group you want to map. type: string required: - idpGroupName - groupId CreateNetworkSourceDetails: description: 'Properties for creating a network source object. ' properties: compartmentId: description: The OCID of the tenancy (root compartment) containing the network source object. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the network source during creation. Does not have to be unique, and it's changeable. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object name: description: 'The name you assign to the network source during creation. The name must be unique across all groups in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string publicSourceList: description: 'A list of allowed public IP addresses and CIDR ranges. ' items: type: string maxItems: 100 minItems: 0 type: array services: description: '-- The services attribute has no effect and is reserved for use by Oracle. -- ' items: type: string maxItems: 1 minItems: 1 type: array virtualSourceList: description: 'A list of allowed VCN OCID and IP range pairs. Example:`"vcnId": "ocid1.vcn.oc1.iad.aaaaaaaaexampleuniqueID", "ipRanges": [ "129.213.39.0/24" ]` ' items: properties: ipRanges: items: type: string type: array vcnId: type: string type: object maxItems: 100 minItems: 0 type: array required: - name - compartmentId - description CreateOAuth2ClientCredentialDetails: properties: description: description: Description of the oauth credential to help user differentiate them. type: string name: description: Name of the oauth credential to help user differentiate them. type: string scopes: description: Allowed scopes for the given oauth credential. items: $ref: '#/definitions/FullyQualifiedScope' type: array required: - name - description - scopes CreatePolicyDetails: properties: compartmentId: description: The OCID of the compartment containing the policy (either the tenancy or another compartment). type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the policy during creation. Does not have to be unique, and it''s changeable. ' maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object locks: description: Locks associated with this resource. items: $ref: '#/definitions/AddPolicyLockDetails' maxItems: 1 type: array name: description: 'The name you assign to the policy during creation. The name must be unique across all policies in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string statements: description: 'An array of policy statements written in the policy language. See [How Policies Work](/Content/Identity/policieshow/how-policies-work.htm) and [Common Policies](/Content/Identity/policiescommon/commonpolicies.htm). ' items: type: string type: array versionDate: description: 'The version of the policy. If null or set to an empty string, when a request comes in for authorization, the policy will be evaluated according to the current behavior of the services at that moment. If set to a particular date (YYYY-MM-DD), the policy will be evaluated according to the behavior of the services on that date. ' format: date-time type: string required: - name - compartmentId - statements - description CreateRegionSubscriptionDetails: properties: regionKey: description: 'The regions''s key. See [Regions and Availability Domains](/Content/General/Concepts/regions.htm) for the full list of supported 3-letter region codes. Example: `PHX` ' maxLength: 16 minLength: 1 type: string required: - regionKey CreateSaml2IdentityProviderDetails: allOf: - $ref: '#/definitions/CreateIdentityProviderDetails' - discriminator: SAML2 properties: authnContextClassRefs: description: 'Authentication contexts requested when sending a SAML request to the identity provider. There could be one or more requested contexts. Usually identity provider uses the one that has the highest authentication strength. Example: `["urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport", "urn:oasis:names:tc:SAML:2.0:ac:classes:TLSClient"]` ' items: type: string type: array encryptAssertion: description: 'When set to true, the service provider expects the SAML assertion to be encrypted by the identity provider, using the service provider''s encryption key. In this case, the service provider is Oracle Cloud Infrastructure Authentication service. ' type: boolean forceAuthentication: description: 'If set to true, when the user is redirected to the identity provider, the identity provider forces the user to provide credentials and re-authenticate, even if there is an active login session. ' type: boolean freeformAttributes: additionalProperties: type: string description: 'Extra name value pairs associated with this identity provider. Example: `{"clientId": "app_sf3kdjf3"}` ' type: object metadata: description: 'The XML that contains the information required for federating. ' maxLength: 100000 minLength: 1 type: string metadataUrl: description: 'The URL for retrieving the identity provider''s metadata, which contains information required for federating. ' maxLength: 512 minLength: 1 type: string required: - metadataUrl - metadata CreateSmtpCredentialDetails: properties: description: description: 'The description you assign to the SMTP credentials during creation. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' maxLength: 400 minLength: 1 type: string required: - description CreateSwiftPasswordDetails: properties: description: description: 'The description you assign to the Swift password during creation. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' maxLength: 400 minLength: 1 type: string required: - description CreateTagDefaultDetails: properties: compartmentId: description: 'The OCID of the compartment. The tag default will be applied to all new resources created in this compartment. ' type: string isRequired: description: 'If you specify that a value is required, a value is set during resource creation (either by the user creating the resource or another tag defualt). If no value is set, resource creation is blocked. * If the `isRequired` flag is set to "true", the value is set during resource creation. * If the `isRequired` flag is set to "false", the value you enter is set during resource creation. Example: `false` ' type: boolean locks: description: Locks associated with this resource. items: $ref: '#/definitions/AddLockDetails' maxItems: 1 type: array tagDefinitionId: description: 'The OCID of the tag definition. The tag default will always assign a default value for this tag definition. ' type: string value: description: 'The default value for the tag definition. This will be applied to all new resources created in the compartment. ' type: string required: - compartmentId - tagDefinitionId - value x-example: "{\n \"compartmentId\" : \"ocid1.compartment.oc1..<unique_ID>\"\ ,\n \"tagDefinitionId\" : \"ocid1.tagdefinition.oc1..<unique_ID>\"\ ,\n \"value\" : \"W123\",\n \"isRequired\" : \"false\"\n}\n" CreateTagDetails: properties: definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the tag during creation. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object isCostTracking: description: 'Indicates whether the tag is enabled for cost tracking. ' type: boolean name: description: 'The name you assign to the tag during creation. This is the tag key definition. The name must be unique within the tag namespace and cannot be changed. ' maxLength: 100 minLength: 1 type: string validator: $ref: '#/definitions/BaseTagDefinitionValidator' required: - name - description CreateTagNamespaceDetails: properties: compartmentId: description: The OCID of the tenancy containing the tag namespace. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the tag namespace during creation. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object locks: description: Locks associated with this resource. items: $ref: '#/definitions/AddLockDetails' maxItems: 1 type: array name: description: 'The name you assign to the tag namespace during creation. It must be unique across all tag namespaces in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string required: - name - compartmentId - description CreateUserDetails: properties: compartmentId: description: The OCID of the tenancy containing the user. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the user during creation. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' maxLength: 400 minLength: 1 type: string email: description: 'The email you assign to the user during creation. The email must be unique across all users in the tenancy. (For tenancies that support identity domains) You must provide an email for each user. ' maxLength: 254 minLength: 0 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object name: description: 'The name you assign to the user during creation. This is the user''s login for the Console. The name must be unique across all users in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string required: - name - compartmentId - description CustomerSecretKey: description: 'A `CustomerSecretKey` is an Oracle-provided key for using the Object Storage Service''s [Amazon S3 compatible API](/Content/Object/Tasks/s3compatibleapi.htm). The key consists of a secret key/access key pair. A user can have up to two secret keys at a time. **Note:** The secret key is always an Oracle-generated string; you can''t change it to a string of your choice. For more information, see [Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm). ' properties: displayName: description: The display name you assign to the secret key. Does not have to be unique, and it's changeable. type: string id: description: The access key portion of the key pair. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer key: description: 'The secret key. ' type: string lifecycleState: description: 'The secret key''s current state. After creating a secret key, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string timeCreated: description: 'Date and time the `CustomerSecretKey` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeExpires: description: 'Date and time when this password will expire, in the format defined by RFC3339. Null if it never expires. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user the password belongs to. type: string CustomerSecretKeySummary: description: 'As the name suggests, a `CustomerSecretKeySummary` object contains information about a `CustomerSecretKey`. A `CustomerSecretKey` is an Oracle-provided key for using the Object Storage Service''s Amazon S3 compatible API. ' properties: displayName: description: The displayName you assign to the secret key. Does not have to be unique, and it's changeable. type: string id: description: The OCID of the secret key. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The secret key''s current state. After creating a secret key, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string timeCreated: description: 'Date and time the `CustomerSecretKey` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeExpires: description: 'Date and time when this password will expire, in the format defined by RFC3339. Null if it never expires. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user the password belongs to. type: string DbCredential: description: 'Database credentials are needed for onboarding cloud database to identity. The DB credentials are used for DB authentication with the service. ' properties: id: description: The OCID of the DB credential. type: string lifecycleDetails: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The credential''s current state. After creating a DB credential, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string timeCreated: description: 'Date and time the `DbCredential` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeExpires: description: 'Date and time when this credential will expire, in the format defined by RFC3339. Null if it never expires. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user the DB credential belongs to. type: string DbCredentialSummary: description: 'As the name suggests, an `DbCredentialSummary` object contains information about an `DbCredential`. The DB credential is used for DB authentication with the [DB Service]. ' properties: description: description: 'The description you assign to the DB credential. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' type: string id: description: The OCID of the DB credential. type: string lifecycleState: description: 'The credential''s current state. After creating a DB credential, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' maxLength: 64 minLength: 1 type: string x-obmcs-enumref: '#/definitions/DbCredential/lifecycleState' timeCreated: description: 'Date and time the `DbCredential` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeExpires: description: 'Date and time when this credential will expire, in the format defined by RFC3339. Null if it never expires. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user the DB credential belongs to. type: string DefaultTagDefinitionValidator: allOf: - $ref: '#/definitions/BaseTagDefinitionValidator' - discriminator: DEFAULT description: 'Use this validator to clear any existing validator on the tag key definition with the UpdateTag operation. Using this `validatorType` is the same as not setting any value on the validator field. The resultant value for `validatorType` returned in the response body is `null`. ' Domain: description: '(For tenancies that support identity domains) Properties for an identity domain. An identity domain is used to manage users and groups, integration standards, external identities, and secure application integration through Oracle Single Sign-on (SSO) configuration. ' properties: compartmentId: description: The OCID of the compartment containing the identity domain. maxLength: 100 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The identity domain description. You can have an empty description. maxLength: 400 minLength: 1 type: string displayName: description: The mutable display name of the identity domain. maxLength: 100 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object homeRegion: description: 'The home region for the identity domain. See [Regions and Availability Domains](/Content/General/Concepts/regions.htm) for the full list of supported region names. Example: `us-phoenix-1` ' maxLength: 50 minLength: 1 type: string homeRegionUrl: description: Region-specific identity domain URL. type: string id: description: The OCID of the identity domain. maxLength: 100 minLength: 1 type: string isHiddenOnLogin: description: 'Indicates whether the identity domain is hidden on the sign-in screen or not. ' type: boolean licenseType: description: The license type of the identity domain. maxLength: 64 minLength: 1 type: string lifecycleDetails: description: 'Any additional details about the current state of the identity domain. ' enum: - DEACTIVATING - ACTIVATING - UPDATING maxLength: 64 minLength: 1 type: string lifecycleState: description: 'The current state. ' enum: - CREATING - ACTIVE - DELETING - INACTIVE maxLength: 64 minLength: 1 type: string replicaRegions: description: The regions where replicas of the identity domain exist. items: $ref: '#/definitions/ReplicatedRegionDetails' type: array timeCreated: description: 'Date and time the identity domain was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string type: description: 'The type of the domain. ' enum: - DEFAULT - SECONDARY maxLength: 64 minLength: 1 type: string url: description: Region-agnostic identity domain URL. type: string required: - id - compartmentId - displayName - description - url - homeRegionUrl - homeRegion - replicaRegions - type - licenseType - isHiddenOnLogin - timeCreated - lifecycleState DomainReplication: description: (For tenancies that support identity domains) Identity domain replication states. properties: domainReplicationStates: description: The identity domain's replication state. items: $ref: '#/definitions/DomainReplicationStates' type: array opcWaterMark: description: The version number indicating the value of kievTxnId, starting from which the identity domain replication events need to be returned. format: long type: number txnSeqNumber: description: A custom value defining the order of records with the same kievTxnId. format: long type: number required: - opcWaterMark - txnSeqNumber - domainReplicationStates DomainReplicationStates: description: (For tenancies that support identity domains) The identity domain replication log for all identity domains for a given region. properties: domainId: description: The OCID of the identity domain. maxLength: 100 minLength: 1 type: string replicaRegion: description: The replica region for the identity domain. maxLength: 5 minLength: 1 type: string state: description: 'The IDCS-replicated region state. ' enum: - ENABLING_REPLICATION - REPLICATION_ENABLED - DISABLING_REPLICATION - REPLICATION_DISABLED - DELETED maxLength: 64 minLength: 1 type: string x-obmcs-enumref: '#/definitions/ReplicatedRegionDetails/state' required: - domainId - state - replicaRegion DomainSummary: description: '(For tenancies that support identity domains) As the name suggests, a `DomainSummary` object contains information about a `Domain`. ' properties: compartmentId: description: The OCID of the compartment containing the identity domain. maxLength: 100 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The identity domain description. You can have an empty description. maxLength: 400 minLength: 1 type: string displayName: description: The mutable display name of the identity domain. maxLength: 100 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object homeRegion: description: The home region for the identity domain. maxLength: 50 minLength: 1 type: string homeRegionUrl: description: Region-specific identity domain URL. type: string id: description: The OCID of the identity domain. maxLength: 100 minLength: 1 type: string isHiddenOnLogin: description: 'Indicates whether the identity domain is hidden on the sign-in screen or not. ' type: boolean licenseType: description: The license type of the identity domain. maxLength: 64 minLength: 1 type: string lifecycleDetails: description: 'Any additional details about the current state of the identity domain. ' enum: - DEACTIVATING - ACTIVATING - UPDATING maxLength: 64 minLength: 1 type: string lifecycleState: description: 'The current state. ' enum: - CREATING - ACTIVE - DELETING - INACTIVE maxLength: 64 minLength: 1 type: string x-obmcs-enumref: '#/definitions/Domain/lifecycleState' replicaRegions: description: The regions where replicas of the identity domain exist. items: $ref: '#/definitions/ReplicatedRegionDetails' type: array timeCreated: description: 'Date and time the identity domain was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string type: description: 'The type of the identity domain. ' enum: - DEFAULT - SECONDARY maxLength: 64 minLength: 1 type: string x-obmcs-enumref: '#/definitions/Domain/type' url: description: Region-agnostic identity domain URL. type: string required: - id - compartmentId - displayName - description - url - homeRegionUrl - homeRegion - replicaRegions - type - licenseType - isHiddenOnLogin - timeCreated - lifecycleState DynamicGroup: description: 'A dynamic group defines a matching rule. Every bare metal or virtual machine instance is deployed with an instance certificate. The certificate contains metadata about the instance. This includes the instance OCID and the compartment OCID, along with a few other optional properties. When an API call is made using this instance certificate as the authenticator, the certificate can be matched to one or multiple dynamic groups. The instance can then get access to the API based on the permissions granted in policies written for the dynamic groups. This works like regular user/group membership. But in that case, the membership is a static relationship, whereas in a dynamic group, the membership of an instance certificate to a dynamic group is determined during runtime. For more information, see [Managing Dynamic Groups](/Content/Identity/dynamicgroups/managingdynamicgroups.htm). **Warning:** Oracle recommends that you avoid using any confidential information when you supply string values using the API. ' properties: compartmentId: description: The OCID of the tenancy containing the group. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the group. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object id: description: The OCID of the group. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The group''s current state. After creating a group, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string matchingRule: description: 'A rule string that defines which instance certificates will be matched. For syntax, see [Managing Dynamic Groups](/Content/Identity/dynamicgroups/managingdynamicgroups.htm). ' maxLength: 100000 minLength: 1 type: string name: description: 'The name you assign to the group during creation. The name must be unique across all groups in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string timeCreated: description: 'Date and time the group was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - compartmentId - name - description - matchingRule - timeCreated - lifecycleState EnableReplicationToRegionDetails: description: (For tenancies that support identity domains) Identity domain replication request packet. properties: replicaRegion: description: 'A region to which you want identity domain replication to occur. See [Regions and Availability Domains](/Content/General/Concepts/regions.htm) for the full list of supported region names. Example: `us-phoenix-1` ' maxLength: 50 minLength: 1 type: string EnumTagDefinitionValidator: allOf: - $ref: '#/definitions/BaseTagDefinitionValidator' - discriminator: ENUM properties: values: description: 'The list of allowed values for a definedTag value. ' items: type: string type: array description: 'Used to validate the value set for a defined tag and contains the list of allowable `values`. You must specify at least one valid value in the `values` array. You can''t have blank or or empty strings (`""`). Duplicate values are not allowed. ' required: - values Error: properties: code: description: 'A short error code that defines the error, meant for programmatic parsing. See [API Errors](/Content/API/References/apierrors.htm). ' type: string message: description: A human-readable error string. type: string required: - code - message FaultDomain: description: 'A Fault Domain is a logical grouping of hardware and infrastructure within an Availability Domain that can become unavailable in its entirety either due to hardware failure such as Top-of-rack (TOR) switch failure or due to planned software maintenance such as security updates that reboot your instances. ' properties: availabilityDomain: description: The name of the availabilityDomain where the Fault Domain belongs. type: string compartmentId: description: The OCID of the compartment. Currently only tenancy (root) compartment can be provided. type: string id: description: The OCID of the Fault Domain. type: string name: description: The name of the Fault Domain. type: string FullyQualifiedScope: properties: audience: description: Audience for the given scope context. type: string scope: description: Allowed permission scope for the given context. type: string required: - audience - scope Group: description: 'A collection of users who all need the same type of access to a particular set of resources or compartment. For conceptual information about groups and other IAM Service components, see [Overview of IAM](/Content/Identity/getstarted/identity-domains.htm). If you''re federating with an identity provider (IdP), you need to create mappings between the groups defined in the IdP and groups you define in the IAM service. For more information, see [Identity Providers and Federation](/Content/Identity/Concepts/federation.htm). Also see [IdentityProvider](#/en/identity/20160918/IdentityProvider/) and [IdpGroupMapping](#/en/identity/20160918/IdpGroupMapping/). To use any of the API operations, you must be authorized in an IAM policy. If you''re not authorized, talk to an administrator. If you''re an administrator who needs to write policies to give users access, see [Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm). **Warning:** Oracle recommends that you avoid using any confidential information when you supply string values using the API. ' properties: compartmentId: description: The OCID of the tenancy containing the group. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the group. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object id: description: The OCID of the group. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The group''s current state. After creating a group, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string name: description: 'The name you assign to the group during creation. The name must be unique across all groups in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string timeCreated: description: 'Date and time the group was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - compartmentId - name - description - timeCreated - lifecycleState IamWorkRequest: description: '(For tenancies that support identity domains) An IAM work request object that allows users to track the status of asynchronous API requests. ' properties: compartmentId: description: The OCID of the compartment containing this IAM work request. maxLength: 100 minLength: 1 type: string id: description: The OCID of the work request. maxLength: 100 minLength: 1 type: string operationType: description: The asynchronous operation tracked by this IAM work request. enum: - CREATE_DOMAIN - REPLICATE_DOMAIN_TO_REGION - UPDATE_DOMAIN - ACTIVATE_DOMAIN - DEACTIVATE_DOMAIN - DELETE_DOMAIN - CHANGE_COMPARTMENT_FOR_DOMAIN - CHANGE_LICENSE_TYPE_FOR_DOMAIN maxLength: 34 minLength: 1 type: string percentComplete: description: 'How much progress the operation has made. ' format: float maximum: 100 minimum: 1 type: number resources: description: The resources this work request affects. items: $ref: '#/definitions/IamWorkRequestResource' type: array status: description: The status of the work request. enum: - ACCEPTED - IN_PROGRESS - FAILED - SUCCEEDED - CANCELING - CANCELED maxLength: 15 minLength: 1 type: string timeAccepted: description: 'Date and time the work was accepted, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeFinished: description: 'Date and time the work completed, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeStarted: description: 'Date and time the work started, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - operationType - status IamWorkRequestErrorSummary: description: '(For tenancies that support identity domains) An error encountered while executing an operation that is tracked by a IAM work request. ' properties: code: description: A machine-usable code for the error that occured. maxLength: 32 minLength: 1 type: string message: description: A human-readable error string. maxLength: 4000 minLength: 1 type: string timestamp: description: The date and time the error occurred. format: date-time type: string required: - code - message - timestamp x-example: "{\n \"code\" : \"InternalError\",\n \"message\" : \"Launch instance\ \ failed, Retrying failed to complete successfully after 5 attempts.\",\n \"\ timestamp\" : \"2019-05-07T01:04:43.543Z\"\n}\n" IamWorkRequestLogSummary: description: '(For tenancies that support identity domains) The log entity for a IAM work request. ' properties: message: description: A human-readable error string. maxLength: 4000 minLength: 1 type: string timestamp: description: 'Date and time the log was written, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - message IamWorkRequestResource: description: (For tenancies that support identity domains) A IAM work request resource entry. properties: actionType: description: 'The way in which this resource is affected by the work tracked in the work request. A resource being created, updated, or deleted will remain in the IN_PROGRESS state until work is complete for that resource at which point it will transition to CREATED, UPDATED, or DELETED, respectively. ' enum: - CREATED - UPDATED - DELETED - RELATED - IN_PROGRESS maxLength: 11 minLength: 1 type: string entityType: description: The resource type the work request is affects. maxLength: 32 minLength: 1 type: string entityUri: description: The URI path that the user can do a GET on to access the resource metadata. maxLength: 1000 minLength: 1 type: string identifier: description: An OCID of the resource that the work request affects. maxLength: 100 minLength: 1 type: string required: - actionType - entityType - identifier IamWorkRequestSummary: description: '(For tenancies that support identity domains) The IAM work request summary. Tracks the status of asynchronous operations. ' properties: compartmentId: description: The OCID of the compartment containing this IAM work request. maxLength: 100 minLength: 1 type: string id: description: The OCID of the work request. maxLength: 100 minLength: 1 type: string operationType: description: The asynchronous operation tracked by this IAM work request. enum: - CREATE_DOMAIN - REPLICATE_DOMAIN_TO_REGION - UPDATE_DOMAIN - ACTIVATE_DOMAIN - DEACTIVATE_DOMAIN - DELETE_DOMAIN - CHANGE_COMPARTMENT_FOR_DOMAIN - CHANGE_LICENSE_TYPE_FOR_DOMAIN maxLength: 34 minLength: 1 type: string percentComplete: description: 'How much progress the operation has made. ' format: float maximum: 100 minimum: 1 type: number resources: description: The resources this work request affects. items: $ref: '#/definitions/IamWorkRequestResource' type: array status: description: The status of the work request. enum: - ACCEPTED - IN_PROGRESS - FAILED - SUCCEEDED - CANCELING - CANCELED maxLength: 15 minLength: 1 type: string timeAccepted: description: 'Date and time the work was accepted, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeFinished: description: 'Date and time the work completed, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeStarted: description: 'Date and time the work started, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - operationType - status IdentityProvider: description: 'The resulting base object when you add an identity provider to your tenancy. A [Saml2IdentityProvider](#/en/identity/20160918/Saml2IdentityProvider/) is a specific type of `IdentityProvider` that supports the SAML 2.0 protocol. Each `IdentityProvider` object has its own OCID. For more information, see [Identity Providers and Federation](/Content/Identity/Concepts/federation.htm). To use any of the API operations, you must be authorized in an IAM policy. If you''re not authorized, talk to an administrator. If you''re an administrator who needs to write policies to give users access, see [Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm). **Warning:** Oracle recommends that you avoid using any confidential information when you supply string values using the API. ' discriminator: protocol properties: compartmentId: description: The OCID of the tenancy containing the `IdentityProvider`. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the `IdentityProvider` during creation. Does not have to be unique, and it''s changeable. ' maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object id: description: The OCID of the `IdentityProvider`. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The current state. After creating an `IdentityProvider`, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string name: description: 'The name you assign to the `IdentityProvider` during creation. The name must be unique across all `IdentityProvider` objects in the tenancy and cannot be changed. This is the name federated users see when choosing which identity provider to use when signing in to the Oracle Cloud Infrastructure Console. ' maxLength: 100 minLength: 1 type: string productType: description: 'The identity provider service or product. Supported identity providers are Oracle Identity Cloud Service (IDCS) and Microsoft Active Directory Federation Services (ADFS). Allowed values are: - `ADFS` - `IDCS` Example: `IDCS` ' maxLength: 64 minLength: 1 type: string protocol: description: 'The protocol used for federation. Allowed value: `SAML2`. Example: `SAML2` ' maxLength: 64 minLength: 1 type: string timeCreated: description: 'Date and time the `IdentityProvider` was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - compartmentId - name - description - productType - timeCreated - lifecycleState - protocol IdentityProviderGroupSummary: description: 'A group created in an identity provider that can be mapped to a group in OCI ' properties: displayName: description: Display name of the group type: string externalIdentifier: description: Identifier of the group in the identity provider type: string id: description: The OCID of the `IdentityProviderGroup`. type: string identityProviderId: description: The OCID of the `IdentityProvider` this group belongs to. type: string name: description: Display name of the group type: string timeCreated: description: 'Date and time the `IdentityProviderGroup` was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeModified: description: 'Date and time the `IdentityProviderGroup` was last modified, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string IdpGroupMapping: description: 'A mapping between a single group defined by the identity provider (IdP) you''re federating with and a single IAM Service [group](#/en/identity/20160918/Group/) in Oracle Cloud Infrastructure. For more information about group mappings and what they''re for, see [Identity Providers and Federation](/Content/Identity/Concepts/federation.htm). A given IdP group can be mapped to zero, one, or multiple IAM Service groups, and vice versa. But each `IdPGroupMapping` object is between only a single IdP group and IAM Service group. Each `IdPGroupMapping` object has its own OCID. **Note:** Any users who are in more than 50 IdP groups cannot be authenticated to use the Oracle Cloud Infrastructure Console. ' properties: compartmentId: description: The OCID of the tenancy containing the `IdentityProvider`. type: string groupId: description: The OCID of the IAM Service group that is mapped to the IdP group. type: string id: description: The OCID of the `IdpGroupMapping`. type: string idpGroupName: description: The name of the IdP group that is mapped to the IAM Service group. type: string idpId: description: The OCID of the `IdentityProvider` this mapping belongs to. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The mapping''s current state. After creating a mapping object, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string timeCreated: description: 'Date and time the mapping was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - idpId - idpGroupName - groupId - compartmentId - timeCreated - lifecycleState ImportStandardTagsDetails: properties: compartmentId: description: 'The OCID of the compartment where the bulk create request is submitted and where the tag namespaces will be created. ' type: string standardTagNamespaceName: description: 'The name of standard tag namespace that will be imported in bulk ' type: string required: - compartmentId - standardTagNamespaceName type: object MfaTotpDevice: description: 'Users can enable multi-factor authentication (MFA) for their own user accounts. After MFA is enabled, the user is prompted for a time-based one-time password (TOTP) to authenticate before they can sign in to the Console. To enable multi-factor authentication, the user must register a mobile device with a TOTP authenticator app installed. The registration process creates the `MfaTotpDevice` object. The registration process requires interaction with the Console and cannot be completed programmatically. For more information, see [Managing Multi-Factor Authentication](/Content/Identity/mfa/understand-multi-factor-authentication.htm). ' properties: id: description: The OCID of the MFA TOTP device. type: string inactiveStatus: description: "The detailed status of INACTIVE lifecycleState.\nAllowed values\ \ are:\n - 1 - SUSPENDED\n - 2 - DISABLED\n - 4 - BLOCKED\n - 8 - LOCKED\n" format: int64 type: integer isActivated: description: Flag to indicate if the MFA TOTP device has been activated. type: boolean lifecycleState: description: 'The MFA TOTP device''s current state. After creating the MFA TOTP device, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string seed: description: 'The seed for the MFA TOTP device (Base32 encoded). ' type: string timeCreated: description: 'Date and time the `MfaTotpDevice` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeExpires: description: 'Date and time when this MFA TOTP device will expire, in the format defined by RFC3339. Null if it never expires. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user the MFA TOTP device belongs to. type: string required: - id - seed - userId - isActivated - timeCreated - lifecycleState MfaTotpDeviceSummary: description: 'As the name suggests, a `MfaTotpDeviceSummary` object contains information about a `MfaTotpDevice`. ' properties: id: description: The OCID of the MFA TOTP Device. type: string inactiveStatus: description: "The detailed status of INACTIVE lifecycleState.\nAllowed values\ \ are:\n - 1 - SUSPENDED\n - 2 - DISABLED\n - 4 - BLOCKED\n - 8 - LOCKED\n" format: int64 type: integer isActivated: description: Flag to indicate if the MFA TOTP device has been activated type: boolean lifecycleState: description: 'The MFA TOTP device''s current state. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string timeCreated: description: 'Date and time the `MfaTotpDevice` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeExpires: description: 'Date and time when this MFA TOTP device will expire, in the format defined by RFC3339. Null if it never expires. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user the MFA TOTP device belongs to. type: string required: - id - userId - isActivated - timeCreated - lifecycleState MfaTotpToken: description: 'Totp token for MFA ' properties: totpToken: description: 'The Totp token for MFA. ' type: string MoveCompartmentDetails: properties: targetCompartmentId: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the destination compartment into which to move the compartment. ' maxLength: 255 minLength: 1 type: string required: - targetCompartmentId type: object NetworkPolicy: description: 'Network policy, which consists of a list of network source IDs. ' properties: networkSourceIds: description: 'Network Source ids ' items: maxLength: 255 minLength: 1 type: string type: array NetworkSources: description: 'A network source specifies a list of source IP addresses that are allowed to make authorization requests. Use the network source in policy statements to restrict access to only requests that come from the specified IPs. For more information, see [Managing Network Sources](/Content/Identity/Tasks/managingnetworksources.htm). ' properties: compartmentId: description: The OCID of the tenancy containing the network source. The tenancy is the root compartment. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the network source. Does not have to be unique, and it's changeable. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object id: description: The OCID of the network source. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The network source object''s current state. After creating a network source, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string name: description: 'The name you assign to the network source during creation. The name must be unique across the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string publicSourceList: description: 'A list of allowed public IPs and CIDR ranges. ' items: type: string maxItems: 100 minItems: 0 type: array services: description: '-- The services attribute has no effect and is reserved for use by Oracle. -- ' items: type: string maxItems: 1 minItems: 1 type: array timeCreated: description: 'Date and time the network source was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string virtualSourceList: description: 'A list of allowed VCN OCID and IP range pairs. Example:`"vcnId": "ocid1.vcn.oc1.iad.aaaaaaaaexampleuniqueID", "ipRanges": [ "129.213.39.0/24" ]` ' items: properties: ipRanges: items: type: string type: array vcnId: type: string type: object maxItems: 100 minItems: 0 type: array required: - id - compartmentId - name - description - timeCreated - lifecycleState NetworkSourcesSummary: description: 'A network source specifies a list of source IP addresses that are allowed to make authorization requests. Use the network source in policy statements to restrict access to only requests that come from the specified IPs. For more information, see [Managing Network Sources](/Content/Identity/Tasks/managingnetworksources.htm). ' properties: compartmentId: description: The OCID of the tenancy (root compartment) containing the network source. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the network source. Does not have to be unique, and it's changeable. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object id: description: The OCID of the network source. type: string lifecycleState: description: 'The network source object''s current state. After creating a network source, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' type: string x-obmcs-enumref: '#/definitions/NetworkSources/lifecycleState' name: description: 'The name you assign to the network source during creation. The name must be unique across the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string publicSourceList: description: 'A list of allowed public IP addresses and CIDR ranges. ' items: type: string maxItems: 100 minItems: 0 type: array services: description: '-- The services attribute has no effect and is reserved for use by Oracle. -- ' items: type: string maxItems: 1 minItems: 1 type: array timeCreated: description: 'Date and time the network source was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string virtualSourceList: description: 'A list of allowed VCN OCID and IP range pairs. Example:`"vcnId": "ocid1.vcn.oc1.iad.aaaaaaaaexampleuniqueID", "ipRanges": [ "129.213.39.0/24" ]` ' items: properties: ipRanges: items: type: string type: array vcnId: type: string type: object maxItems: 100 minItems: 0 type: array required: - id - compartmentId - name - description - timeCreated - lifecycleState OAuth2ClientCredential: description: 'User can define Oauth clients in IAM, then use it to generate a token to grant access to app resources. ' properties: compartmentId: description: The OCID of the compartment containing the Oauth credential. type: string description: description: The description of the Oauth credential. type: string expiresOn: description: 'Date and time when this credential will expire, in the format defined by RFC3339. Null if it never expires. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string id: description: The OCID of the Oauth credential. type: string lifecycleState: description: 'The credential''s current state. After creating a Oauth credential, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED type: string name: description: The name of the Oauth credential. type: string password: description: Returned during create and update with password reset requests. type: string scopes: description: Allowed scopes for the given oauth credential. items: $ref: '#/definitions/FullyQualifiedScope' type: array timeCreated: description: 'Date and time the `OAuth2ClientCredential` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user the Oauth credential belongs to. type: string OAuth2ClientCredentialSummary: description: 'User can define Oauth clients in IAM, then use it to generate a token to grant access to app resources. ' properties: compartmentId: description: The OCID of the compartment containing the Oauth credential. type: string description: description: The description of the Oauth credential. type: string expiresOn: description: 'Date and time when this credential will expire, in the format defined by RFC3339. Null if it never expires. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string id: description: The OCID of the Oauth credential. type: string lifecycleState: description: 'The credential''s current state. After creating a Oauth credential, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED type: string name: description: The name of the Oauth credential. type: string scopes: description: Allowed scopes for the given oauth credential. items: $ref: '#/definitions/FullyQualifiedScope' type: array timeCreated: description: 'Date and time the `OAuth2ClientCredential` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user the Oauth credential belongs to. type: string PasswordPolicy: description: 'Password policy, currently set for the given compartment. ' properties: isLowercaseCharactersRequired: default: true description: At least one lower case character required. type: boolean isNumericCharactersRequired: default: true description: At least one numeric character required. type: boolean isSpecialCharactersRequired: default: true description: At least one special character required. type: boolean isUppercaseCharactersRequired: default: true description: At least one uppercase character required. type: boolean isUsernameContainmentAllowed: default: false description: User name is allowed to be part of the password. type: boolean minimumPasswordLength: default: 12 description: Minimum password length required. type: integer Policy: description: "A document that specifies the type of access a group has to the\ \ resources in a compartment. For information about\npolicies and other IAM\ \ Service components, see\n[Overview of IAM](/Content/Identity/getstarted/identity-domains.htm).\ \ If you're new to policies, see\n[Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm).\n\ \nThe word \"policy\" is used by people in different ways:\n\n * An individual\ \ statement written in the policy language\n * A collection of statements in\ \ a single, named \"policy\" document (which has an Oracle Cloud ID (OCID) assigned\ \ to it)\n * The overall body of policies your organization uses to control\ \ access to resources\n\nTo use any of the API operations, you must be authorized\ \ in an IAM policy. If you're not authorized,\ntalk to an administrator.\n\n\ **Warning:** Oracle recommends that you avoid using any confidential information\ \ when you supply string values\nusing the API.\n" properties: compartmentId: description: 'The OCID of the compartment containing the policy (either the tenancy or another compartment). ' type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the policy. Does not have to be unique, and it's changeable. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object id: description: The OCID of the policy. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The policy''s current state. After creating a policy, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string locks: description: Locks associated with this resource.This can be used only after your tenancy is whitelisted for this feature. items: $ref: '#/definitions/ResourceLockPolicy' type: array name: description: 'The name you assign to the policy during creation. The name must be unique across all policies in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string statements: description: An array of one or more policy statements written in the policy language. items: type: string type: array timeCreated: description: 'Date and time the policy was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string versionDate: description: 'The version of the policy. If null or set to an empty string, when a request comes in for authorization, the policy will be evaluated according to the current behavior of the services at that moment. If set to a particular date (YYYY-MM-DD), the policy will be evaluated according to the behavior of the services on that date. ' format: date-time type: string required: - id - compartmentId - name - statements - description - timeCreated - lifecycleState Region: description: 'A localized geographic area, such as Phoenix, AZ. Oracle Cloud Infrastructure is hosted in regions and Availability Domains. A region is composed of several Availability Domains. An Availability Domain is one or more data centers located within a region. For more information, see [Regions and Availability Domains](/Content/General/Concepts/regions.htm). To use any of the API operations, you must be authorized in an IAM policy. If you''re not authorized, talk to an administrator. If you''re an administrator who needs to write policies to give users access, see [Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm). ' properties: key: description: 'The key of the region. See [Regions and Availability Domains](/Content/General/Concepts/regions.htm) for the full list of supported 3-letter region codes. Example: `PHX` ' maxLength: 16 minLength: 1 type: string name: description: 'The name of the region. See [Regions and Availability Domains](/Content/General/Concepts/regions.htm) for the full list of supported region names. Example: `us-phoenix-1` ' maxLength: 16 minLength: 1 type: string RegionSubscription: description: 'An object that represents your tenancy''s access to a particular region (i.e., a subscription), the status of that access, and whether that region is the home region. For more information, see [Managing Regions](/Content/Identity/regions/managingregions.htm). To use any of the API operations, you must be authorized in an IAM policy. If you''re not authorized, talk to an administrator. If you''re an administrator who needs to write policies to give users access, see [Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm). ' properties: isHomeRegion: description: Indicates if the region is the home region or not. type: boolean regionKey: description: 'The region''s key. See [Regions and Availability Domains](/Content/General/Concepts/regions.htm) for the full list of supported 3-letter region codes. Example: `PHX` ' maxLength: 16 minLength: 1 type: string regionName: description: 'The region''s name. See [Regions and Availability Domains](/Content/General/Concepts/regions.htm) for the full list of supported region names. Example: `us-phoenix-1` ' maxLength: 16 minLength: 1 type: string status: description: The region subscription status. enum: - READY - IN_PROGRESS type: string required: - regionKey - regionName - status - isHomeRegion RemoveLockDetails: description: 'Request payload to remove lock to the resource. ' properties: type: description: Type of the lock. enum: - FULL - DELETE type: string required: - type type: object RemovePolicyLockDetails: description: 'Request payload to remove lock to the resource. ' properties: type: description: Type of the lock. enum: - FULL - DELETE type: string required: - type type: object ReplicatedRegionDetails: description: (For tenancies that support identity domains) Properties for a region where a replica for the identity domain exists. properties: region: description: 'A REPLICATION_ENABLED region, e.g. us-ashburn-1. See [Regions and Availability Domains](/Content/General/Concepts/regions.htm) for the full list of supported region names. ' maxLength: 50 minLength: 1 type: string regionalUrl: description: Region-specific identity domain URL. type: string state: description: 'The IDCS-replicated region state. ' enum: - ENABLING_REPLICATION - REPLICATION_ENABLED - DISABLING_REPLICATION - REPLICATION_DISABLED - DELETED maxLength: 64 minLength: 1 type: string url: description: Region-agnostic identity domain URL. type: string ResourceLock: description: 'Resource locks are used to prevent certain APIs from being called for the resource. A full lock prevents both updating the resource and deleting the resource. A delete lock prevents deleting the resource. ' properties: isActive: description: Indicates if the lock is active or not. For example, if there are mutliple FULL locks, the first-created FULL lock will be effective. type: boolean message: description: 'A message added by the creator of the lock. This is typically used to give an indication of why the resource is locked. ' type: string relatedResourceId: description: 'The ID of the resource that is locking this resource. Indicates that deleting this resource will remove the lock. ' type: string timeCreated: description: When the lock was created. format: date-time type: string type: description: Type of the lock. enum: - FULL - DELETE type: string required: - type type: object ResourceLockPolicy: description: 'Resource locks are used to prevent certain APIs from being called for the resource. A full lock prevents both updating the resource and deleting the resource. A delete lock prevents deleting the resource. ' properties: compartmentId: description: The compartment ID of the lock. type: string isActive: description: Indicates if the lock is active or not. For example, if there are mutliple FULL locks, the first-created FULL lock wi`ll be effective. type: boolean message: description: 'A message added by the creator of the lock. This is typically used to give an indication of why the resource is locked. ' type: string relatedResourceId: description: 'The ID of the resource that is locking this resource. Indicates that deleting this resource will remove the lock. ' type: string timeCreated: description: When the lock was created. format: date-time type: string type: description: Type of the lock. enum: - FULL - DELETE type: string required: - type type: object Saml2IdentityProvider: allOf: - $ref: '#/definitions/IdentityProvider' - discriminator: SAML2 properties: authnContextClassRefs: description: 'Authentication contexts requested when sending a SAML request to the identity provider. There could be one or more requested contexts. Usually identity provider uses the one that has the highest authentication strength. Example: `["urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport", "urn:oasis:names:tc:SAML:2.0:ac:classes:TLSClient"]` ' items: type: string type: array encryptAssertion: description: 'When set to true, the service provider expects the SAML assertion to be encrypted by the identity provider, using the service provider''s encryption key. In this case, the service provider is Oracle Cloud Infrastructure Authentication service. ' type: boolean forceAuthentication: description: 'If set to true, when the user is redirected to the identity provider, the identity provider forces the user to provide credentials and re-authenticate, even if there is an active login session. ' type: boolean freeformAttributes: additionalProperties: type: string description: 'Extra name value pairs associated with this identity provider. Example: `{"clientId": "app_sf3kdjf3"}` ' type: object metadataUrl: description: 'The URL for retrieving the identity provider''s metadata, which contains information required for federating. ' maxLength: 512 minLength: 1 type: string redirectUrl: description: 'The URL to redirect federated users to for authentication with the identity provider. ' maxLength: 512 minLength: 1 type: string signingCertificate: description: 'The identity provider''s signing certificate used by the IAM Service to validate the SAML2 token. ' maxLength: 10000 minLength: 1 type: string statusMessage: description: 'A status message for this identity provider. Example: SAML metadata for this identity provider has expired. ' type: string required: - signingCertificate - redirectUrl - metadataUrl description: 'A special type of [IdentityProvider](#/en/identity/20160918/IdentityProvider/) that supports the SAML 2.0 protocol. For more information, see [Identity Providers and Federation](/Content/Identity/Concepts/federation.htm). ' ScimClientCredentials: description: 'The OAuth2 client credentials. ' properties: clientId: description: The client identifier. type: string clientSecret: description: The client secret. type: string SmtpCredential: description: 'Simple Mail Transfer Protocol (SMTP) credentials are needed to send email through Email Delivery. The SMTP credentials are used for SMTP authentication with the service. The credentials never expire. A user can have up to 2 SMTP credentials at a time. **Note:** The credential set is always an Oracle-generated SMTP user name and password pair; you cannot designate the SMTP user name or the SMTP password. For more information, see [Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm#SMTP). ' properties: description: description: 'The description you assign to the SMTP credential. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' type: string id: description: The OCID of the SMTP credential. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The credential''s current state. After creating a SMTP credential, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string password: description: 'The SMTP password. ' type: string timeCreated: description: 'Date and time the `SmtpCredential` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeExpires: description: 'Date and time when this credential will expire, in the format defined by RFC3339. Null if it never expires. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user the SMTP credential belongs to. type: string username: description: 'The SMTP user name. ' type: string SmtpCredentialSummary: description: 'As the name suggests, an `SmtpCredentialSummary` object contains information about an `SmtpCredential`. The SMTP credential is used for SMTP authentication with the [Email Delivery Service](/Content/Email/Concepts/overview.htm). ' properties: description: description: 'The description you assign to the SMTP credential. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' type: string id: description: The OCID of the SMTP credential. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The credential''s current state. After creating a SMTP credential, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string timeCreated: description: 'Date and time the `SmtpCredential` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeExpires: description: 'Date and time when this credential will expire, in the format defined by RFC3339. Null if it never expires. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user the SMTP credential belongs to. type: string username: description: 'The SMTP user name. ' type: string StandardTagDefinitionTemplate: description: The template of the tag definition. This object includes necessary details to create the provided standard tag definition. properties: description: description: The default description of the tag namespace that users can use to create the tag definition type: string enumMutability: description: The mutability of the possible values list for enum tags. This will default to IMMUTABLE for string value tags enum: - IMMUTABLE - MUTABLE - APPENDABLE type: string isCostTracking: description: Is the tag a cost tracking tag. Default will be false as cost tracking tags have been deprecated type: boolean possibleValues: description: List of possible values. An optional parameter that will be present if the type of definition is enum. items: type: string type: array uniqueItems: true tagDefinitionName: description: The name of this standard tag definition type: string type: description: The type of tag definition. Enum or string. enum: - ENUM - STRING type: string required: - description - tagDefinitionName - type - isCostTracking type: object StandardTagNamespaceTemplate: description: The template of the standard tag namespace. This object includes necessary details to create the provided standard tag namespace. properties: description: description: The default description of the tag namespace that users can use to create the tag namespace type: string standardTagNamespaceName: description: The reserved name of this standard tag namespace type: string status: description: The status of the standard tag namespace type: string tagDefinitionTemplates: description: The template of the tag definition. This object includes necessary details to create the provided standard tag definition. items: $ref: '#/definitions/StandardTagDefinitionTemplate' type: array required: - standardTagNamespaceName - description - tagDefinitionTemplates - status type: object StandardTagNamespaceTemplateSummary: description: The template of the standard tag namespace. This object includes necessary details to create the provided standard tag namespace. properties: description: description: The default description of the tag namespace that users can use to create the tag namespace type: string standardTagNamespaceName: description: The reserved name of this standard tag namespace type: string status: description: The status of the standard tag namespace type: string required: - standardTagNamespaceName - description - status type: object SwiftPassword: description: '**Deprecated. Use [AuthToken](#/en/identity/20160918/AuthToken/) instead.** Swift is the OpenStack object storage service. A `SwiftPassword` is an Oracle-provided password for using a Swift client with the Object Storage Service. This password is associated with the user''s Console login. Swift passwords never expire. A user can have up to two Swift passwords at a time. **Note:** The password is always an Oracle-generated string; you can''t change it to a string of your choice. For more information, see [Managing User Credentials](/Content/Identity/Tasks/managingcredentials.htm). ' properties: description: description: The description you assign to the Swift password. Does not have to be unique, and it's changeable. type: string expiresOn: description: 'Date and time when this password will expire, in the format defined by RFC3339. Null if it never expires. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string id: description: The OCID of the Swift password. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The password''s current state. After creating a password, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string password: description: 'The Swift password. The value is available only in the response for `CreateSwiftPassword`, and not for `ListSwiftPasswords` or `UpdateSwiftPassword`. ' type: string timeCreated: description: 'Date and time the `SwiftPassword` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user the password belongs to. type: string Tag: description: 'A tag definition that belongs to a specific tag namespace. "Defined tags" must be set up in your tenancy before you can apply them to resources. For more information, see [Managing Tags and Tag Namespaces](/Content/Identity/Concepts/taggingoverview.htm). **Warning:** Oracle recommends that you avoid using any confidential information when you supply string values using the API. ' properties: compartmentId: description: The OCID of the compartment that contains the tag definition. maxLength: 100 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the tag. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object id: description: The OCID of the tag definition. maxLength: 100 minLength: 1 type: string isCostTracking: description: 'Indicates whether the tag is enabled for cost tracking. ' type: boolean isRetired: description: 'Indicates whether the tag is retired. See [Retiring Key Definitions and Namespace Definitions](/Content/Tagging/Tasks/managingtagsandtagnamespaces.htm#retiringkeys). ' type: boolean lifecycleState: description: The tag's current state. After creating a tag, make sure its `lifecycleState` is ACTIVE before using it. After retiring a tag, make sure its `lifecycleState` is INACTIVE before using it. If you delete a tag, you cannot delete another tag until the deleted tag's `lifecycleState` changes from DELETING to DELETED. enum: - ACTIVE - INACTIVE - DELETING - DELETED type: string name: description: 'The name assigned to the tag during creation. This is the tag key definition. The name must be unique within the tag namespace and cannot be changed. ' maxLength: 100 minLength: 1 type: string systemTags: additionalProperties: additionalProperties: description: 'The value of the tag. ' type: object description: 'Key-value pair representing a system tag key and value, scoped to a namespace. Example: `{"free-tier-retained" : "true"}` ' type: object description: 'The system tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"orcl-cloud": {"free-tier-retained": "true"}}` ' type: object tagNamespaceId: description: The OCID of the namespace that contains the tag definition. maxLength: 100 minLength: 1 type: string tagNamespaceName: description: 'The name of the tag namespace that contains the tag definition. ' maxLength: 100 minLength: 1 type: string timeCreated: description: 'Date and time the tag was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string validator: $ref: '#/definitions/BaseTagDefinitionValidator' required: - compartmentId - tagNamespaceId - tagNamespaceName - id - name - description - isRetired - timeCreated TagDefault: description: 'Tag defaults let you specify a default tag (tagnamespace.tag="value") to apply to all resource types in a specified compartment. The tag default is applied at the time the resource is created. Resources that exist in the compartment before you create the tag default are not tagged. The `TagDefault` object specifies the tag and compartment details. Tag defaults are inherited by child compartments. This means that if you set a tag default on the root compartment for a tenancy, all resources that are created in the tenancy are tagged. For more information about using tag defaults, see [Managing Tag Defaults](/Content/Tagging/Tasks/managingtagdefaults.htm). To use any of the API operations, you must be authorized in an IAM policy. If you''re not authorized, talk to an administrator. ' properties: compartmentId: description: 'The OCID of the compartment. The tag default applies to all new resources that get created in the compartment. Resources that existed before the tag default was created are not tagged. ' type: string id: description: The OCID of the tag default. type: string isRequired: description: 'If you specify that a value is required, a value is set during resource creation (either by the user creating the resource or another tag defualt). If no value is set, resource creation is blocked. * If the `isRequired` flag is set to "true", the value is set during resource creation. * If the `isRequired` flag is set to "false", the value you enter is set during resource creation. Example: `false` ' type: boolean lifecycleState: description: 'The tag default''s current state. After creating a `TagDefault`, make sure its `lifecycleState` is ACTIVE before using it. ' enum: - ACTIVE type: string locks: description: Locks associated with this resource. items: $ref: '#/definitions/ResourceLock' type: array tagDefinitionId: description: 'The OCID of the tag definition. The tag default will always assign a default value for this tag definition. ' type: string tagDefinitionName: description: 'The name used in the tag definition. This field is informational in the context of the tag default. ' type: string tagNamespaceId: description: 'The OCID of the tag namespace that contains the tag definition. ' type: string timeCreated: description: 'Date and time the `TagDefault` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string value: description: 'The default value for the tag definition. This will be applied to all resources created in the compartment. ' type: string required: - id - compartmentId - tagNamespaceId - tagDefinitionId - tagDefinitionName - value - timeCreated - isRequired x-example: "{\n \"id\" : \"ocid1.tagdefault.oc1..<unique_ID>\"\ ,\n \"compartmentId\" : \"ocid1.compartment.oc1..<unique_ID>\"\ ,\n \"tagNamespaceId\" : \"ocid1.namespace.oc1..<unique_ID>\"\ ,\n \"tagDefinitionId\" : \"ocid1.tagdefinition.oc1..<unique_ID>\"\ ,\n \"tagDefinitionName\" : \"Finance\",\n \"value\" : \"W123\",\n \"timeCreated\"\ \ : \"2018-11-22T19:00:00.000Z\",\n \"lifecycleState\" : \"ACTIVE\",\n \"\ isRequired\" : \"true\"\n}\n" TagDefaultSummary: description: 'Summary information for the specified tag default. ' properties: compartmentId: description: 'The OCID of the compartment. The tag default will apply to all new resources that are created in the compartment. ' type: string id: description: The OCID of the tag default. type: string isRequired: description: 'If you specify that a value is required, a value is set during resource creation (either by the user creating the resource or another tag defualt). If no value is set, resource creation is blocked. * If the `isRequired` flag is set to "true", the value is set during resource creation. * If the `isRequired` flag is set to "false", the value you enter is set during resource creation. Example: `false` ' type: boolean lifecycleState: description: 'The tag default''s current state. After creating a `TagDefault`, make sure its `lifecycleState` is ACTIVE before using it. ' enum: - ACTIVE type: string locks: description: Locks associated with this resource. items: $ref: '#/definitions/ResourceLock' type: array tagDefinitionId: description: 'The OCID of the tag definition. The tag default will always assign a default value for this tag definition. ' type: string tagDefinitionName: description: 'The name used in the tag definition. This field is informational in the context of the tag default. ' type: string tagNamespaceId: description: 'The OCID of the tag namespace that contains the tag definition. ' type: string timeCreated: description: 'Date and time the `TagDefault` object was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string value: description: 'The default value for the tag definition. This will be applied to all new resources created in the compartment. ' type: string required: - id - compartmentId - tagNamespaceId - tagDefinitionId - tagDefinitionName - value - timeCreated - isRequired x-example: "{\n \"id\" : \"ocid1.tagdefault.oc1..<unique_ID>\"\ ,\n \"compartmentId\" : \"ocid1.compartment.oc1..<unique_ID>\"\ ,\n \"tagNamespaceId\" : \"ocid1.namespace.oc1..<unique_ID>\"\ ,\n \"tagDefinitionId\" : \"ocid1.tagdefinition.oc1..<unique_ID>\"\ ,\n \"tagDefinitionName\" : \"Finance\",\n \"value\" : \"W123\",\n \"timeCreated\"\ \ : \"2018-11-22T19:00:00.000Z\",\n \"lifecycleState\" : \"ACTIVE\",\n \"\ isRequired\" : \"false\"\n}\n" TagNamespace: description: 'A managed container for defined tags. A tag namespace is unique in a tenancy. For more information, see [Managing Tags and Tag Namespaces](/Content/Tagging/Tasks/managingtagsandtagnamespaces.htm). **Warning:** Oracle recommends that you avoid using any confidential information when you supply string values using the API. ' properties: compartmentId: description: The OCID of the compartment that contains the tag namespace. maxLength: 100 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the tag namespace. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object id: description: The OCID of the tag namespace. maxLength: 100 minLength: 1 type: string isRetired: description: 'Whether the tag namespace is retired. See [Retiring Key Definitions and Namespace Definitions](/Content/Tagging/Tasks/managingtagsandtagnamespaces.htm#retiringkeys). ' type: boolean lifecycleState: description: The tagnamespace's current state. After creating a tagnamespace, make sure its `lifecycleState` is ACTIVE before using it. After retiring a tagnamespace, make sure its `lifecycleState` is INACTIVE before using it. enum: - ACTIVE - INACTIVE - DELETING - DELETED type: string locks: description: Locks associated with this resource. items: $ref: '#/definitions/ResourceLock' type: array name: description: 'The name of the tag namespace. It must be unique across all tag namespaces in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string systemTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only string, integer and boolean types are supported. ' type: object description: 'Key-value pair representing system tags'' keys and values scoped to a namespace. Example: `{"bar-key": "value"}` ' type: object description: 'Usage of system tag keys. These predefined keys are scoped to namespaces. Example: `{"orcl-cloud": {"free-tier-retained": "true"}}` ' type: object timeCreated: description: 'Date and time the tagNamespace was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - compartmentId - name - description - isRetired - timeCreated TagNamespaceSummary: description: 'A container for defined tags. ' properties: compartmentId: description: The OCID of the compartment that contains the tag namespace. type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the tag namespace. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object id: description: The OCID of the tag namespace. type: string isRetired: description: 'Whether the tag namespace is retired. For more information, see [Retiring Key Definitions and Namespace Definitions](/Content/Tagging/Tasks/managingtagsandtagnamespaces.htm#retiringkeys). ' type: boolean lifecycleState: description: The tagnamespace's current state. After creating a tagnamespace, make sure its `lifecycleState` is ACTIVE before using it. After retiring a tagnamespace, make sure its `lifecycleState` is INACTIVE before using it. type: string x-obmcs-enumref: '#/definitions/TagNamespace/lifecycleState' locks: description: Locks associated with this resource. items: $ref: '#/definitions/ResourceLock' type: array name: description: 'The name of the tag namespace. It must be unique across all tag namespaces in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string systemTags: additionalProperties: additionalProperties: description: 'The value of the tag. ' type: object description: 'Key-value pair representing a system tag key and value, scoped to a namespace. Example: `{"free-tier-retained" : "true"}` ' type: object description: 'The system tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"orcl-cloud": {"free-tier-retained": "true"}}` ' type: object timeCreated: description: 'Date and time the tag namespace was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string TagSummary: description: 'A tag definition that belongs to a specific tag namespace. ' properties: compartmentId: description: The OCID of the compartment that contains the tag definition. maxLength: 100 minLength: 1 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the tag. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object id: description: The OCID of the tag definition. maxLength: 100 minLength: 1 type: string isCostTracking: description: 'Indicates whether the tag is enabled for cost tracking. ' type: boolean isRetired: description: 'Whether the tag is retired. See [Retiring Key Definitions and Namespace Definitions](/Content/Tagging/Tasks/managingtagsandtagnamespaces.htm#retiringkeys). ' type: boolean lifecycleState: description: The tag's current state. After creating a tag, make sure its `lifecycleState` is ACTIVE before using it. After retiring a tag, make sure its `lifecycleState` is INACTIVE before using it. If you delete a tag, you cannot delete another tag until the deleted tag's `lifecycleState` changes from DELETING to DELETED. type: string x-obmcs-enumref: '#/definitions/Tag/lifecycleState' name: description: 'The name assigned to the tag during creation. This is the tag key definition. The name must be unique within the tag namespace and cannot be changed. ' maxLength: 100 minLength: 1 type: string systemTags: additionalProperties: additionalProperties: description: 'The value of the tag. ' type: object description: 'Key-value pair representing a system tag key and value, scoped to a namespace. Example: `{"free-tier-retained" : "true"}` ' type: object description: 'The system tags for this resource. Each key is predefined and scoped to a namespace. Example: `{"orcl-cloud": {"free-tier-retained": "true"}}` ' type: object timeCreated: description: 'Date and time the tag was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string TaggingWorkRequest: description: 'The asynchronous API request does not take effect immediately. This request spawns an asynchronous workflow to fulfill the request. WorkRequest objects provide visibility for in-progress workflows. ' properties: compartmentId: description: The OCID of the compartment that contains the work request. type: string id: description: The OCID of the work request. type: string operationType: description: An enum-like description of the type of work the work request is doing. enum: - DELETE_TAG_DEFINITION - DELETE_NON_EMPTY_TAG_NAMESPACE - BULK_DELETE_TAG_DEFINITION - BULK_EDIT_OF_TAGS - IMPORT_STANDARD_TAGS type: string percentComplete: description: 'How much progress the operation has made. ' format: float maximum: 100 minimum: 1 type: number resources: description: 'The resources this work request affects. ' items: $ref: '#/definitions/WorkRequestResource' type: array status: description: The current status of the work request. enum: - ACCEPTED - IN_PROGRESS - FAILED - SUCCEEDED - PARTIALLY_SUCCEEDED - CANCELING - CANCELED type: string timeAccepted: description: 'Date and time the work was accepted, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeFinished: description: 'Date and time the work completed, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeStarted: description: 'Date and time the work started, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - operationType - status TaggingWorkRequestErrorSummary: description: 'The error entity. ' properties: code: description: A machine-usable code for the error that occured. type: string message: description: A human-readable error string. type: string timestamp: description: 'Date and time the error happened, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - code - message TaggingWorkRequestLogSummary: description: 'The log entity. ' properties: message: description: A human-readable error string. type: string timestamp: description: 'Date and time the log was written, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - message TaggingWorkRequestSummary: description: 'The work request summary. Tracks the status of the asynchronous operation. ' properties: compartmentId: description: The OCID of the compartment that contains the work request. type: string id: description: The OCID of the work request. type: string operationType: description: An enum-like description of the type of work the work request is doing. enum: - DELETE_TAG_DEFINITION - DELETE_NON_EMPTY_TAG_NAMESPACE - BULK_DELETE_TAG_DEFINITION - BULK_EDIT_OF_TAGS - IMPORT_STANDARD_TAGS type: string percentComplete: description: 'How much progress the operation has made. ' format: float maximum: 100 minimum: 1 type: number resources: description: 'The resources this work request affects. ' items: $ref: '#/definitions/WorkRequestResource' type: array status: description: The current status of the work request. enum: - ACCEPTED - IN_PROGRESS - FAILED - SUCCEEDED - PARTIALLY_SUCCEEDED - CANCELING - CANCELED type: string timeAccepted: description: 'Date and time the work was accepted, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeFinished: description: 'Date and time the work completed, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeStarted: description: 'Date and time the work started, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - operationType - status Tenancy: description: 'The root compartment that contains all of your organization''s compartments and other Oracle Cloud Infrastructure cloud resources. When you sign up for Oracle Cloud Infrastructure, Oracle creates a tenancy for your company, which is a secure and isolated partition where you can create, organize, and administer your cloud resources. To use any of the API operations, you must be authorized in an IAM policy. If you''re not authorized, talk to an administrator. If you''re an administrator who needs to write policies to give users access, see [Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm). ' properties: definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description of the tenancy. type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object homeRegionKey: description: 'The region key for the tenancy''s home region. For the full list of supported regions, see [Regions and Availability Domains](/Content/General/Concepts/regions.htm). Example: `PHX` ' type: string id: description: The OCID of the tenancy. type: string name: description: The name of the tenancy. type: string upiIdcsCompatibilityLayerEndpoint: description: Url which refers to the UPI IDCS compatibility layer endpoint configured for this Tenant's home region. type: string UIPassword: description: 'A text password that enables a user to sign in to the Console, the user interface for interacting with Oracle Cloud Infrastructure. For more information about user credentials, see [User Credentials](/Content/Identity/usercred/usercredentials.htm). ' properties: inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The password''s current state. After creating a password, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string password: description: The user's password for the Console. type: string timeCreated: description: 'Date and time the password was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user. type: string UIPasswordInformation: description: 'Information about the UIPassword, which is a text password that enables a user to sign in to the Console, the user interface for interacting with Oracle Cloud Infrastructure. For more information about user credentials, see [User Credentials](/Content/Identity/Concepts/usercredentials.htm). ' properties: lifecycleState: description: 'The password''s current state. After creating a password, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string timeCreated: description: 'Date and time the password was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user. type: string UpdateAuthTokenDetails: properties: description: description: 'The description you assign to the auth token. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' type: string UpdateAuthenticationPolicyDetails: description: 'Update request for authentication policy, describes set of validation rules and their parameters to be updated. ' properties: networkPolicy: $ref: '#/definitions/NetworkPolicy' passwordPolicy: $ref: '#/definitions/PasswordPolicy' UpdateCompartmentDetails: properties: definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the compartment. Does not have to be unique, and it's changeable. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object name: description: 'The new name you assign to the compartment. The name must be unique across all compartments in the parent compartment. Avoid entering confidential information. ' maxLength: 100 minLength: 1 type: string UpdateCustomerSecretKeyDetails: properties: displayName: description: 'The description you assign to the secret key. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' type: string UpdateDomainDetails: description: (For tenancies that support identity domains) Update identity domain details. properties: definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The identity domain description. You can have an empty description. maxLength: 400 minLength: 1 type: string displayName: description: The mutable display name of the identity domain. maxLength: 100 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object isHiddenOnLogin: description: 'Indicates whether the identity domain is hidden on the sign-in screen or not. ' type: boolean UpdateDynamicGroupDetails: description: Properties for updating a dynamic group. properties: definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the dynamic group. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object matchingRule: description: 'The matching rule to dynamically match an instance certificate to this dynamic group. For rule syntax, see [Managing Dynamic Groups](/Content/Identity/dynamicgroups/managingdynamicgroups.htm). ' maxLength: 100000 minLength: 1 type: string UpdateGroupDetails: properties: definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the group. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object UpdateIdentityProviderDetails: discriminator: protocol properties: definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the `IdentityProvider`. Does not have to be unique, and it''s changeable. ' maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object protocol: description: 'The protocol used for federation. Example: `SAML2` ' enum: - SAML2 type: string required: - protocol UpdateIdpGroupMappingDetails: properties: groupId: description: The OCID of the group. type: string idpGroupName: description: The idp group name. type: string UpdateNetworkSourceDetails: properties: definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the network source. Does not have to be unique, and it's changeable. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object publicSourceList: description: 'A list of allowed public IP addresses and CIDR ranges. ' items: type: string maxItems: 100 minItems: 0 type: array services: description: '-- The services attribute has no effect and is reserved for use by Oracle. -- ' items: type: string maxItems: 1 minItems: 1 type: array virtualSourceList: description: 'A list of allowed VCN OCID and IP range pairs. Example:`"vcnId": "ocid1.vcn.oc1.iad.aaaaaaaaexampleuniqueID", "ipRanges": [ "129.213.39.0/24" ]` ' items: properties: ipRanges: items: type: string type: array vcnId: type: string type: object maxItems: 100 minItems: 0 type: array UpdateOAuth2ClientCredentialDetails: properties: description: description: Description of the oauth credential to help user differentiate them. type: string isResetPassword: description: Indicate if the password to be reset or not in the update. type: boolean scopes: description: Allowed scopes for the given oauth credential. items: $ref: '#/definitions/FullyQualifiedScope' type: array required: - description - scopes - passwordReset UpdatePolicyDetails: properties: definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the policy. Does not have to be unique, and it's changeable. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object statements: description: 'An array of policy statements written in the policy language. See [How Policies Work](/Content/Identity/policieshow/how-policies-work.htm) and [Common Policies](/Content/Identity/policiescommon/commonpolicies.htm). ' items: type: string type: array versionDate: description: 'The version of the policy. If null or set to an empty string, when a request comes in for authorization, the policy will be evaluated according to the current behavior of the services at that moment. If set to a particular date (YYYY-MM-DD), the policy will be evaluated according to the behavior of the services on that date. ' format: date-time type: string UpdateSaml2IdentityProviderDetails: allOf: - $ref: '#/definitions/UpdateIdentityProviderDetails' - discriminator: SAML2 properties: authnContextClassRefs: description: 'Authentication contexts requested when sending a SAML request to the identity provider. There could be one or more requested contexts. Usually identity provider uses the one that has the highest authentication strength. Example: `["urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport", "urn:oasis:names:tc:SAML:2.0:ac:classes:TLSClient"]` ' items: type: string type: array encryptAssertion: description: 'When set to true, the service provider expects the SAML assertion to be encrypted by the identity provider, using the service provider''s encryption key. In this case, the service provider is Oracle Cloud Infrastructure Authentication service. ' type: boolean forceAuthentication: description: 'If set to true, when the user is redirected to the identity provider, the identity provider forces the user to provide credentials and re-authenticate, even if there is an active login session. ' type: boolean freeformAttributes: additionalProperties: type: string description: 'Extra name value pairs associated with this identity provider. Example: `{"clientId": "app_sf3kdjf3"}` ' type: object metadata: description: 'The XML that contains the information required for federating. ' maxLength: 100000 minLength: 1 type: string metadataUrl: description: 'The URL for retrieving the identity provider''s metadata, which contains information required for federating. ' maxLength: 512 minLength: 1 type: string UpdateSmtpCredentialDetails: properties: description: description: 'The description you assign to the SMTP credential. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' type: string UpdateStateDetails: properties: blocked: description: 'Update state to blocked or unblocked. Only "false" is supported (for changing the state to unblocked). ' type: boolean UpdateSwiftPasswordDetails: properties: description: description: 'The description you assign to the Swift password. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' type: string UpdateTagDefaultDetails: properties: isRequired: description: 'If you specify that a value is required, a value is set during resource creation (either by the user creating the resource or another tag defualt). If no value is set, resource creation is blocked. * If the `isRequired` flag is set to "true", the value is set during resource creation. * If the `isRequired` flag is set to "false", the value you enter is set during resource creation. Example: `false` ' type: boolean value: description: 'The default value for the tag definition. This will be applied to all resources created in the Compartment. ' type: string required: - value x-example: "{\n \"value\" : \"W123\",\n \"isRequired\" : \"false\"\n}\n" UpdateTagDetails: properties: definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the tag during creation. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object isCostTracking: description: 'Indicates whether the tag is enabled for cost tracking. ' type: boolean isRetired: description: 'Whether the tag is retired. See [Retiring Key Definitions and Namespace Definitions](/Content/Tagging/Tasks/managingtagsandtagnamespaces.htm#retiringkeys). ' type: boolean validator: $ref: '#/definitions/BaseTagDefinitionValidator' UpdateTagNamespaceDetails: properties: definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: The description you assign to the tag namespace. maxLength: 400 minLength: 1 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object isRetired: description: 'Whether the tag namespace is retired. See [Retiring Key Definitions and Namespace Definitions](/Content/Tagging/Tasks/managingtagsandtagnamespaces.htm#retiringkeys). ' type: boolean UpdateUserCapabilitiesDetails: properties: canUseApiKeys: description: 'Indicates if the user can use API keys. ' type: boolean canUseAuthTokens: description: 'Indicates if the user can use SWIFT passwords / auth tokens. ' type: boolean canUseConsolePassword: description: 'Indicates if the user can log in to the console. ' type: boolean canUseCustomerSecretKeys: description: 'Indicates if the user can use SigV4 symmetric keys. ' type: boolean canUseDBCredentials: description: 'Indicates if the user can use DB passwords. ' type: boolean canUseOAuth2ClientCredentials: description: 'Indicates if the user can use OAuth2 credentials and tokens. ' type: boolean canUseSmtpCredentials: description: 'Indicates if the user can use SMTP passwords. ' type: boolean UpdateUserDetails: properties: dbUserName: description: DB username of the DB credential. Has to be unique across the tenancy. maxLength: 201 minLength: 0 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the user. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' maxLength: 400 minLength: 1 type: string email: description: 'The email you assign to the user during creation. The email must be unique across all users in the tenancy. (For tenancies that support identity domains) You must provide an email for each user. ' maxLength: 254 minLength: 0 type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object User: description: 'An individual employee or system that needs to manage or use your company''s Oracle Cloud Infrastructure resources. Users might need to launch instances, manage remote disks, work with your cloud network, etc. Users have one or more IAM Service credentials ([ApiKey](#/en/identity/20160918/ApiKey/), [UIPassword](#/en/identity/20160918/UIPassword/), [SwiftPassword](#/en/identity/20160918/SwiftPassword/) and [AuthToken](#/en/identity/20160918/AuthToken/)). For more information, see [User Credentials](/Content/Identity/usercred/usercredentials.htm)). End users of your application are not typically IAM Service users, but for tenancies that have identity domains, they might be. For conceptual information about users and other IAM Service components, see [Overview of IAM](/Content/Identity/getstarted/identity-domains.htm). These users are created directly within the Oracle Cloud Infrastructure system, via the IAM service. They are different from *federated users*, who authenticate themselves to the Oracle Cloud Infrastructure Console via an identity provider. For more information, see [Identity Providers and Federation](/Content/Identity/Concepts/federation.htm). To use any of the API operations, you must be authorized in an IAM policy. If you''re not authorized, talk to an administrator. If you''re an administrator who needs to write policies to give users access, see [Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm). **Warning:** Oracle recommends that you avoid using any confidential information when you supply string values using the API. ' properties: capabilities: $ref: '#/definitions/UserCapabilities' compartmentId: description: The OCID of the tenancy containing the user. type: string dbUserName: description: DB username of the DB credential. Has to be unique across the tenancy. maxLength: 201 minLength: 0 type: string definedTags: additionalProperties: additionalProperties: description: 'The value of the tag. Only the String type is supported. ' type: object description: 'Key-value pair representing a defined tag key and value, scoped to a namespace. Example: `{"CostCenter": "42"}` ' type: object description: 'Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Operations": {"CostCenter": "42"}}` ' type: object description: description: 'The description you assign to the user. Does not have to be unique, and it''s changeable. (For tenancies that support identity domains) You can have an empty description. ' maxLength: 400 minLength: 1 type: string email: description: 'The email address you assign to the user. The email address must be unique across all users in the tenancy. (For tenancies that support identity domains) The email address is required unless the requirement is disabled at the tenancy level. ' maxLength: 254 minLength: 0 type: string emailVerified: description: Whether the email address has been validated. type: boolean externalIdentifier: description: Identifier of the user in the identity provider type: string freeformTags: additionalProperties: type: string description: 'Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/Content/General/Concepts/resourcetags.htm). Example: `{"Department": "Finance"}` ' type: object id: description: The OCID of the user. type: string identityProviderId: description: The OCID of the `IdentityProvider` this user belongs to. type: string inactiveStatus: description: 'Returned only if the user''s `lifecycleState` is INACTIVE. A 16-bit value showing the reason why the user is inactive: - bit 0: SUSPENDED (reserved for future use) - bit 1: DISABLED (reserved for future use) - bit 2: BLOCKED (the user has exceeded the maximum number of failed login attempts for the Console) ' format: int64 type: integer isMfaActivated: description: Flag indicates if MFA has been activated for the user. type: boolean lastSuccessfulLoginTime: description: 'The date and time of when the user most recently logged in the format defined by RFC3339 (ex. `2016-08-25T21:10:29.600Z`). If there is no login history, this field is null. For illustrative purposes, suppose we have a user who has logged in at July 1st, 2020 at 1200 PST and logged out 30 minutes later. They then login again on July 2nd, 2020 at 1500 PST. Their previousSuccessfulLoginTime would be `2020-07-01:19:00.000Z`. Their lastSuccessfulLoginTime would be `2020-07-02:22:00.000Z`. ' format: date-time type: string lifecycleState: description: 'The user''s current state. After creating a user, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string name: description: 'The name you assign to the user during creation. This is the user''s login for the Console. The name must be unique across all users in the tenancy and cannot be changed. ' maxLength: 100 minLength: 1 type: string previousSuccessfulLoginTime: description: 'The date and time of when the user most recently logged in the format defined by RFC3339 (ex. `2016-08-25T21:10:29.600Z`). If there is no login history, this field is null. For illustrative purposes, suppose we have a user who has logged in at July 1st, 2020 at 1200 PST and logged out 30 minutes later. They then login again on July 2nd, 2020 at 1500 PST. Their previousSuccessfulLoginTime would be `2020-07-01:19:00.000Z`. Their lastSuccessfulLoginTime would be `2020-07-02:22:00.000Z`. ' format: date-time type: string timeCreated: description: 'Date and time the user was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - compartmentId - name - description - timeCreated - lifecycleState - isMfaActivated UserCapabilities: description: Properties indicating how the user is allowed to authenticate. properties: canUseApiKeys: description: Indicates if the user can use API keys. type: boolean canUseAuthTokens: description: Indicates if the user can use SWIFT passwords / auth tokens. type: boolean canUseConsolePassword: description: Indicates if the user can log in to the console. type: boolean canUseCustomerSecretKeys: description: Indicates if the user can use SigV4 symmetric keys. type: boolean canUseDbCredentials: description: 'Indicates if the user can use DB passwords. ' type: boolean canUseOAuth2ClientCredentials: description: 'Indicates if the user can use OAuth2 credentials and tokens. ' type: boolean canUseSmtpCredentials: description: Indicates if the user can use SMTP passwords. type: boolean UserGroupMembership: description: 'An object that represents the membership of a user in a group. When you add a user to a group, the result is a `UserGroupMembership` with its own OCID. To remove a user from a group, you delete the `UserGroupMembership` object. ' properties: compartmentId: description: The OCID of the tenancy containing the user, group, and membership object. type: string groupId: description: The OCID of the group. type: string id: description: The OCID of the membership. type: string inactiveStatus: description: The detailed status of INACTIVE lifecycleState. format: int64 type: integer lifecycleState: description: 'The membership''s current state. After creating a membership object, make sure its `lifecycleState` changes from CREATING to ACTIVE before using it. ' enum: - CREATING - ACTIVE - INACTIVE - DELETING - DELETED maxLength: 64 minLength: 1 type: string timeCreated: description: 'Date and time the membership was created, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string userId: description: The OCID of the user. type: string required: - id - compartmentId - timeCreated - lifecycleState - groupId - userId WorkRequest: description: 'The asynchronous API request does not take effect immediately. This request spawns an asynchronous workflow to fulfill the request. WorkRequest objects provide visibility for in-progress workflows. ' properties: compartmentId: description: The OCID of the compartment that contains the work request. type: string errors: description: 'The errors for work request. ' items: $ref: '#/definitions/WorkRequestError' type: array id: description: The OCID of the work request. type: string logs: description: 'The logs for work request. ' items: $ref: '#/definitions/WorkRequestLogEntry' type: array operationType: description: An enum-like description of the type of work the work request is doing. enum: - DELETE_COMPARTMENT - DELETE_TAG_DEFINITION type: string percentComplete: description: 'How much progress the operation has made. ' format: float maximum: 100 minimum: 1 type: number resources: description: 'The resources this work request affects. ' items: $ref: '#/definitions/WorkRequestResource' type: array status: description: The current status of the work request. enum: - ACCEPTED - IN_PROGRESS - FAILED - SUCCEEDED - CANCELING - CANCELED type: string timeAccepted: description: 'Date and time the work was accepted, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeFinished: description: 'Date and time the work completed, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeStarted: description: 'Date and time the work started, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - operationType - status WorkRequestError: description: 'The error entity. ' properties: code: description: A machine-usable code for the error that occured. type: string message: description: A human-readable error string. type: string timestamp: description: 'Date and time the error happened, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - code - message WorkRequestLogEntry: description: 'The log entity. ' properties: message: description: A human-readable error string. type: string timestamp: description: 'Date and time the log was written, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - message WorkRequestResource: description: 'The resource entity. ' properties: actionType: description: The way in which this resource was affected by the work tracked by the work request. enum: - CREATED - UPDATED - DELETED - RELATED - IN_PROGRESS - FAILED type: string entityType: description: The resource type the work request is affects. type: string entityUri: description: The URI path that the user can do a GET on to access the resource metadata. type: string identifier: description: The resource identifier the work request affects. type: string required: - identifier - actionType - entityType WorkRequestSummary: description: 'The work request summary. Tracks the status of the asynchronous operation. ' properties: compartmentId: description: The OCID of the compartment that contains the work request. type: string errors: description: 'The errors for work request. ' items: $ref: '#/definitions/WorkRequestError' type: array id: description: The OCID of the work request. type: string operationType: description: An enum-like description of the type of work the work request is doing. enum: - DELETE_COMPARTMENT - DELETE_TAG_DEFINITION type: string percentComplete: description: 'How much progress the operation has made. ' format: float maximum: 100 minimum: 1 type: number resources: description: 'The resources this work request affects. ' items: $ref: '#/definitions/WorkRequestResource' type: array status: description: The current status of the work request. enum: - ACCEPTED - IN_PROGRESS - FAILED - SUCCEEDED - CANCELING - CANCELED type: string timeAccepted: description: 'Date and time the work was accepted, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeFinished: description: 'Date and time the work completed, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string timeStarted: description: 'Date and time the work started, in the format defined by RFC3339. Example: `2016-08-25T21:10:29.600Z` ' format: date-time type: string required: - id - operationType - status host: localhost:9000 info: description: Use the Identity and Access Management Service API to manage users, groups, identity domains, compartments, policies, tagging, and limits. For information about managing users, groups, compartments, and policies, see [Identity and Access Management (without identity domains)](/iaas/Content/Identity/Concepts/overview.htm). For information about tagging and service limits, see [Tagging](/iaas/Content/Tagging/Concepts/taggingoverview.htm) and [Service Limits](/iaas/Content/General/Concepts/servicelimits.htm). For information about creating, modifying, and deleting identity domains, see [Identity and Access Management (with identity domains)](/iaas/Content/Identity/home.htm). license: name: Oracle Corporation title: Identity and Access Management Service API version: '20160918' parameters: AccessLevelQueryParam: description: 'Valid values are `ANY` and `ACCESSIBLE`. Default is `ANY`. Setting this to `ACCESSIBLE` returns only those compartments for which the user has INSPECT permissions directly or indirectly (permissions can be on a resource in a subcompartment). For the compartments on which the user indirectly has INSPECT permissions, a restricted set of fields is returned. When set to `ANY` permissions are not checked. ' enum: - ANY - ACCESSIBLE in: query name: accessLevel type: string AuthTokenIdPathParam: description: The OCID of the auth token. in: path name: authTokenId required: true type: string AvailabilityDomainQueryParam: description: 'The name of the availabilityDomain. ' in: query name: availabilityDomain required: true type: string BulkActionTypeQueryParam: description: 'The type of bulk action. ' enum: - BULK_MOVE_RESOURCES - BULK_DELETE_RESOURCES in: query name: bulkActionType required: true type: string CompartmentIdInSubtreeQueryParam: description: 'Default is false. Can only be set to true when performing ListCompartments on the tenancy (root compartment). When set to true, the hierarchy of compartments is traversed and all compartments and subcompartments in the tenancy are returned depending on the the setting of `accessLevel`. ' in: query name: compartmentIdInSubtree required: false type: boolean CompartmentIdPathParam: description: The OCID of the compartment. in: path name: compartmentId required: true type: string CompartmentIdQueryParam: description: 'The OCID of the compartment (remember that the tenancy is simply the root compartment). ' in: query maxLength: 255 minLength: 1 name: compartmentId required: true type: string CustomerSecretKeyIdPathParam: description: The access token of the secret key. in: path name: customerSecretKeyId required: true type: string DbCredentialIdPathParam: description: The OCID of the DB credential. in: path name: dbCredentialId required: true type: string DomainDisplayNameQueryParam: description: The mutable display name of the identity domain. in: query name: displayName type: string x-default-description: 'null' DomainHomeRegionURLQueryParam: description: The region-specific identity domain URL. in: query name: homeRegionUrl type: string x-default-description: 'null' DomainIdPathParam: description: The OCID of the identity domain. in: path name: domainId required: true type: string DomainTypeQueryParam: description: The identity domain type. in: query name: type type: string x-default-description: 'null' DomainURLQueryParam: description: The region-agnostic identity domain URL. in: query name: url type: string x-default-description: 'null' DynamicGroupIdPathParam: description: The OCID of the dynamic group. in: path name: dynamicGroupId required: true type: string EmailVerificationTokenIdPathParam: description: The OCID of the email verification token. in: path name: emailVerificationTokenId required: true type: string ExternalIdentifierQueryParam: description: 'The id of a user in the identity provider. ' in: query maxLength: 255 minLength: 1 name: externalIdentifier required: false type: string FilterByIdQueryParam: description: 'A filter to only return resources that match the specified OCID exactly. ' in: query maxLength: 255 minLength: 1 name: id required: false type: string FilterByNameQueryParam: description: 'A filter to only return resources that match the given name exactly. ' in: query maxLength: 255 minLength: 1 name: name required: false type: string GroupIdPathParam: description: The OCID of the group. in: path name: groupId required: true type: string GroupIdQueryParam: description: The OCID of the group. in: query name: groupId type: string IamWorkRequestIdPathParam: description: The OCID of the IAM work request. in: path name: iamWorkRequestId required: true type: string IdentityProviderIdPathParam: description: The OCID of the identity provider. in: path name: identityProviderId required: true type: string IdentityProviderIdQueryParam: description: 'The id of the identity provider. ' in: query maxLength: 255 minLength: 1 name: identityProviderId required: false type: string IdentityProviderProtocolQueryParam: description: The protocol used for federation. enum: - SAML2 in: query name: protocol required: true type: string x-obmcs-inline-enum: false IdpGroupMappingIdPathParam: description: The OCID of the group mapping. in: path name: mappingId required: true type: string IfMatchHeader: description: 'For optimistic concurrency control. In the PUT or DELETE call for a resource, set the `if-match` parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource''s current etag value. ' in: header name: if-match type: string IsHiddenOnLoginQueryParam: description: Indicates whether or not the identity domain is visible at the sign-in screen. in: query name: isHiddenOnLogin type: boolean x-default-description: 'null' KeyFingerprintPathParam: description: The key's fingerprint. in: path name: fingerprint required: true type: string LicenseTypeQueryParam: description: The license type of the identity domain. in: query maxLength: 64 minLength: 1 name: licenseType type: string x-default-description: 'null' MfaTotpDeviceIdPathParam: description: The OCID of the MFA TOTP device. in: path name: mfaTotpDeviceId required: true type: string NetworkSourceIdPathParam: description: The OCID of the network source. in: path name: networkSourceId required: true type: string Oauth2ClientCredentialIdPathParam: description: The ID of the Oauth credential. in: path name: oauth2ClientCredentialId required: true type: string OptionalCompartmentIdQueryParam: description: 'The OCID of the compartment (remember that the tenancy is simply the root compartment). ' in: query maxLength: 255 minLength: 1 name: compartmentId required: false type: string OptionalDomainIdPathParam: description: The OCID of the identity domain. in: query name: domainId required: false type: string x-default-description: 'null' OptionalLicenseTypeQueryParam: description: The license type of the identity domain. in: query maxLength: 64 minLength: 1 name: currentLicenseTypeName required: false type: string x-default-description: 'null' OptionalTagDefinitionIdQueryParam: description: 'The OCID of the tag definition. ' in: query maxLength: 255 minLength: 1 name: tagDefinitionId required: false type: string OverrideLocksQueryParam: default: false description: Whether to override locks (if any exist). in: query name: isLockOverride type: boolean OverrideLocksQueryParameter: default: false description: Whether to override locks (if any exist). in: query name: isLockOverride type: boolean PaginationLimitQueryParam: description: 'The maximum number of items to return in a paginated "List" call. ' in: query maximum: 1000 minimum: 1 name: limit type: integer x-default-description: 'null' PaginationTokenQueryParam: description: 'The value of the `opc-next-page` response header from the previous "List" call. ' in: query maxLength: 512 minLength: 1 name: page type: string PolicyIdPathParam: description: The OCID of the policy. in: path name: policyId required: true type: string RequestIdHeader: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' in: header name: opc-request-id type: string ResourceIdentifierQueryParam: description: The identifier of the resource the work request affects. in: query name: resourceIdentifier required: false type: string x-default-description: 'null' RetryTokenHeader: description: 'A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (e.g., if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). ' in: header maxLength: 64 minLength: 1 name: opc-retry-token type: string ServiceNameQueryParam: description: The name of the whitelisted service caller. Such as 'PSM' in: query maxLength: 100 minLength: 1 name: serviceName required: true type: string SmtpCredentialIdPathParam: description: The OCID of the SMTP credential. in: path name: smtpCredentialId required: true type: string SortByQueryParam: description: 'The field to sort by. You can provide one sort order (`sortOrder`). Default order for TIMECREATED is descending. Default order for NAME is ascending. The NAME sort order is case sensitive. **Note:** In general, some "List" operations (for example, `ListInstances`) let you optionally filter by Availability Domain if the scope of the resource type is within a single Availability Domain. If you call one of these "List" operations without specifying an Availability Domain, the resources are grouped by Availability Domain, then sorted. ' enum: - TIMECREATED - NAME in: query name: sortBy required: false type: string x-default-description: 'null' SortOrderQueryParam: description: 'The sort order to use, either ascending (`ASC`) or descending (`DESC`). The NAME sort order is case sensitive. ' enum: - ASC - DESC in: query name: sortOrder required: false type: string x-default-description: 'null' StandardTagNamespaceNamePathParam: description: 'The name of the standard tag namespace tempate that is requested ' in: path maxLength: 100 minLength: 1 name: standardTagNamespaceName required: true type: string SwiftPasswordIdPathParam: description: The OCID of the Swift password. in: path name: swiftPasswordId required: true type: string TagDefaultIdPathParam: description: The OCID of the tag default. in: path name: tagDefaultId required: true type: string TagIdPathParam: description: 'The OCID of the tag definition. ' in: path maxLength: 100 minLength: 1 name: tagId required: true type: string TagNamePathParam: description: 'The name of the tag. ' in: path maxLength: 100 minLength: 1 name: tagName required: true type: string TagNamespaceIdPathParam: description: 'The OCID of the tag namespace. ' in: path maxLength: 100 minLength: 1 name: tagNamespaceId required: true type: string TasDomainIdPathParam: description: The OCID of the identity domain. in: path name: tasDomainId required: true type: string TenancyIdPathParam: description: The OCID of the tenancy. in: path name: tenancyId required: true type: string TenantIdPathParam: description: The OCID of the tenancy. in: path name: tenantId required: true type: string TenantIdQueryParam: description: The OCID of the tenancy. in: query maxLength: 255 minLength: 1 name: tenantId required: false type: string x-default-description: 'null' UserGroupMembershipIdPathParam: description: The OCID of the userGroupMembership. in: path name: userGroupMembershipId required: true type: string UserIdPathParam: description: The OCID of the user. in: path name: userId required: true type: string UserIdQueryParam: description: The OCID of the user. in: query name: userId type: string WorkRequestIdPathParam: description: The OCID of the work request. in: path name: workRequestId required: true type: string paths: /allowedDomainLicenseTypes: get: description: '(For tenancies that support identity domains) Lists the license types for identity domains supported by Oracle Cloud Infrastructure. (License types are also referred to as domain types.) If `currentLicenseTypeName` is provided, then the request returns license types that the identity domain with the specified license type name can change to. Otherwise, the request returns all valid license types currently supported. ' operationId: ListAllowedDomainLicenseTypes parameters: - $ref: '#/parameters/OptionalLicenseTypeQueryParam' - $ref: '#/parameters/RequestIdHeader' responses: 200: description: A list of allowed license types for identity domains. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/AllowedDomainLicenseTypeSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: List allowed identity domain license types tags: - identity x-related-resource: '#/definitions/Domain' /authenticationPolicies/{compartmentId}: get: description: 'Gets the authentication policy for the given tenancy. You must specify your tenant''s OCID as the value for the compartment ID (remember that the tenancy is simply the root compartment). ' operationId: GetAuthenticationPolicy parameters: - $ref: '#/parameters/CompartmentIdPathParam' responses: 200: description: The authentication policy was found. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/AuthenticationPolicy' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetAuthenticationPolicy tags: - identity put: description: 'Updates authentication policy for the specified tenancy. ' operationId: UpdateAuthenticationPolicy parameters: - $ref: '#/parameters/CompartmentIdPathParam' - description: Request object for updating the authentication policy. in: body name: UpdateAuthenticationPolicyDetails required: true schema: $ref: '#/definitions/UpdateAuthenticationPolicyDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The authentication policy is being updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/AuthenticationPolicy' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateAuthenticationPolicy tags: - identity /availabilityDomains/: get: description: 'Lists the availability domains in your tenancy. Specify the OCID of either the tenancy or another of your compartments as the value for the compartment ID (remember that the tenancy is simply the root compartment). See [Where to Get the Tenancy''s OCID and User''s OCID](/Content/API/Concepts/apisigningkey.htm#five). Note that the order of the results returned can change if availability domains are added or removed; therefore, do not create a dependency on the list order. ' operationId: ListAvailabilityDomains parameters: - $ref: '#/parameters/CompartmentIdQueryParam' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/AvailabilityDomain' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListAvailabilityDomains tags: - identity /compartments/: get: description: 'Lists the compartments in a specified compartment. The members of the list returned depends on the values set for several parameters. With the exception of the tenancy (root compartment), the ListCompartments operation returns only the first-level child compartments in the parent compartment specified in `compartmentId`. The list does not include any subcompartments of the child compartments (grandchildren). The parameter `accessLevel` specifies whether to return only those compartments for which the requestor has INSPECT permissions on at least one resource directly or indirectly (the resource can be in a subcompartment). The parameter `compartmentIdInSubtree` applies only when you perform ListCompartments on the tenancy (root compartment). When set to true, the entire hierarchy of compartments can be returned. To get a full list of all compartments and subcompartments in the tenancy (root compartment), set the parameter `compartmentIdInSubtree` to true and `accessLevel` to ANY. See [Where to Get the Tenancy''s OCID and User''s OCID](/Content/API/Concepts/apisigningkey.htm#five). ' operationId: ListCompartments parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/AccessLevelQueryParam' - $ref: '#/parameters/CompartmentIdInSubtreeQueryParam' - $ref: '#/parameters/FilterByNameQueryParam' - $ref: '#/parameters/SortByQueryParam' - $ref: '#/parameters/SortOrderQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/Compartment/lifecycleState' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/Compartment' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListCompartments tags: - identity post: description: 'Creates a new compartment in the specified compartment. Specify the parent compartment''s OCID as the compartment ID in the request object. Remember that the tenancy is simply the root compartment. For information about OCIDs, see [Resource Identifiers](/Content/General/Concepts/identifiers.htm). You must also specify a *name* for the compartment, which must be unique across all compartments in your tenancy. You can use this name or the OCID when writing policies that apply to the compartment. For more information about policies, see [How Policies Work](/Content/Identity/policieshow/how-policies-work.htm). You must also specify a *description* for the compartment (although it can be an empty string). It does not have to be unique, and you can change it anytime with [UpdateCompartment](#/en/identity/20160918/Compartment/UpdateCompartment). After you send your request, the new object''s `lifecycleState` will temporarily be CREATING. Before using the object, first make sure its `lifecycleState` has changed to ACTIVE. ' operationId: CreateCompartment parameters: - description: Request object for creating a new compartment. in: body name: createCompartmentDetails required: true schema: $ref: '#/definitions/CreateCompartmentDetails' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The compartment is being created. examples: application-json: "{\n \"id\" : \"ocid1.compartment.oc1..aaaaaaaayzexampleuniqueID\"\ ,\n \"compartmentId\" : \"ocid1.tenancy.oc1..aaaaaaaaba3pexampleuniqueID\"\ ,\n \"name\" : \"Network\",\n \"description\" : \"For network components\"\ ,\n \"lifecycleState\" : \"ACTIVE\",\n \"timeCreated\" : \"2016-11-18T23:01:40.936Z\"\ \n}\n" headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Compartment' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateCompartment tags: - identity x-example: "POST /20160918/compartments/\nHost: identity.us-phoenix-1.oraclecloud.com\n\ <authorization and other headers>\n{\n \"compartmentId\"\ \ : \"ocid1.tenancy.oc1..aaaaaaaaba3exampleuniqueID\",\n \"description\"\ \ : \"For network components\",\n \"name\" : \"Network\"\n}\n" /compartments/bulkActionResourceTypes: get: description: 'Lists the resource-types supported by compartment bulk actions. Use this API to help you provide the correct resource-type information to the [BulkDeleteResources](#/en/identity/20160918/Compartment/BulkDeleteResources/) and [BulkMoveResources](#/en/identity/20160918/Compartment/BulkMoveResources/) operations. The returned list of resource-types provides the appropriate resource-type names to use with the bulk action operations along with the type of identifying information you''ll need to provide for each resource-type. Most resource-types just require an [OCID](/Content/General/Concepts/identifiers.htm) to identify a specific resource, but some resource-types, such as buckets, require you to provide other identifying information. ' operationId: ListBulkActionResourceTypes parameters: - $ref: '#/parameters/BulkActionTypeQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/BulkActionResourceTypeCollection' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListBulkActionResourceTypes tags: - identity /compartments/{compartmentId}: delete: description: 'Deletes the specified compartment. The compartment must be empty. ' operationId: DeleteCompartment parameters: - $ref: '#/parameters/CompartmentIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 202: description: The request was accepted for processing. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteCompartment tags: - identity x-related-resource: '#/definitions/Compartment' get: description: 'Gets the specified compartment''s information. This operation does not return a list of all the resources inside the compartment. There is no single API operation that does that. Compartments can contain multiple types of resources (instances, block storage volumes, etc.). To find out what''s in a compartment, you must call the "List" operation for each resource type and specify the compartment''s OCID as a query parameter in the request. For example, call the [ListInstances](#/en/iaas/20160918/Instance/ListInstances) operation in the Cloud Compute Service or the [ListVolumes](#/en/iaas/20160918/Volume/ListVolumes) operation in Cloud Block Storage. ' operationId: GetCompartment parameters: - $ref: '#/parameters/CompartmentIdPathParam' responses: 200: description: The compartment was retrieved. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Compartment' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetCompartment tags: - identity put: description: Updates the specified compartment's description or name. You can't update the root compartment. operationId: UpdateCompartment parameters: - $ref: '#/parameters/CompartmentIdPathParam' - description: Request object for updating a compartment. in: body name: updateCompartmentDetails required: true schema: $ref: '#/definitions/UpdateCompartmentDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The compartment is being updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Compartment' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateCompartment tags: - identity /compartments/{compartmentId}/actions/bulkDeleteResources: post: description: 'Deletes multiple resources in the compartment. All resources must be in the same compartment. You must have the appropriate permissions to delete the resources in the request. This API can only be invoked from the tenancy''s [home region](/Content/Identity/regions/managingregions.htm#Home). This operation creates a [WorkRequest](#/en/workrequests/20160918/WorkRequest/). Use the [GetWorkRequest](#/en/workrequests/20160918/WorkRequest/GetWorkRequest) API to monitor the status of the bulk action. ' operationId: BulkDeleteResources parameters: - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/CompartmentIdPathParam' - description: Request object for bulk delete resources in a compartment. in: body name: BulkDeleteResourcesDetails required: true schema: $ref: '#/definitions/BulkDeleteResourcesDetails' responses: 202: description: The request was accepted for processing. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Bulk delete resources in the compartment tags: - identity x-related-resource: '#/definitions/Compartment' /compartments/{compartmentId}/actions/bulkMoveResources: post: description: 'Moves multiple resources from one compartment to another. All resources must be in the same compartment. This API can only be invoked from the tenancy''s [home region](/Content/Identity/regions/managingregions.htm#Home). To move resources, you must have the appropriate permissions to move the resource in both the source and target compartments. This operation creates a [WorkRequest](#/en/workrequests/20160918/WorkRequest/). Use the [GetWorkRequest](#/en/workrequests/20160918/WorkRequest/GetWorkRequest) API to monitor the status of the bulk action. ' operationId: BulkMoveResources parameters: - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/CompartmentIdPathParam' - description: Request object for bulk move resources in the compartment. in: body name: BulkMoveResourcesDetails required: true schema: $ref: '#/definitions/BulkMoveResourcesDetails' responses: 202: description: The request was accepted for processing. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Move multiple resources at once to a different compartment. tags: - identity x-related-resource: '#/definitions/Compartment' /compartments/{compartmentId}/actions/moveCompartment: post: description: 'Move the compartment to a different parent compartment in the same tenancy. When you move a compartment, all its contents (subcompartments and resources) are moved with it. Note that the `CompartmentId` that you specify in the path is the compartment that you want to move. **IMPORTANT**: After you move a compartment to a new parent compartment, the access policies of the new parent take effect and the policies of the previous parent no longer apply. Ensure that you are aware of the implications for the compartment contents before you move it. For more information, see [Moving a Compartment](/Content/Identity/compartments/managingcompartments.htm#MoveCompartment). ' operationId: MoveCompartment parameters: - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/CompartmentIdPathParam' - description: Request object for moving a compartment. in: body name: MoveCompartmentDetails required: true schema: $ref: '#/definitions/MoveCompartmentDetails' responses: 202: description: The request was accepted for processing. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: 'Moves a compartment tree to a different parent compartment. When provided, If-Match is checked against ETag values of the resource. ' tags: - identity x-related-resource: '#/definitions/Compartment' /compartments/{compartmentId}/actions/recoverCompartment: post: description: 'Recover the compartment from DELETED state to ACTIVE state. ' operationId: RecoverCompartment parameters: - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/CompartmentIdPathParam' responses: 200: description: The compartment was recovered. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Compartment' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: RecoverCompartment tags: - identity x-related-resource: '#/definitions/Compartment' /domains/: get: description: '(For tenancies that support identity domains) Lists all identity domains within a tenancy. ' operationId: ListDomains parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/DomainDisplayNameQueryParam' - $ref: '#/parameters/DomainURLQueryParam' - $ref: '#/parameters/DomainHomeRegionURLQueryParam' - $ref: '#/parameters/DomainTypeQueryParam' - $ref: '#/parameters/LicenseTypeQueryParam' - $ref: '#/parameters/IsHiddenOnLoginQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/FilterByNameQueryParam' - $ref: '#/parameters/SortByQueryParam' - $ref: '#/parameters/SortOrderQueryParam' - $ref: '#/parameters/RequestIdHeader' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/Domain/lifecycleState' responses: 200: description: The identity domains were retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/DomainSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListDomains tags: - identity post: description: '(For tenancies that support identity domains) Creates a new identity domain in the tenancy with the identity domain home in `homeRegion`. After you send your request, the temporary `lifecycleState` of this identity domain is set to CREATING and `lifecycleDetails` to UPDATING. When creation of the identity domain completes, this identity domain''s `lifecycleState` is set to ACTIVE and `lifecycleDetails` to null. To track the progress of the request, submitting an HTTP GET on the /iamWorkRequests/{iamWorkRequestsId} endpoint retrieves the operation''s status. After creating an `identity domain`, first make sure its `lifecycleState` changes from CREATING to ACTIVE before you use it. ' operationId: CreateDomain parameters: - description: The request object for creating a new identity domain. in: body name: CreateDomainDetails required: true schema: $ref: '#/definitions/CreateDomainDetails' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/RequestIdHeader' responses: 202: description: This identity domain creation has started. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateDomain tags: - identity x-obmcs-get-work-request-operation: GetIamWorkRequest x-related-resource: '#/definitions/Domain' /domains/{domainId}: delete: description: '(For tenancies that support identity domains) Deletes an identity domain. The identity domain must have no active apps present in the underlying IDCS stripe. You must also deactivate the identity domain, rendering the `lifecycleState` of the identity domain INACTIVE. Furthermore, as the authenticated user performing the operation, you cannot be a member of the identity domain you are deleting. Lastly, you cannot delete the default identity domain. A tenancy must always have at least the default identity domain. To track the progress of the request, submitting an HTTP GET on the /iamWorkRequests/{iamWorkRequestsId} endpoint retrieves the operation''s status. ' operationId: DeleteDomain parameters: - $ref: '#/parameters/DomainIdPathParam' - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RequestIdHeader' responses: 202: description: The identity domain is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteDomain tags: - identity x-obmcs-get-work-request-operation: GetIamWorkRequest x-related-resource: '#/definitions/Domain' get: description: '(For tenancies that support identity domains) Gets the specified identity domain''s information. ' operationId: GetDomain parameters: - $ref: '#/parameters/DomainIdPathParam' - $ref: '#/parameters/RequestIdHeader' responses: 200: description: The identity domain was retrieved. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Domain' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetDomain tags: - identity x-related-resource: '#/definitions/Domain' put: description: '(For tenancies that support identity domains) Updates identity domain information and the associated Identity Cloud Service (IDCS) stripe. To track the progress of the request, submitting an HTTP GET on the /iamWorkRequests/{iamWorkRequestsId} endpoint retrieves the operation''s status. ' operationId: UpdateDomain parameters: - $ref: '#/parameters/DomainIdPathParam' - $ref: '#/parameters/IfMatchHeader' - description: Request object for updating the identity domain. in: body name: UpdateDomainDetails required: true schema: $ref: '#/definitions/UpdateDomainDetails' - $ref: '#/parameters/RequestIdHeader' responses: 202: description: The identity domain is being updated. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateDomain tags: - identity x-obmcs-get-work-request-operation: GetIamWorkRequest x-related-resource: '#/definitions/Domain' /domains/{domainId}/actions/activate: post: description: '(For tenancies that support identity domains) Activates a deactivated identity domain. You can only activate identity domains that your user account is not a part of. After you send the request, the `lifecycleDetails` of the identity domain is set to ACTIVATING. When the operation completes, the `lifecycleDetails` is set to null and the `lifecycleState` of the identity domain is set to ACTIVE. To track the progress of the request, submitting an HTTP GET on the /iamWorkRequests/{iamWorkRequestsId} endpoint retrieves the operation''s status. ' operationId: ActivateDomain parameters: - $ref: '#/parameters/DomainIdPathParam' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/IfMatchHeader' responses: 202: description: The identity domain activation is starting. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Activate a deactivated domain tags: - identity x-obmcs-get-work-request-operation: GetIamWorkRequest x-related-resource: '#/definitions/Domain' /domains/{domainId}/actions/changeCompartment: post: description: '(For tenancies that support identity domains) Moves the identity domain to a different compartment in the tenancy. To track the progress of the request, submitting an HTTP GET on the /iamWorkRequests/{iamWorkRequestsId} endpoint retrieves the operation''s status. ' operationId: ChangeDomainCompartment parameters: - $ref: '#/parameters/DomainIdPathParam' - description: The request object for moving the identity domain to a different compartment. in: body name: ChangeDomainCompartmentDetails required: true schema: $ref: '#/definitions/ChangeDomainCompartmentDetails' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/IfMatchHeader' responses: 202: description: This identity domain's compartment move is starting. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Change domain compartment tags: - identity x-obmcs-get-work-request-operation: GetIamWorkRequest x-related-resource: '#/definitions/Domain' /domains/{domainId}/actions/changeFaPodBaseUrl: post: description: '(For tenancies that support identity domains) Updates the fa pod base url of the given identity domain. To track the progress of the request, submitting an HTTP GET on the /iamWorkRequests/{iamWorkRequestsId} endpoint retrieves the operation''s status. ' operationId: ChangeDomainFaPodBaseUrl parameters: - $ref: '#/parameters/DomainIdPathParam' - description: The request object for an update to the fa pod base url of the identity domain. in: body name: ChangeDomainFaPodBaseUrlDetails required: true schema: $ref: '#/definitions/ChangeDomainFaPodBaseUrlDetails' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/IfMatchHeader' responses: 202: description: The update of the identity domain's fa pod base url is starting. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Update the fa pod base url of an identity domain tags: - identity x-obmcs-get-work-request-operation: GetIamWorkRequest x-related-resource: '#/definitions/Domain' /domains/{domainId}/actions/changeLicenseType: post: description: '(For tenancies that support identity domains) Changes the license type of the given identity domain. The identity domain''s `lifecycleState` must be set to ACTIVE and the requested `licenseType` must be allowed. To retrieve the allowed `licenseType` for the identity domain, use [ListAllowedDomainLicenseTypes](#/en/identity/20160918/Domain/ListAllowedDomainLicenseTypes). After you send your request, the `lifecycleDetails` of this identity domain is set to UPDATING. When the update of the identity domain completes, then the `lifecycleDetails` is set to null. To track the progress of the request, submitting an HTTP GET on the /iamWorkRequests/{iamWorkRequestsId} endpoint retrieves the operation''s status. ' operationId: ChangeDomainLicenseType parameters: - $ref: '#/parameters/DomainIdPathParam' - description: The request object for an update to the license type of the identity domain. in: body name: ChangeDomainLicenseTypeDetails required: true schema: $ref: '#/definitions/ChangeDomainLicenseTypeDetails' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/IfMatchHeader' responses: 202: description: The update of the identity domain's license type is starting. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Change the license type of an identity domain tags: - identity x-obmcs-get-work-request-operation: GetIamWorkRequest x-related-resource: '#/definitions/Domain' /domains/{domainId}/actions/deactivate: post: description: '(For tenancies that support identity domains) Deactivates the specified identity domain. Identity domains must be in an ACTIVE `lifecycleState` and have no active apps present in the domain or underlying Identity Cloud Service stripe. You cannot deactivate the default identity domain. After you send your request, the `lifecycleDetails` of this identity domain is set to DEACTIVATING. When the operation completes, then the `lifecycleDetails` is set to null and the `lifecycleState` is set to INACTIVE. To track the progress of the request, submitting an HTTP GET on the /iamWorkRequests/{iamWorkRequestsId} endpoint retrieves the operation''s status. ' operationId: DeactivateDomain parameters: - $ref: '#/parameters/DomainIdPathParam' - default: false description: Indicates whether domain can be forcefully deactivated even when there are Active Apps present in: query name: isForceDeactivate required: false type: boolean - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/IfMatchHeader' responses: 202: description: The identity domain deactivation is starting. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Deactivate an active identity domain. tags: - identity x-obmcs-get-work-request-operation: GetIamWorkRequest x-related-resource: '#/definitions/Domain' /domains/{domainId}/actions/enableReplicationToRegion: post: description: '(For tenancies that support identity domains) Replicates the identity domain to a new region (provided that the region is the tenancy home region or other region that the tenancy subscribes to). You can only replicate identity domains that are in an ACTIVE `lifecycleState` and not currently updating or already replicating. You also can only trigger the replication of secondary identity domains. The default identity domain is automatically replicated to all regions that the tenancy subscribes to. After you send the request, the `state` of the identity domain in the replica region is set to ENABLING_REPLICATION. When the operation completes, the `state` is set to REPLICATION_ENABLED. To track the progress of the request, submitting an HTTP GET on the /iamWorkRequests/{iamWorkRequestsId} endpoint retrieves the operation''s status. ' operationId: EnableReplicationToRegion parameters: - $ref: '#/parameters/DomainIdPathParam' - description: The request object for replicating the identity domain to another region. in: body name: EnableReplicationToRegionDetails required: true schema: $ref: '#/definitions/EnableReplicationToRegionDetails' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/IfMatchHeader' responses: 202: description: The identity domain replication is starting. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Replicate identity domain to a new region tags: - identity x-obmcs-get-work-request-operation: GetIamWorkRequest x-related-resource: '#/definitions/Domain' /dynamicGroups/: get: description: 'Lists the dynamic groups in your tenancy. You must specify your tenancy''s OCID as the value for the compartment ID (remember that the tenancy is simply the root compartment). See [Where to Get the Tenancy''s OCID and User''s OCID](/Content/API/Concepts/apisigningkey.htm#five). ' operationId: ListDynamicGroups parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/FilterByNameQueryParam' - $ref: '#/parameters/SortByQueryParam' - $ref: '#/parameters/SortOrderQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/DynamicGroup/lifecycleState' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/DynamicGroup' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListDynamicGroups tags: - identity post: description: 'Creates a new dynamic group in your tenancy. You must specify your tenancy''s OCID as the compartment ID in the request object (remember that the tenancy is simply the root compartment). Notice that IAM resources (users, groups, compartments, and some policies) reside within the tenancy itself, unlike cloud resources such as compute instances, which typically reside within compartments inside the tenancy. For information about OCIDs, see [Resource Identifiers](/Content/General/Concepts/identifiers.htm). You must also specify a *name* for the dynamic group, which must be unique across all dynamic groups in your tenancy, and cannot be changed. Note that this name has to be also unique across all groups in your tenancy. You can use this name or the OCID when writing policies that apply to the dynamic group. For more information about policies, see [How Policies Work](/Content/Identity/policieshow/how-policies-work.htm). You must also specify a *description* for the dynamic group (although it can be an empty string). It does not have to be unique, and you can change it anytime with [UpdateDynamicGroup](#/en/identity/20160918/DynamicGroup/UpdateDynamicGroup). After you send your request, the new object''s `lifecycleState` will temporarily be CREATING. Before using the object, first make sure its `lifecycleState` has changed to ACTIVE. ' operationId: CreateDynamicGroup parameters: - description: Request object for creating a new dynamic group. in: body name: CreateDynamicGroupDetails required: true schema: $ref: '#/definitions/CreateDynamicGroupDetails' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The dynamic group is being created. examples: application-json: "{\n \"id\" : \"ocid1.group.oc1..aaaaaaaavpexampleuniqueID\"\ ,\n \"compartmentId\" : \"ocid1.tenancy.oc1..aaaaaaaaba3pvexampleuniqueID\"\ ,\n \"name\" : \"DevCompartmentDynamicGroup\",\n \"description\" :\ \ \"Dynamic group for dev compartment\",\n \"matchingRule\": \"instance.compartment.id=ocid1.compartment.oc1..aaaaaaaayd6exampleuniqueID\"\ ,\n \"lifecycleState\" : \"ACTIVE\",\n \"timeCreated\" : \"2016-11-18T22:01:40.936Z\"\ \n}\n" headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/DynamicGroup' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateDynamicGroup tags: - identity x-example: "POST /20160918/dynamicGroups/\nHost: identity.us-phoenix-1.oraclecloud.com\n\ <authorization and other headers>\n{\n \"compartmentId\"\ \ : \"ocid1.tenancy.oc1..aaaaaaaaba3pv6exampleuniqueID\",\n \"description\"\ \ : \"Instance group for dev compartment\",\n \"name\" : \"DevCompartmentDynamicGroup\"\ ,\n \"matchingRule\": \"instance.compartment.id=ocid1.compartment.oc1..aaaaaaaayd6iexampleuniqueID\"\ \n}\n" /dynamicGroups/{dynamicGroupId}: delete: description: 'Deletes the specified dynamic group. ' operationId: DeleteDynamicGroup parameters: - $ref: '#/parameters/DynamicGroupIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The dynamic group is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteDynamicGroup tags: - identity get: description: 'Gets the specified dynamic group''s information. ' operationId: GetDynamicGroup parameters: - $ref: '#/parameters/DynamicGroupIdPathParam' responses: 200: description: The dynamic group was retrieved. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/DynamicGroup' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetDynamicGroup tags: - identity put: description: Updates the specified dynamic group. operationId: UpdateDynamicGroup parameters: - $ref: '#/parameters/DynamicGroupIdPathParam' - description: Request object for updating an dynamic group. in: body name: UpdateDynamicGroupDetails required: true schema: $ref: '#/definitions/UpdateDynamicGroupDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The dynamic group is being updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/DynamicGroup' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateDynamicGroup tags: - identity /faultDomains/: get: description: 'Lists the Fault Domains in your tenancy. Specify the OCID of either the tenancy or another of your compartments as the value for the compartment ID (remember that the tenancy is simply the root compartment). See [Where to Get the Tenancy''s OCID and User''s OCID](/Content/API/Concepts/apisigningkey.htm#five). ' operationId: ListFaultDomains parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/AvailabilityDomainQueryParam' responses: 200: description: The list is being retrieved. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/FaultDomain' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListFaultDomains tags: - identity /groups/: get: description: 'Lists the groups in your tenancy. You must specify your tenancy''s OCID as the value for the compartment ID (remember that the tenancy is simply the root compartment). See [Where to Get the Tenancy''s OCID and User''s OCID](/Content/API/Concepts/apisigningkey.htm#five). ' operationId: ListGroups parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/FilterByNameQueryParam' - $ref: '#/parameters/SortByQueryParam' - $ref: '#/parameters/SortOrderQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/Group/lifecycleState' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/Group' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListGroups tags: - identity post: description: 'Creates a new group in your tenancy. You must specify your tenancy''s OCID as the compartment ID in the request object (remember that the tenancy is simply the root compartment). Notice that IAM resources (users, groups, compartments, and some policies) reside within the tenancy itself, unlike cloud resources such as compute instances, which typically reside within compartments inside the tenancy. For information about OCIDs, see [Resource Identifiers](/Content/General/Concepts/identifiers.htm). You must also specify a *name* for the group, which must be unique across all groups in your tenancy and cannot be changed. You can use this name or the OCID when writing policies that apply to the group. For more information about policies, see [How Policies Work](/Content/Identity/policieshow/how-policies-work.htm). You must also specify a *description* for the group (although it can be an empty string). It does not have to be unique, and you can change it anytime with [UpdateGroup](#/en/identity/20160918/Group/UpdateGroup). After you send your request, the new object''s `lifecycleState` will temporarily be CREATING. Before using the object, first make sure its `lifecycleState` has changed to ACTIVE. After creating the group, you need to put users in it and write policies for it. See [AddUserToGroup](#/en/identity/20160918/UserGroupMembership/AddUserToGroup) and [CreatePolicy](#/en/identity/20160918/Policy/CreatePolicy). ' operationId: CreateGroup parameters: - description: Request object for creating a new group. in: body name: createGroupDetails required: true schema: $ref: '#/definitions/CreateGroupDetails' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The group is being created. examples: application-json: "{\n \"id\" : \"ocid1.group.oc1..aaaaaaaavp6exampleuniqueID\"\ ,\n \"compartmentId\" : \"ocid1.tenancy.oc1..aaaaaaaaba3exampleuniqueID\"\ ,\n \"name\" : \"NetworkAdmins\",\n \"description\" : \"Group for\ \ network administrators\",\n \"lifecycleState\" : \"ACTIVE\",\n \"\ timeCreated\" : \"2016-11-18T22:01:40.936Z\"\n}\n" headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Group' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateGroup tags: - identity x-example: "POST /20160918/groups/\nHost: identity.us-phoenix-1.oraclecloud.com\n\ <authorization and other headers>\n{\n \"compartmentId\"\ \ : \"ocid1.tenancy.oc1..aaaaaaaaba3pvexampleuniqueID\",\n \"description\"\ \ : \"Group for network administrators\",\n \"name\" : \"NetworkAdmins\"\n\ }\n" /groups/{groupId}: delete: description: 'Deletes the specified group. The group must be empty. ' operationId: DeleteGroup parameters: - $ref: '#/parameters/GroupIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The group is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteGroup tags: - identity get: description: 'Gets the specified group''s information. This operation does not return a list of all the users in the group. To do that, use [ListUserGroupMemberships](#/en/identity/20160918/UserGroupMembership/ListUserGroupMemberships) and provide the group''s OCID as a query parameter in the request. ' operationId: GetGroup parameters: - $ref: '#/parameters/GroupIdPathParam' responses: 200: description: The group was retrieved. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Group' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetGroup tags: - identity put: description: Updates the specified group. operationId: UpdateGroup parameters: - $ref: '#/parameters/GroupIdPathParam' - description: Request object for updating a group. in: body name: updateGroupDetails required: true schema: $ref: '#/definitions/UpdateGroupDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The group is being updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Group' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateGroup tags: - identity /iamWorkRequests: get: description: 'Lists the IAM work requests in compartment. The workRequestID is returned in the opc-work-request-id header for any asynchronous operation in the Identity and Access Management service. ' operationId: ListIamWorkRequests parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/ResourceIdentifierQueryParam' - $ref: '#/parameters/RequestIdHeader' responses: 200: description: A list of IAM work requests. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/IamWorkRequestSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: List IAM work requests tags: - identity /iamWorkRequests/{iamWorkRequestId}: get: description: 'Gets the details of a specified IAM work request. The workRequestID is returned in the opc-work-request-id header for any asynchronous operation in the Identity and Access Management service. ' operationId: GetIamWorkRequest parameters: - $ref: '#/parameters/IamWorkRequestIdPathParam' - $ref: '#/parameters/RequestIdHeader' responses: 200: description: IAM Work request headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/IamWorkRequest' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Gets IAM work request tags: - identity /iamWorkRequests/{iamWorkRequestId}/errors: get: description: 'Gets error details for a specified IAM work request. The workRequestID is returned in the opc-work-request-id header for any asynchronous operation in the Identity and Access Management service. ' operationId: ListIamWorkRequestErrors parameters: - $ref: '#/parameters/IamWorkRequestIdPathParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/SortOrderQueryParam' - $ref: '#/parameters/RequestIdHeader' responses: 200: description: The list of work request errors. headers: opc-next-page: description: 'For list pagination. When this header appears in the response, additional pages of results remain. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/IamWorkRequestErrorSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Lists work request errors tags: - identity x-related-resource: '#/definitions/IamWorkRequest' /iamWorkRequests/{iamWorkRequestId}/logs: get: description: 'Gets logs for a specified IAM work request. The workRequestID is returned in the opc-work-request-id header for any asynchronous operation in the Identity and Access Management service. ' operationId: ListIamWorkRequestLogs parameters: - $ref: '#/parameters/IamWorkRequestIdPathParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/SortOrderQueryParam' - $ref: '#/parameters/RequestIdHeader' responses: 200: description: The list of IAM work request logs. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string retry-after: description: 'The number of seconds that the client should wait before polling again. ' format: float type: number schema: items: $ref: '#/definitions/IamWorkRequestLogSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: List IAM workrequest logs tags: - identity /identityProviders/: get: deprecated: true description: '**Deprecated.** For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm). Lists all the identity providers in your tenancy. You must specify the identity provider type (e.g., `SAML2` for identity providers using the SAML2.0 protocol). You must specify your tenancy''s OCID as the value for the compartment ID (remember that the tenancy is simply the root compartment). See [Where to Get the Tenancy''s OCID and User''s OCID](/Content/API/Concepts/apisigningkey.htm#five). ' operationId: ListIdentityProviders parameters: - $ref: '#/parameters/IdentityProviderProtocolQueryParam' - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/FilterByNameQueryParam' - $ref: '#/parameters/SortByQueryParam' - $ref: '#/parameters/SortOrderQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/IdentityProvider/lifecycleState' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/IdentityProvider' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListIdentityProviders tags: - identity post: deprecated: true description: '**Deprecated.** For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm). Creates a new identity provider in your tenancy. For more information, see [Identity Providers and Federation](/Content/Identity/Concepts/federation.htm). You must specify your tenancy''s OCID as the compartment ID in the request object. Remember that the tenancy is simply the root compartment. For information about OCIDs, see [Resource Identifiers](/Content/General/Concepts/identifiers.htm). You must also specify a *name* for the `IdentityProvider`, which must be unique across all `IdentityProvider` objects in your tenancy and cannot be changed. You must also specify a *description* for the `IdentityProvider` (although it can be an empty string). It does not have to be unique, and you can change it anytime with [UpdateIdentityProvider](#/en/identity/20160918/IdentityProvider/UpdateIdentityProvider). After you send your request, the new object''s `lifecycleState` will temporarily be CREATING. Before using the object, first make sure its `lifecycleState` has changed to ACTIVE. ' operationId: CreateIdentityProvider parameters: - description: Request object for creating a new SAML2 identity provider. in: body name: createIdentityProviderDetails required: true schema: $ref: '#/definitions/CreateIdentityProviderDetails' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The identity provider is being created. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/IdentityProvider' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateIdentityProvider tags: - identity /identityProviders/{identityProviderId}: delete: deprecated: true description: '**Deprecated.** For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm). Deletes the specified identity provider. The identity provider must not have any group mappings (see [IdpGroupMapping](#/en/identity/20160918/IdpGroupMapping/)). ' operationId: DeleteIdentityProvider parameters: - $ref: '#/parameters/IdentityProviderIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The identity provider is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteIdentityProvider tags: - identity get: deprecated: true description: '**Deprecated.** For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm). Gets the specified identity provider''s information. ' operationId: GetIdentityProvider parameters: - $ref: '#/parameters/IdentityProviderIdPathParam' responses: 200: description: The user was found. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/IdentityProvider' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetIdentityProvider tags: - identity put: deprecated: true description: '**Deprecated.** For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm). Updates the specified identity provider. ' operationId: UpdateIdentityProvider parameters: - $ref: '#/parameters/IdentityProviderIdPathParam' - description: Request object for updating a identity provider. in: body name: updateIdentityProviderDetails required: true schema: $ref: '#/definitions/UpdateIdentityProviderDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The identity provider is being updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/IdentityProvider' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateIdentityProvider tags: - identity /identityProviders/{identityProviderId}/actions/resetScimClient/: post: description: 'Resets the OAuth2 client credentials for the SCIM client associated with this identity provider. ' operationId: ResetIdpScimClient parameters: - $ref: '#/parameters/IdentityProviderIdPathParam' responses: 200: description: The client credentials were reset successfully. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/ScimClientCredentials' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ResetIdpScimClient tags: - identity /identityProviders/{identityProviderId}/groupMappings/: get: deprecated: true description: '**Deprecated.** For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm). Lists the group mappings for the specified identity provider. ' operationId: ListIdpGroupMappings parameters: - $ref: '#/parameters/IdentityProviderIdPathParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/IdpGroupMapping' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListIdpGroupMappings tags: - identity post: deprecated: true description: '**Deprecated.** For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm). Creates a single mapping between an IdP group and an IAM Service [group](#/en/identity/20160918/Group/). ' operationId: CreateIdpGroupMapping parameters: - description: Add a mapping from an SAML2.0 identity provider group to a BMC group. in: body name: createIdpGroupMappingDetails required: true schema: $ref: '#/definitions/CreateIdpGroupMappingDetails' - $ref: '#/parameters/IdentityProviderIdPathParam' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The mapping is being created. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/IdpGroupMapping' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateIdpGroupMapping tags: - identity /identityProviders/{identityProviderId}/groupMappings/{mappingId}: delete: deprecated: true description: '**Deprecated.** For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm). Deletes the specified group mapping. ' operationId: DeleteIdpGroupMapping parameters: - $ref: '#/parameters/IdentityProviderIdPathParam' - $ref: '#/parameters/IdpGroupMappingIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The mapping is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteIdpGroupMapping tags: - identity get: deprecated: true description: '**Deprecated.** For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm). Gets the specified group mapping. ' operationId: GetIdpGroupMapping parameters: - $ref: '#/parameters/IdentityProviderIdPathParam' - $ref: '#/parameters/IdpGroupMappingIdPathParam' responses: 200: description: The mapping is being retrieved. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/IdpGroupMapping' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetIdpGroupMapping tags: - identity put: deprecated: true description: '**Deprecated.** For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm). Updates the specified group mapping. ' operationId: UpdateIdpGroupMapping parameters: - $ref: '#/parameters/IdentityProviderIdPathParam' - $ref: '#/parameters/IdpGroupMappingIdPathParam' - description: Request object for updating an identity provider group mapping in: body name: updateIdpGroupMappingDetails required: true schema: $ref: '#/definitions/UpdateIdpGroupMappingDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The identity provider is being updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/IdpGroupMapping' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateIdpGroupMapping tags: - identity /identityProviders/{identityProviderId}/groups/: get: deprecated: true description: '**Deprecated.** For more information, see [Deprecated IAM Service APIs](/Content/Identity/Reference/deprecatediamapis.htm). Lists the identity provider groups. ' operationId: ListIdentityProviderGroups parameters: - $ref: '#/parameters/IdentityProviderIdPathParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/FilterByNameQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/IdentityProvider/lifecycleState' responses: 200: description: The identity provider groups are being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/IdentityProviderGroupSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Gets the identity provider groups. tags: - identity /networkSources: get: description: 'Lists the network sources in your tenancy. You must specify your tenancy''s OCID as the value for the compartment ID (remember that the tenancy is simply the root compartment). See [Where to Get the Tenancy''s OCID and User''s OCID](/Content/API/Concepts/apisigningkey.htm#five). ' operationId: ListNetworkSources parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/FilterByNameQueryParam' - $ref: '#/parameters/SortByQueryParam' - $ref: '#/parameters/SortOrderQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/NetworkSources/lifecycleState' responses: 200: description: The list is being retrieved headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/NetworkSourcesSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListNetworkSources tags: - identity post: description: 'Creates a new network source in your tenancy. You must specify your tenancy''s OCID as the compartment ID in the request object (remember that the tenancy is simply the root compartment). Notice that IAM resources (users, groups, compartments, and some policies) reside within the tenancy itself, unlike cloud resources such as compute instances, which typically reside within compartments inside the tenancy. For information about OCIDs, see [Resource Identifiers](/Content/General/Concepts/identifiers.htm). You must also specify a *name* for the network source, which must be unique across all network sources in your tenancy, and cannot be changed. You can use this name or the OCID when writing policies that apply to the network source. For more information about policies, see [How Policies Work](/Content/Identity/policieshow/how-policies-work.htm). You must also specify a *description* for the network source (although it can be an empty string). It does not have to be unique, and you can change it anytime with [UpdateNetworkSource](#/en/identity/20160918/NetworkSource/UpdateNetworkSource). After you send your request, the new object''s `lifecycleState` will temporarily be CREATING. Before using the object, first make sure its `lifecycleState` has changed to ACTIVE. After your network resource is created, you can use it in policy to restrict access to only requests made from an allowed IP address specified in your network source. For more information, see [Managing Network Sources](/Content/Identity/Tasks/managingnetworksources.htm). ' operationId: CreateNetworkSource parameters: - description: Request object for creating a new network source. in: body name: CreateNetworkSourceDetails required: true schema: $ref: '#/definitions/CreateNetworkSourceDetails' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The network source is being created. examples: application-json: "{\n \"id\": \"ocid1.networksource.oc1..aaaaaaaavp6jexampleuniqueID4q\"\ ,\n \"compartmentId\": \"ocid1.tenancy.oc1..aaaaaaaabbbbexampleuniqueIDdsq\"\ ,\n \"name\": \"corpnet\",\n \"description\": \"Network source for\ \ corporate network\",\n \"virtualSourceList\": [\n {\n \"\ vcnId\": \"ocid1.vcn.oc1.iad.aaaaaaaaozfexampleuniqueIDgcq\",\n \ \ \"ipRanges\": [\n \"129.213.39.0/24\"\n ]\n }\n ],\n\ \ \"publicSourceList\": [\n \"128.2.13.5\",\n \"128.2.14.0/24\"\ \n ],\n \"lifecycleState\": \"CREATING\",\n \"timeCreated\": \"2016-11-18T22:01:40.936Z\"\ \n}\n" headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/NetworkSources' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateNetworkSource tags: - identity x-example: "POST /20160918/networkSources/\nHost: identity.us-phoenix-1.oraclecloud.com\n\ <authorization and other headers>\n{\n \"compartmentId\"\ \ : \"ocid1.tenancy.oc1..aaaaaaaaba3exampleuniqueIDdsq\",\n \"description\"\ \ : \"corporate ip ranges to be used for ip based authorization\",\n \"name\"\ \ : \"corpnet\",\n \"virtualSourceList\":\n [\n {\"vcnId\": \"ocid1.vcn.oc1.iad.aaaaaaaaozexampleuniqueID6wcgcq\"\ , \"ipRanges\": [ \"129.213.39.0/24\" ]}\n ],\n \"publicSourceList\"\ : [ \"128.2.13.5\", \"128.2.13.6\" ],\n \"services\": [\"all\"]\n}\n" /networkSources/{networkSourceId}: delete: description: 'Deletes the specified network source. ' operationId: DeleteNetworkSource parameters: - $ref: '#/parameters/NetworkSourceIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The network source is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteNetworkSource tags: - identity x-related-resource: '#/definitions/NetworkSources' get: description: 'Gets the specified network source''s information. ' operationId: GetNetworkSource parameters: - $ref: '#/parameters/NetworkSourceIdPathParam' responses: 200: description: The network source was retrieved. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/NetworkSources' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetNetworkSource tags: - identity put: description: 'Updates the specified network source. ' operationId: UpdateNetworkSource parameters: - $ref: '#/parameters/NetworkSourceIdPathParam' - description: Request object for updating a network source. in: body name: UpdateNetworkSourceDetails required: true schema: $ref: '#/definitions/UpdateNetworkSourceDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The network source is being updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/NetworkSources' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateNetworkSource tags: - identity /policies/: get: description: 'Lists the policies in the specified compartment (either the tenancy or another of your compartments). See [Where to Get the Tenancy''s OCID and User''s OCID](/Content/API/Concepts/apisigningkey.htm#five). To determine which policies apply to a particular group or compartment, you must view the individual statements inside all your policies. There isn''t a way to automatically obtain that information via the API. ' operationId: ListPolicies parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/FilterByNameQueryParam' - $ref: '#/parameters/SortByQueryParam' - $ref: '#/parameters/SortOrderQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/Policy/lifecycleState' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/Policy' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListPolicies tags: - identity post: description: 'Creates a new policy in the specified compartment (either the tenancy or another of your compartments). If you''re new to policies, see [Get Started with Policies](/Content/Identity/policiesgs/get-started-with-policies.htm). You must specify a *name* for the policy, which must be unique across all policies in your tenancy and cannot be changed. You must also specify a *description* for the policy (although it can be an empty string). It does not have to be unique, and you can change it anytime with [UpdatePolicy](#/en/identity/20160918/Policy/UpdatePolicy). You must specify one or more policy statements in the statements array. For information about writing policies, see [How Policies Work](/Content/Identity/policieshow/how-policies-work.htm) and [Common Policies](/Content/Identity/policiescommon/commonpolicies.htm). After you send your request, the new object''s `lifecycleState` will temporarily be CREATING. Before using the object, first make sure its `lifecycleState` has changed to ACTIVE. New policies take effect typically within 10 seconds. ' operationId: CreatePolicy parameters: - description: Request object for creating a new policy. in: body name: createPolicyDetails required: true schema: $ref: '#/definitions/CreatePolicyDetails' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The policy is being created. examples: application-json: "{\n \"statements\" :\n [\n \"Allow group InstanceLaunchers\ \ to manage instance-family in compartment ABC\",\n \"Allow group\ \ InstanceLaunchers to use volume-family in compartment ABC\",\n \ \ \"Allow group InstanceLaunchers to use virtual-network-family in\ \ compartment XYZ\"\n ],\n \"id\" : \"ocid1.policy.oc1..aaaaaaaauzkexampleuniqueID\"\ ,\n \"compartmentId\" : \"ocid1.tenancy.oc1..aaaaaaaabaexampleuniqueID\"\ ,\n \"name\" : \"LaunchInstances\",\n \"description\" : \"Policy for\ \ users who need to launch instances, attach volumes, manage images\"\ ,\n \"lifecycleState\" : \"ACTIVE\",\n \"timeCreated\" : \"2016-12-07T00:49:14.807Z\"\ \n}\n" headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Policy' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreatePolicy tags: - identity x-example: "POST /20160918/policies/\nHost: identity.us-phoenix-1.oraclecloud.com\n\ <authorization and other headers>\n{\n \"compartmentId\"\ \ : \"ocid1.tenancy.oc1..aaaaaaaaba3pexampleuniqueID\",\n \"description\"\ \ : \"Policy for users who need to launch instances, attach volumes, manage\ \ images\",\n \"name\" : \"LaunchInstances\",\n \"statements\":\n [\n\ \ \"Allow group InstanceLaunchers to manage instance-family in compartment\ \ ABC\",\n \"Allow group InstanceLaunchers to use volume-family in compartment\ \ ABC\",\n \"Allow group InstanceLaunchers to use virtual-network-family\ \ in compartment Network\"\n ]\n}\n" /policies/{policyId}: delete: description: Deletes the specified policy. The deletion takes effect typically within 10 seconds. operationId: DeletePolicy parameters: - $ref: '#/parameters/PolicyIdPathParam' - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/OverrideLocksQueryParameter' responses: 204: description: The policy is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeletePolicy tags: - identity get: description: Gets the specified policy's information. operationId: GetPolicy parameters: - $ref: '#/parameters/PolicyIdPathParam' responses: 200: description: The policy was retrieved. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Policy' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetPolicy tags: - identity put: description: 'Updates the specified policy. You can update the description or the policy statements themselves. Policy changes take effect typically within 10 seconds. ' operationId: UpdatePolicy parameters: - $ref: '#/parameters/PolicyIdPathParam' - description: Request object for updating a policy. in: body name: updatePolicyDetails required: true schema: $ref: '#/definitions/UpdatePolicyDetails' - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/OverrideLocksQueryParameter' responses: 200: description: The policy was updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Policy' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdatePolicy tags: - identity /policies/{policyId}/actions/addLock: post: description: 'Add a resource lock to a tag namespace. ' operationId: AddPolicyLock parameters: - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/PolicyIdPathParam' - description: Lock that is going to be added to resource in: body name: AddPolicyLockDetails required: true schema: $ref: '#/definitions/AddPolicyLockDetails' produces: - application/json responses: 200: description: Lock is added headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Policy' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Add a resource lock to a policy tags: - identity x-related-resource: '#/definitions/Policy' /policies/{policyId}/actions/removeLock: post: description: 'Remove a resource lock to a policy ' operationId: RemovePolicyLock parameters: - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/PolicyIdPathParam' - description: Lock that is going to be removed from resource in: body name: RemovePolicyLockDetails required: true schema: $ref: '#/definitions/RemovePolicyLockDetails' produces: - application/json responses: 200: description: Lock is removed headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Policy' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Remove a resource lock to a policy tags: - identity x-related-resource: '#/definitions/Policy' /regions: get: description: Lists all the regions offered by Oracle Cloud Infrastructure. operationId: ListRegions responses: 200: description: The list is being retrieved. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/Region' type: array 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListRegions tags: - identity /tagDefaults: get: description: 'Lists the tag defaults for tag definitions in the specified compartment. ' operationId: ListTagDefaults parameters: - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/FilterByIdQueryParam' - $ref: '#/parameters/OptionalCompartmentIdQueryParam' - $ref: '#/parameters/OptionalTagDefinitionIdQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/TagDefaultSummary/lifecycleState' responses: 200: description: The list of tag default values. examples: application-json: "[\n {\n \"id\" : \"ocid1.tagdefault.oc1..aaaaaaaasexampleuniqueID\"\ ,\n \"compartmentId\" : \"ocid1.compartment.oc1..aaaaaaaaexampleuniqueID\"\ ,\n \"tagNamespaceId\" : \"ocid1.namespace.oc1..aaaaaaaaexampleuniqueID\"\ ,\n \"tagDefinitionId\" : \"ocid1.tagdefinition.oc1..aaaaaaaaexampleuniqueID\"\ ,\n \"tagDefinitionName\" : \"Finance\",\n \"value\" : \"W123\"\ ,\n \"timeCreated\" : \"2018-11-22T19:00:00.000Z\",\n \"lifecycleState\"\ \ : \"ACTIVE\",\n \"isRequired\" : \"true\"\n },\n {\n \"id\"\ \ : \"ocid1.tagdefault.oc1..aaaaaaaasexampleuniqueID\",\n \"compartmentId\"\ \ : \"ocid1.compartment.oc1..aaaaaaaaexampleuniqueID\",\n \"tagNamespaceId\"\ \ : \"ocid1.namespace.oc1..aaaaaaaaexampleuniqueID\",\n \"tagDefinitionId\"\ \ : \"ocid1.tagdefinition.oc1..aaaaaaaasexampleuniqueID\",\n \"tagDefinitionName\"\ \ : \"Operations\",\n \"value\" : \"Dept42\",\n \"timeCreated\"\ \ : \"2018-11-22T20:00:00.000Z\",\n \"lifecycleState\" : \"ACTIVE\"\ ,\n \"isRequired\" : \"false\"\n }\n]\n" headers: opc-next-page: description: 'For pagination of a list of tag default values. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/TagDefaultSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListTagDefaults tags: - identity x-example: 'GET /20160918/tagDefaults?compartmentId=ocid1.compartment.oc1..aaaaaaaamexampleuniqueID Host: identity.us-phoenix-1.oraclecloud.com <authorization and other headers> ' post: description: 'Creates a new tag default in the specified compartment for the specified tag definition. If you specify that a value is required, a value is set during resource creation (either by the user creating the resource or another tag defualt). If no value is set, resource creation is blocked. * If the `isRequired` flag is set to "true", the value is set during resource creation. * If the `isRequired` flag is set to "false", the value you enter is set during resource creation. ' operationId: CreateTagDefault parameters: - description: Request object for creating a new tag default. in: body name: CreateTagDefaultDetails required: true schema: $ref: '#/definitions/CreateTagDefaultDetails' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/RequestIdHeader' responses: 200: description: The tag default has been created. examples: application-json: "{\n \"id\" : \"ocid1.tagdefault.oc1..aaaaaaaashexampleuniqueID\"\ ,\n \"compartmentId\" : \"ocid1.compartment.oc1..aaaaaaaaexampleuniqueID\"\ ,\n \"tagNamespaceId\" : \"ocid1.namespace.oc1..aaaaaaaasexampleuniqueID\"\ ,\n \"tagDefinitionId\" : \"ocid1.tagdefinition.oc1..aaaaaaaash5exampleuniqueID\"\ ,\n \"tagDefinitionName\" : \"Finance\",\n \"value\" : \"W123\",\n\ \ \"timeCreated\" : \"2018-11-22T19:00:00.000Z\",\n \"lifecycleState\"\ \ : \"ACTIVE\",\n \"isRequired\" : \"true\"\n}\n" headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/TagDefault' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateTagDefault tags: - identity x-example: "POST /20160918/tagDefaults\nHost: identity.us-phoenix-1.oraclecloud.com\n\ <authorization and other headers>\n{\n \"compartmentId\"\ \ : \"ocid1.compartment.oc1..aaaaaaaaexampleuniqueID\",\n \"tagDefinitionId\"\ \ : \"ocid1.tagdefinition.oc1..aaaaaaaaexampleuniqueID\",\n \"value\" : \"\ W123\",\n \"isRequired\" : \"true\"\n}\n" /tagDefaults/actions/assembleEffectiveTagSet: get: description: 'Assembles tag defaults in the specified compartment and any parent compartments to determine the tags to apply. Tag defaults from parent compartments do not override tag defaults referencing the same tag in a compartment lower down the hierarchy. This set of tag defaults includes all tag defaults from the current compartment back to the root compartment. ' operationId: AssembleEffectiveTagSet parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/TagDefaultSummary/lifecycleState' responses: 200: description: The list of tag defaults. examples: application-json: "[\n {\n \"id\" : \"ocid1.tagdefault.oc1..aaaaaaaasexampleuniqueID\"\ ,\n \"compartmentId\" : \"ocid1.compartment.oc1..aaaaaaaaexampleuniqueID\"\ ,\n \"tagNamespaceId\" : \"ocid1.namespace.oc1..aaaaaaaaexampleuniqueID\"\ ,\n \"tagDefinitionId\" : \"ocid1.tagdefinition.oc1..aaaaaaaaexampleuniqueID\"\ ,\n \"tagDefinitionName\" : \"Finance\",\n \"value\" : \"W123\"\ ,\n \"timeCreated\" : \"2018-11-22T19:00:00.000Z\",\n \"lifecycleState\"\ \ : \"ACTIVE\",\n \"isRequired\" : \"true\"\n },\n {\n \"id\"\ \ : \"ocid1.tagdefault.oc1..aaaaaaaasexampleuniqueID\",\n \"compartmentId\"\ \ : \"ocid1.compartment.oc1..aaaaaaaaexampleuniqueID\",\n \"tagNamespaceId\"\ \ : \"ocid1.namespace.oc1..aaaaaaaaexampleuniqueID\",\n \"tagDefinitionId\"\ \ : \"ocid1.tagdefinition.oc1..aaaaaaaasexampleuniqueID\",\n \"tagDefinitionName\"\ \ : \"Operations\",\n \"value\" : \"Dept42\",\n \"timeCreated\"\ \ : \"2018-11-22T20:00:00.000Z\",\n \"lifecycleState\" : \"ACTIVE\"\ ,\n \"isRequired\" : \"false\"\n }\n]\n" headers: opc-next-page: description: 'For pagination of a list of tag default values. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/TagDefaultSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: AssembleEffectiveTagSet tags: - identity x-example: 'GET /20160918/tagDefaults/actions/assembleEffectiveTagSet?compartmentId=ocid1.compartment.oc1..aaaaaaaamexampleuniqueID Host: identity.us-phoenix-1.oraclecloud.com <authorization and other headers> ' x-related-resource: '#/definitions/TagDefault' /tagDefaults/{tagDefaultId}: delete: description: 'Deletes the the specified tag default. ' operationId: DeleteTagDefault parameters: - $ref: '#/parameters/TagDefaultIdPathParam' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/OverrideLocksQueryParam' responses: 204: description: The tag default was deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteTagDefault tags: - identity x-related-resource: '#/definitions/TagDefault' get: description: 'Retrieves the specified tag default. ' operationId: GetTagDefault parameters: - $ref: '#/parameters/TagDefaultIdPathParam' responses: 200: description: The tag default was retrieved. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/TagDefault' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetTagDefault tags: - identity put: description: 'Updates the specified tag default. If you specify that a value is required, a value is set during resource creation (either by the user creating the resource or another tag defualt). If no value is set, resource creation is blocked. * If the `isRequired` flag is set to "true", the value is set during resource creation. * If the `isRequired` flag is set to "false", the value you enter is set during resource creation. ' operationId: UpdateTagDefault parameters: - $ref: '#/parameters/TagDefaultIdPathParam' - $ref: '#/parameters/OverrideLocksQueryParam' - description: Request object for updating a tag default. in: body name: UpdateTagDefaultDetails required: true schema: $ref: '#/definitions/UpdateTagDefaultDetails' - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RequestIdHeader' responses: 200: description: The tag default was updated. examples: application-json: "{\n \"id\" : \"ocid1.tagdefault.oc1..aaaaaaaaexampleuniqueID\"\ ,\n \"compartmentId\" : \"ocid1.compartment.oc1..aaaaaaaaexampleuniqueID\"\ ,\n \"tagNamespaceId\" : \"ocid1.namespace.oc1..aaaaaaaasexampleuniqueID\"\ ,\n \"tagDefinitionId\" : \"ocid1.tagdefinition.oc1..aaaaaaaasexampleuniqueID\"\ ,\n \"tagDefinitionName\" : \"Finance\",\n \"value\" : \"W123\",\n\ \ \"timeCreated\" : \"2018-11-22T19:00:00.000Z\",\n \"lifecycleState\"\ \ : \"ACTIVE\",\n \"isRequired\" : \"false\"\n}\n" headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/TagDefault' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateTagDefault tags: - identity x-example: "PUT /20160918/tagDefaults/ocid1.tagdefault.oc1..aaaaaaaasexampleuniqueID\n\ Host: identity.us-phoenix-1.oraclecloud.com\n<authorization and other\ \ headers>\n{\n \"value\" : \"W123\",\n \"isRequired\" : \"true\"\ \n}\n" /tagDefaults/{tagDefaultId}/actions/addLock: post: description: 'Add a resource lock to a tag default. ' operationId: AddTagDefaultLock parameters: - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/TagDefaultIdPathParam' - description: Lock that is going to be added to resource in: body name: AddLockDetails required: true schema: $ref: '#/definitions/AddLockDetails' produces: - application/json responses: 200: description: Lock is added headers: etag: type: string opc-request-id: type: string schema: $ref: '#/definitions/TagDefault' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Add a resource lock to a tag default tags: - identity x-related-resource: '#/definitions/TagDefault' /tagDefaults/{tagDefaultId}/actions/removeLock: post: description: 'Remove a resource lock from a tag default. ' operationId: RemoveTagDefaultLock parameters: - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/TagDefaultIdPathParam' - description: Lock that is going to be removed from resource in: body name: RemoveLockDetails required: true schema: $ref: '#/definitions/RemoveLockDetails' produces: - application/json responses: 200: description: Lock is removed headers: etag: type: string opc-request-id: type: string schema: $ref: '#/definitions/TagDefault' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Remove a resource lock from a tag default tags: - identity x-related-resource: '#/definitions/TagDefault' /tagNamespaces: get: description: 'Lists the tag namespaces in the specified compartment. ' operationId: ListTagNamespaces parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - description: 'An optional boolean parameter indicating whether to retrieve all tag namespaces in subcompartments. If this parameter is not specified, only the tag namespaces defined in the specified compartment are retrieved. ' in: query name: includeSubcompartments required: false type: boolean - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/TagNamespace/lifecycleState' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of tagNamespaces. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/TagNamespaceSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListTagNamespaces tags: - identity post: description: 'Creates a new tag namespace in the specified compartment. You must specify the compartment ID in the request object (remember that the tenancy is simply the root compartment). You must also specify a *name* for the namespace, which must be unique across all namespaces in your tenancy and cannot be changed. The name can contain any ASCII character except the space (_) or period (.). Names are case insensitive. That means, for example, "myNamespace" and "mynamespace" are not allowed in the same tenancy. Once you created a namespace, you cannot change the name. If you specify a name that''s already in use in the tenancy, a 409 error is returned. You must also specify a *description* for the namespace. It does not have to be unique, and you can change it with [UpdateTagNamespace](#/en/identity/latest/TagNamespace/UpdateTagNamespace). ' operationId: CreateTagNamespace parameters: - description: Request object for creating a new tag namespace. in: body name: CreateTagNamespaceDetails required: true schema: $ref: '#/definitions/CreateTagNamespaceDetails' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The tagNamespace is being created. examples: application-json: "{\n \"id\" : \"ocid1.namespace.oc1..aaaaaaaaqexampleuniqueID\"\ ,\n \"compartmentId\" : \"ocid1.tenancy.oc1..aaaaaaaabaexampleuniqueID\"\ ,\n \"name\" : \"BillingTags\",\n \"description\" : \"This namespace\ \ contains tags that will be used in billing.\",\n \"isRetired\" :\ \ \"false\",\n \"lifecycleState\" : \"ACTIVE\",\n \"timeCreated\"\ \ : \"2017-09-01T18:13:12.210Z\"\n}\n" headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/TagNamespace' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateTagNamespace tags: - identity x-example: "POST /20160918/tagNamespaces/\nHost: identity.us-phoenix-1.oraclecloud.com\n\ <authorization and other headers>\n{\n \"compartmentId\"\ \ : \"ocid1.tenancy.oc1..aaaaaaaabaexampleuniqueID\",\n \"name\" : \"BillingTags\"\ ,\n \"description\" : \"This namespace contains tags that will be used in\ \ billing.\",\n}\n" /tagNamespaces/actions/listCostTrackingTags: get: description: 'Lists all the tags enabled for cost-tracking in the specified tenancy. Note that all tags are now available for cost-tracking and can be exposed in Cost Analysis or Cost and Usage Reports. This operation is available for backwards compatibility only. For more information, see [Overview of Tagging](/iaas/Content/Tagging/Concepts/taggingoverview.htm). ' operationId: ListCostTrackingTags parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' responses: 200: description: List of cost tracking tags defined in the compartment headers: opc-next-page: description: 'For pagination of a list of cost tracking tag. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/Tag' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListCostTrackingTags tags: - identity /tagNamespaces/{tagNamespaceId}: delete: description: 'Deletes the specified tag namespace. Only an empty tag namespace can be deleted with this operation. To use this operation to delete a tag namespace that contains tag definitions, first delete all of its tag definitions. Use [CascadeDeleteTagNamespace](#/en/identity/20160918/TagNamespace/CascadeDeleteTagNamespace) to delete a tag namespace along with all of the tag definitions contained within that namespace. Use [DeleteTag](#/en/identity/latest/Tag/DeleteTag) to delete a tag definition. ' operationId: DeleteTagNamespace parameters: - $ref: '#/parameters/TagNamespaceIdPathParam' - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/OverrideLocksQueryParam' responses: 204: description: The tag namespace has successfully been deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteTagNamespace tags: - identity x-example: 'DELETE /20160918/tagNamespaces/<tagNamespace_OCID> Host: identity.us-phoenix-1.oraclecloud.com <authorization and other headers> ' x-related-resource: '#/definitions/TagNamespace' get: description: 'Gets the specified tag namespace''s information. ' operationId: GetTagNamespace parameters: - $ref: '#/parameters/TagNamespaceIdPathParam' responses: 200: description: The tagNamespace was retrieved. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/TagNamespace' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetTagNamespace tags: - identity put: description: 'Updates the the specified tag namespace. You can''t update the namespace name. Updating `isRetired` to ''true'' retires the namespace and all the tag definitions in the namespace. Reactivating a namespace (changing `isRetired` from ''true'' to ''false'') does not reactivate tag definitions. To reactivate the tag definitions, you must reactivate each one individually *after* you reactivate the namespace, using [UpdateTag](#/en/identity/20160918/Tag/UpdateTag). For more information about retiring tag namespaces, see [Retiring Key Definitions and Namespace Definitions](/Content/Tagging/Tasks/managingtagsandtagnamespaces.htm#retiringkeys). You can''t add a namespace with the same name as a retired namespace in the same tenancy. ' operationId: UpdateTagNamespace parameters: - $ref: '#/parameters/TagNamespaceIdPathParam' - $ref: '#/parameters/OverrideLocksQueryParam' - description: Request object for updating a namespace. in: body name: UpdateTagNamespaceDetails required: true schema: $ref: '#/definitions/UpdateTagNamespaceDetails' responses: 200: description: The tagNamespace was updated. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/TagNamespace' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateTagNamespace tags: - identity /tagNamespaces/{tagNamespaceId}/actions/addLock: post: description: 'Add a resource lock to a tag namespace. ' operationId: AddTagNamespaceLock parameters: - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/TagNamespaceIdPathParam' - description: Lock that is going to be added to resource in: body name: AddLockDetails required: true schema: $ref: '#/definitions/AddLockDetails' produces: - application/json responses: 200: description: Lock is added headers: etag: type: string opc-request-id: type: string schema: $ref: '#/definitions/TagNamespace' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Add a resource lock to a tag namespace tags: - identity x-related-resource: '#/definitions/TagNamespace' /tagNamespaces/{tagNamespaceId}/actions/cascadeDelete: post: description: "Deletes the specified tag namespace. This operation triggers a\ \ process that removes all of the tags\ndefined in the specified tag namespace\ \ from all resources in your tenancy and then deletes the tag namespace.\n\ \nAfter you start the delete operation:\n\n * New tag key definitions cannot\ \ be created under the namespace.\n * The state of the tag namespace changes\ \ to DELETING.\n * Tag removal from the resources begins.\n\nThis process\ \ can take up to 48 hours depending on the number of tag definitions in the\ \ namespace, the number of resources\nthat are tagged, and the locations of\ \ the regions in which those resources reside.\n\nAfter all tags are removed,\ \ the state changes to DELETED. You cannot restore a deleted tag namespace.\ \ After the deleted tag namespace\nchanges its state to DELETED, you can use\ \ the name of the deleted tag namespace again.\n\nAfter you start this operation,\ \ you cannot start either the [DeleteTag](#/en/identity/20160918/Tag/DeleteTag)\ \ or the [BulkDeleteTags](#/en/identity/20160918/Tag/BulkDeleteTags) operation\ \ until this process completes.\n\nTo delete a tag namespace, you must first\ \ retire it. Use [UpdateTagNamespace](#/en/identity/20160918/TagNamespace/UpdateTagNamespace)\n\ to retire a tag namespace.\n" operationId: CascadeDeleteTagNamespace parameters: - $ref: '#/parameters/TagNamespaceIdPathParam' - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/OverrideLocksQueryParam' responses: 202: description: The request was accepted for processing. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Delete tag namespace that contains tags tags: - identity x-example: 'POST /tagNamespaces/<tagNamespace_OCID>/actions/cascadeDelete/ Host: identity.us-phoenix-1.oraclecloud.com <authorization and other headers> ' x-obmcs-get-work-request-operation: GetTaggingWorkRequest x-related-resource: '#/definitions/TagNamespace' /tagNamespaces/{tagNamespaceId}/actions/changeCompartment: post: description: 'Moves the specified tag namespace to the specified compartment within the same tenancy. To move the tag namespace, you must have the manage tag-namespaces permission on both compartments. For more information about IAM policies, see [Details for IAM](/Content/Identity/policyreference/iampolicyreference.htm). Moving a tag namespace moves all the tag key definitions contained in the tag namespace. ' operationId: ChangeTagNamespaceCompartment parameters: - $ref: '#/parameters/TagNamespaceIdPathParam' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/OverrideLocksQueryParam' - description: Request object for changing the compartment of a tag namespace. in: body name: ChangeTagNamespaceCompartmentDetail required: true schema: $ref: '#/definitions/ChangeTagNamespaceCompartmentDetail' responses: 204: description: The compartment of the tag namespace was changed. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: changes compartment of a tag namespace. tags: - identity x-related-resource: '#/definitions/TagNamespace' /tagNamespaces/{tagNamespaceId}/actions/removeLock: post: description: 'Remove a resource lock from a tag namespace. ' operationId: RemoveTagNamespaceLock parameters: - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/TagNamespaceIdPathParam' - description: Lock that is going to be removed from resource in: body name: RemoveLockDetails required: true schema: $ref: '#/definitions/RemoveLockDetails' produces: - application/json responses: 200: description: Lock is removed headers: etag: type: string opc-request-id: type: string schema: $ref: '#/definitions/TagNamespace' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Remove a resource lock from a tag namespace tags: - identity x-related-resource: '#/definitions/TagNamespace' /tagNamespaces/{tagNamespaceId}/tags: get: description: 'Lists the tag definitions in the specified tag namespace. ' operationId: ListTags parameters: - $ref: '#/parameters/TagNamespaceIdPathParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/Tag/lifecycleState' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of tags. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/TagSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListTags tags: - identity post: description: 'Creates a new tag in the specified tag namespace. The tag requires either the OCID or the name of the tag namespace that will contain this tag definition. You must specify a *name* for the tag, which must be unique across all tags in the tag namespace and cannot be changed. The name can contain any ASCII character except the space (_) or period (.) characters. Names are case insensitive. That means, for example, "myTag" and "mytag" are not allowed in the same namespace. If you specify a name that''s already in use in the tag namespace, a 409 error is returned. The tag must have a *description*. It does not have to be unique, and you can change it with [UpdateTag](#/en/identity/latest/Tag/UpdateTag). The tag must have a value type, which is specified with a validator. Tags can use either a static value or a list of possible values. Static values are entered by a user applying the tag to a resource. Lists are created by you and the user must apply a value from the list. Lists are validiated. * If no `validator` is set, the user applying the tag to a resource can type in a static value or leave the tag value empty. * If a `validator` is set, the user applying the tag to a resource must select from a list of values that you supply with [EnumTagDefinitionValidator](#/en/identity/latest/datatypes/EnumTagDefinitionValidator). ' operationId: CreateTag parameters: - $ref: '#/parameters/TagNamespaceIdPathParam' - description: Request object for creating a new tag in the specified tag namespace. in: body name: CreateTagDetails required: true schema: $ref: '#/definitions/CreateTagDetails' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/OverrideLocksQueryParam' responses: 200: description: The tag is being created. examples: application-json: "{\n \"name\" : \"CostCenter\",\n \"description\"\ \ : \"This tag will show the cost center that will be used for billing\ \ of associated resources.\",\n \"type\" : \"string\",\n \"tagNamespaceId\"\ \ : \"ocid1.namespace.oc1..aaaaaaaaqexampleuniqueID\",\n \"tagNameSpaceName\"\ \ : \"BillingTags\",\n \"compartmentId\" : \"ocid1.tenancy.oc1..aaaaaaaabaexampleuniqueID\"\ ,\n \"isRetired\" : \"false\",\n \"lifecycleState\" : \"ACTIVE\",\n\ \ \"timeCreated\" : \"2017-09-01T18:13:12.210Z\",\n \"isCostTracking\"\ \ : \"true\",\n \"validator\" : {}\n}\n" headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Tag' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateTag tags: - identity x-example: "POST /20160918/tagNamespaces/ocid1.tagnamespace.oc1..aaaaaaaabaexampleuniqueID/tags\n\ Host: identity.us-phoenix-1.oraclecloud.com\n<authorization and other\ \ headers>\n{\n \"name\" : \"CostCenter\",\n \"description\" :\ \ \"This tag will show the cost center that will be used for billing of associated\ \ resources.\",\n \"type\" : \"string\"\n}\n" /tagNamespaces/{tagNamespaceId}/tags/{tagName}: delete: description: "Deletes the specified tag definition. This operation triggers\ \ a process that removes the\ntag from all resources in your tenancy.\n\n\ These things happen immediately:\n * If the tag was a cost-tracking tag,\ \ it no longer counts against your 10 cost-tracking\n tags limit, whether\ \ you first disabled it or not.\n * If the tag was used with dynamic groups,\ \ none of the rules that contain the tag will\n be evaluated against the\ \ tag.\n\nWhen you start the delete operation, the state of the tag changes\ \ to DELETING and tag removal\nfrom resources begins. This can take up to\ \ 48 hours depending on the number of resources that\nwere tagged as well\ \ as the regions in which those resources reside.\n\nWhen all tags have been\ \ removed, the state changes to DELETED. You cannot restore a deleted tag.\ \ Once the deleted tag\nchanges its state to DELETED, you can use the same\ \ tag name again.\n\nAfter you start this operation, you cannot start either\ \ the [BulkDeleteTags](#/en/identity/20160918/Tag/BulkDeleteTags) or the [CascadeDeleteTagNamespace](#/en/identity/20160918/TagNamespace/CascadeDeleteTagNamespace)\ \ operation until this process completes.\n\nTo delete a tag, you must first\ \ retire it. Use [UpdateTag](#/en/identity/latest/Tag/UpdateTag)\nto retire\ \ a tag.\n" operationId: DeleteTag parameters: - $ref: '#/parameters/TagNamespaceIdPathParam' - $ref: '#/parameters/TagNamePathParam' - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/OverrideLocksQueryParam' responses: 202: description: The request was accepted for processing. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteTag tags: - identity x-example: 'DELETE /20160918/tagNamespaces/<tagNamespace_OCID>/tags/<TagName> Host: identity.us-phoenix-1.oraclecloud.com <authorization and other headers> ' x-obmcs-get-work-request-operation: GetTaggingWorkRequest x-related-resource: '#/definitions/Tag' get: description: Gets the specified tag's information. operationId: GetTag parameters: - $ref: '#/parameters/TagNamespaceIdPathParam' - $ref: '#/parameters/TagNamePathParam' responses: 200: description: The tag was retrieved. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Tag' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetTag tags: - identity put: description: 'Updates the specified tag definition. Setting `validator` determines the value type. Tags can use either a static value or a list of possible values. Static values are entered by a user applying the tag to a resource. Lists are created by you and the user must apply a value from the list. On update, any values in a list that were previously set do not change, but new values must pass validation. Values already applied to a resource do not change. You cannot remove list values that appear in a TagDefault. To remove a list value that appears in a TagDefault, first update the TagDefault to use a different value. ' operationId: UpdateTag parameters: - $ref: '#/parameters/TagNamespaceIdPathParam' - $ref: '#/parameters/TagNamePathParam' - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/OverrideLocksQueryParam' - description: Request object for updating a tag. in: body name: UpdateTagDetails required: true schema: $ref: '#/definitions/UpdateTagDetails' responses: 200: description: The tag was updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Tag' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateTag tags: - identity /taggingWorkRequests/: get: description: 'Lists the tagging work requests in compartment. ' operationId: ListTaggingWorkRequests parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/ResourceIdentifierQueryParam' responses: 200: description: A list of tagging work requests. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/TaggingWorkRequestSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListTaggingWorkRequests tags: - identity /taggingWorkRequests/{workRequestId}: get: description: 'Gets details on a specified work request. The workRequestID is returned in the opc-work-request-id header for any asynchronous operation in tagging service. ' operationId: GetTaggingWorkRequest parameters: - $ref: '#/parameters/WorkRequestIdPathParam' responses: 200: description: The work request was retrieved. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string retry-after: description: 'The number of seconds that the client should wait before polling again. ' format: float type: number schema: $ref: '#/definitions/TaggingWorkRequest' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetTaggingWorkRequest tags: - identity /taggingWorkRequests/{workRequestId}/errors: get: description: 'Gets the errors for a work request. ' operationId: ListTaggingWorkRequestErrors parameters: - $ref: '#/parameters/WorkRequestIdPathParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' responses: 200: description: The list of work request errors. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string retry-after: description: 'The number of seconds that the client should wait before polling again. ' format: float type: number schema: items: $ref: '#/definitions/TaggingWorkRequestErrorSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListTaggingWorkRequestErrors tags: - identity /taggingWorkRequests/{workRequestId}/logs: get: description: 'Gets the logs for a work request. ' operationId: ListTaggingWorkRequestLogs parameters: - $ref: '#/parameters/WorkRequestIdPathParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' responses: 200: description: The list of work request logs. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string retry-after: description: 'The number of seconds that the client should wait before polling again. ' format: float type: number schema: items: $ref: '#/definitions/TaggingWorkRequestLogSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListTaggingWorkRequestLogs tags: - identity /tags/actions/bulkDelete: post: description: "Deletes the specified tag key definitions. This operation triggers\ \ a process that removes the\ntags from all resources in your tenancy. The\ \ tag key definitions must be within the same tag namespace.\n\nThe following\ \ actions happen immediately:\n\n * If the tag is a cost-tracking tag, the\ \ tag no longer counts against your\n 10 cost-tracking tags limit, even if\ \ you do not disable the tag before running this operation.\n * If the tag\ \ is used with dynamic groups, the rules that contain the tag are no longer\n\ \ evaluated against the tag.\n\nAfter you start this operation, the state\ \ of the tag changes to DELETING, and tag removal\nfrom resources begins.\ \ This process can take up to 48 hours depending on the number of resources\ \ that\nare tagged and the regions in which those resources reside.\n\nWhen\ \ all tags have been removed, the state changes to DELETED. You cannot restore\ \ a deleted tag. After the tag state\nchanges to DELETED, you can use the\ \ same tag name again.\n\nAfter you start this operation, you cannot start\ \ either the [DeleteTag](#/en/identity/20160918/Tag/DeleteTag) or the [CascadeDeleteTagNamespace](#/en/identity/20160918/TagNamespace/CascadeDeleteTagNamespace)\ \ operation until this process completes.\n\nIn order to delete tags, you\ \ must first retire the tags. Use [UpdateTag](#/en/identity/20160918/Tag/UpdateTag)\n\ to retire a tag.\n" operationId: BulkDeleteTags parameters: - description: Request object for deleting tags in bulk. in: body name: BulkDeleteTagsDetails required: true schema: $ref: '#/definitions/BulkDeleteTagsDetails' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - $ref: '#/parameters/OverrideLocksQueryParam' responses: 202: description: The request was accepted for processing. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Delete multiple tag key definitions at the same time tags: - identity x-example: "POST /20160918/tags/actions/bulkDelete/\nHost: identity.us-phoenix-1.oraclecloud.com\n\ <authorization and other headers>\n{\n \"tagDefinitionIds\"\ : [\n \"ocid1.tagdefinition.oc1..<unique_ID_1>\",\n \ \ \"ocid1.tagdefinition.oc1..<unique_ID_2>\",\n \"ocid1.tagdefinition.oc1..<unique_ID_3>\"\ \n ]\n}\n" x-obmcs-get-work-request-operation: GetTaggingWorkRequest x-related-resource: '#/definitions/Tag' /tags/actions/bulkEdit: post: description: "Edits the specified list of tag key definitions for the selected\ \ resources.\nThis operation triggers a process that edits the tags on all\ \ selected resources. The possible actions are:\n\n * Add a defined tag when\ \ the tag does not already exist on the resource.\n * Update the value for\ \ a defined tag when the tag is present on the resource.\n * Add a defined\ \ tag when it does not already exist on the resource or update the value for\ \ a defined tag when the tag is present on the resource.\n * Remove a defined\ \ tag from a resource. The tag is removed from the resource regardless of\ \ the tag value.\n\nSee [BulkEditOperationDetails](#/en/identity/latest/datatypes/BulkEditOperationDetails)\ \ for more information.\n\nThe edits can include a combination of operations\ \ and tag sets.\nHowever, multiple operations cannot apply to one key definition\ \ in the same request.\nFor example, if one request adds `tag set-1` to a\ \ resource and sets a tag value to `tag set-2`,\n`tag set-1` and `tag set-2`\ \ cannot have any common tag definitions.\n" operationId: BulkEditTags parameters: - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - description: The request object for bulk editing tags on resources in the compartment. in: body name: BulkEditTagsDetails required: true schema: $ref: '#/definitions/BulkEditTagsDetails' responses: 202: description: The request was accepted for processing. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Edit multiple tag key definitions on resources tags: - identity x-obmcs-get-work-request-operation: GetTaggingWorkRequest x-related-resource: '#/definitions/Tag' /tags/actions/importStandardTags: post: description: 'OCI will release Tag Namespaces that our customers can import. These Tag Namespaces will provide Tags for our customers and Partners to provide consistency and enable data reporting. ' operationId: ImportStandardTags parameters: - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' - description: The request object for creating or updating standard tag namespace. in: body name: ImportStandardTagsDetails required: true schema: $ref: '#/definitions/ImportStandardTagsDetails' responses: 202: description: The request was accepted for processing. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string opc-work-request-id: description: 'The [OCID](/Content/General/Concepts/identifiers.htm) of the work request. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: 'Create or update tag namespace and their tag definitions if a given tag namespace is a standard tag namespace. If the tag namespace already exists, any missing tag definitions will be added. For existing enum tags, any new enum values will be added. Deleting tagging entities nor removing enum values are not supported. ' tags: - identity x-obmcs-get-work-request-operation: GetTaggingWorkRequest x-related-resource: '#/definitions/Tag' /tags/bulkEditResourceTypes: get: description: 'Lists the resource types that support bulk tag editing. ' operationId: ListBulkEditTagsResourceTypes parameters: - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/BulkEditTagsResourceTypeCollection' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListBulkEditTagsResourceTypes tags: - identity /tags/standardTagNamespaceTemplates: get: description: 'Lists available standard tag namespaces that users can create. ' operationId: ListStandardTagNamespaces parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' responses: 200: description: A list of standard tag namespace templates. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/StandardTagNamespaceTemplateSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListStandardTagNamespaceTemplates tags: - identity /tags/standardTagNamespaceTemplates/{standardTagNamespaceName}: get: description: 'Retrieve the standard tag namespace template given the standard tag namespace name. ' operationId: GetStandardTagTemplate parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/StandardTagNamespaceNamePathParam' responses: 200: description: Requested standard tag namespace template has been retrieved. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/StandardTagNamespaceTemplate' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetStandardTagTemplate tags: - identity /tenancies/{tenancyId}: get: description: Get the specified tenancy's information. operationId: GetTenancy parameters: - $ref: '#/parameters/TenancyIdPathParam' responses: 200: description: The tenancy was retrieved. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Tenancy' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetTenancy tags: - identity /tenancies/{tenancyId}/regionSubscriptions: get: description: Lists the region subscriptions for the specified tenancy. operationId: ListRegionSubscriptions parameters: - $ref: '#/parameters/TenancyIdPathParam' responses: 200: description: The list has been retrieved. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/RegionSubscription' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListRegionSubscriptions tags: - identity post: description: 'Creates a subscription to a region for a tenancy. ' operationId: CreateRegionSubscription parameters: - description: Request object for activate a new region. in: body name: CreateRegionSubscriptionDetails required: true schema: $ref: '#/definitions/CreateRegionSubscriptionDetails' - $ref: '#/parameters/TenancyIdPathParam' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The Region Subscription has been created. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/RegionSubscription' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateRegionSubscription tags: - identity /userGroupMemberships/: get: description: 'Lists the `UserGroupMembership` objects in your tenancy. You must specify your tenancy''s OCID as the value for the compartment ID (see [Where to Get the Tenancy''s OCID and User''s OCID](/Content/API/Concepts/apisigningkey.htm#five)). You must also then filter the list in one of these ways: - You can limit the results to just the memberships for a given user by specifying a `userId`. - Similarly, you can limit the results to just the memberships for a given group by specifying a `groupId`. - You can set both the `userId` and `groupId` to determine if the specified user is in the specified group. If the answer is no, the response is an empty list. - Although`userId` and `groupId` are not individually required, you must set one of them. ' operationId: ListUserGroupMemberships parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/UserIdQueryParam' - $ref: '#/parameters/GroupIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' responses: 200: description: Page of `UserGroupMembership` objects matching the specified criteria. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/UserGroupMembership' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListUserGroupMemberships tags: - identity post: description: 'Adds the specified user to the specified group and returns a `UserGroupMembership` object with its own OCID. After you send your request, the new object''s `lifecycleState` will temporarily be CREATING. Before using the object, first make sure its `lifecycleState` has changed to ACTIVE. ' operationId: AddUserToGroup parameters: - description: Request object for adding a user to a group. in: body name: addUserToGroupDetails required: true schema: $ref: '#/definitions/AddUserToGroupDetails' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The user is being added to the group. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/UserGroupMembership' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: AddUserToGroup tags: - identity /userGroupMemberships/{userGroupMembershipId}: delete: description: Removes a user from a group by deleting the corresponding `UserGroupMembership`. operationId: RemoveUserFromGroup parameters: - $ref: '#/parameters/UserGroupMembershipIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The user is being removed from the group. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: RemoveUserFromGroup tags: - identity x-related-resource: '#/definitions/UserGroupMembership' get: description: Gets the specified UserGroupMembership's information. operationId: GetUserGroupMembership parameters: - $ref: '#/parameters/UserGroupMembershipIdPathParam' responses: 200: description: The membership was retrieved. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/UserGroupMembership' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetUserGroupMembership tags: - identity /users/: get: description: 'Lists the users in your tenancy. You must specify your tenancy''s OCID as the value for the compartment ID (remember that the tenancy is simply the root compartment). See [Where to Get the Tenancy''s OCID and User''s OCID](/Content/API/Concepts/apisigningkey.htm#five). ' operationId: ListUsers parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/IdentityProviderIdQueryParam' - $ref: '#/parameters/ExternalIdentifierQueryParam' - $ref: '#/parameters/FilterByNameQueryParam' - $ref: '#/parameters/SortByQueryParam' - $ref: '#/parameters/SortOrderQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/User/lifecycleState' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/User' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListUsers tags: - identity post: description: 'Creates a new user in your tenancy. For conceptual information about users, your tenancy, and other IAM Service components, see [Overview of IAM](/Content/Identity/getstarted/identity-domains.htm). You must specify your tenancy''s OCID as the compartment ID in the request object (remember that the tenancy is simply the root compartment). Notice that IAM resources (users, groups, compartments, and some policies) reside within the tenancy itself, unlike cloud resources such as compute instances, which typically reside within compartments inside the tenancy. For information about OCIDs, see [Resource Identifiers](/Content/General/Concepts/identifiers.htm). You must also specify a *name* for the user, which must be unique across all users in your tenancy and cannot be changed. Allowed characters: No spaces. Only letters, numerals, hyphens, periods, underscores, +, and @. If you specify a name that''s already in use, you''ll get a 409 error. This name will be the user''s login to the Console. You might want to pick a name that your company''s own identity system (e.g., Active Directory, LDAP, etc.) already uses. If you delete a user and then create a new user with the same name, they''ll be considered different users because they have different OCIDs. You must also specify a *description* for the user (although it can be an empty string). It does not have to be unique, and you can change it anytime with [UpdateUser](#/en/identity/20160918/User/UpdateUser). You can use the field to provide the user''s full name, a description, a nickname, or other information to generally identify the user. After you send your request, the new object''s `lifecycleState` will temporarily be CREATING. Before using the object, first make sure its `lifecycleState` has changed to ACTIVE. A new user has no permissions until you place the user in one or more groups (see [AddUserToGroup](#/en/identity/20160918/UserGroupMembership/AddUserToGroup)). If the user needs to access the Console, you need to provide the user a password (see [CreateOrResetUIPassword](#/en/identity/20160918/UIPassword/CreateOrResetUIPassword)). If the user needs to access the Oracle Cloud Infrastructure REST API, you need to upload a public API signing key for that user (see [Required Keys and OCIDs](/Content/API/Concepts/apisigningkey.htm) and also [UploadApiKey](#/en/identity/20160918/ApiKey/UploadApiKey)). **Important:** Make sure to inform the new user which compartment(s) they have access to. ' operationId: CreateUser parameters: - description: Request object for creating a new user. in: body name: createUserDetails required: true schema: $ref: '#/definitions/CreateUserDetails' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The user is being created. examples: application-json: "{\n \"id\" : \"ocid1.user.oc1..aaaaaaaaqvrabwexampleuniqueID\"\ ,\n \"compartmentId\" : \"ocid1.tenancy.oc1..aaaaaaaaba3pvexampleuniqueID\"\ ,\n \"name\" : \"JohnSmith@example.com\",\n \"description\" : \"John\ \ Smith\",\n \"lifecycleState\" : \"ACTIVE\",\n \"timeCreated\" :\ \ \"2016-11-18T18:13:12.210Z\"\n}\n" headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/User' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateUser tags: - identity x-example: "POST /20160918/users/\nHost: identity.us-phoenix-1.oraclecloud.com\n\ <authorization and other headers>\n{\n \"compartmentId\"\ \ : \"ocid1.tenancy.oc1..aaaaaaaaba3pv6exampleuniqueID\",\n \"description\"\ \ : \"John Smith\",\n \"name\" : \"JohnSmith@example.com\"\n}\n" /users/{userId}: delete: description: Deletes the specified user. The user must not be in any groups. operationId: DeleteUser parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The user is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteUser tags: - identity get: description: Gets the specified user's information. operationId: GetUser parameters: - $ref: '#/parameters/UserIdPathParam' responses: 200: description: The user was retrieved. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/User' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetUser tags: - identity put: description: Updates the description of the specified user. operationId: UpdateUser parameters: - $ref: '#/parameters/UserIdPathParam' - description: Request object for updating a user. in: body name: updateUserDetails required: true schema: $ref: '#/definitions/UpdateUserDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The user was updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/User' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateUser tags: - identity /users/{userId}/apiKeys/: get: description: 'Lists the API signing keys for the specified user. A user can have a maximum of three keys. Every user has permission to use this API call for *their own user ID*. An administrator in your organization does not need to write a policy to give users this ability. ' operationId: ListApiKeys parameters: - $ref: '#/parameters/UserIdPathParam' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/ApiKey' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListApiKeys tags: - identity post: description: 'Uploads an API signing key for the specified user. Every user has permission to use this operation to upload a key for *their own user ID*. An administrator in your organization does not need to write a policy to give users this ability. To compare, administrators who have permission to the tenancy can use this operation to upload a key for any user, including themselves. **Important:** Even though you have permission to upload an API key, you might not yet have permission to do much else. If you try calling an operation unrelated to your own credential management (e.g., `ListUsers`, `LaunchInstance`) and receive an "unauthorized" error, check with an administrator to confirm which IAM Service group(s) you''re in and what access you have. Also confirm you''re working in the correct compartment. After you send your request, the new object''s `lifecycleState` will temporarily be CREATING. Before using the object, first make sure its `lifecycleState` has changed to ACTIVE. ' operationId: UploadApiKey parameters: - $ref: '#/parameters/UserIdPathParam' - description: Request object for uploading an API key for a user. in: body name: createApiKeyDetails required: true schema: $ref: '#/definitions/CreateApiKeyDetails' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The key is being uploaded. examples: application-json: "{\n \"keyId\" : \"ocid1.tenancy.oc1..aaaaaaaaba3pv6exampleuniqueID/ocid1.user.oc1..aaaaaaaaqvexampleuniqueID/cd:7c:ee:29:8b:2f:c6:48:13:c9:9f:12:66:77:ef:c2\"\ ,\n \"keyValue\" : \"-----BEGIN PUBLIC KEY-----\\\\cmdnMIIBIjANBgkqhkiG9w0BAQEFA...AOCAQ8AMIIBCgKCAQEA7hglbuGudIO3sgoAa1n/\\\ nHgUdIGeQmwf//QIv3Y0nOEP4TB7rbdCH99oJYzF86M2\\nmwIDAQAB\\n-----END PUBLIC\ \ KEY-----\",\n \"fingerprint\" : \"cd:7c:ee:29:8b:2f:c6:48:13:c9:9f:12:66:77:ef:c2\"\ ,\n \"userId\" : \"ocid1.user.oc1..aaaaaaaaqvrexampleuniqueID\",\n\ \ \"lifecycleState\" : \"ACTIVE\",\n \"timeCreated\" : \"2016-12-07T00:59:17.326Z\"\ \n}\n" headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/ApiKey' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UploadApiKey tags: - identity x-example: "POST /20160918/users/<userId>/apiKeys/\nHost: identity.us-phoenix-1.oraclecloud.com\n\ <authorization and other headers>\n{\n \"key\" : \"-----BEGIN\ \ PUBLIC KEY-----\\cmdnMIIBIjANBgkqhkiG9w0BAQEFA...AOCAQ8AMIIBCgKCAQEA7hglbuGudIO3sgoAa1n/\\\ nHgUdIGeQmwf/QIv3Y0nOEP4TB7rbdCH99oJYzF86M2\\nmwIDAQAB\\n-----END PUBLIC KEY-----\"\ \n}\n" /users/{userId}/apiKeys/{fingerprint}: delete: description: 'Deletes the specified API signing key for the specified user. Every user has permission to use this operation to delete a key for *their own user ID*. An administrator in your organization does not need to write a policy to give users this ability. To compare, administrators who have permission to the tenancy can use this operation to delete a key for any user, including themselves. ' operationId: DeleteApiKey parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/KeyFingerprintPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The key is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteApiKey tags: - identity /users/{userId}/authTokens/: get: description: 'Lists the auth tokens for the specified user. The returned object contains the token''s OCID, but not the token itself. The actual token is returned only upon creation. ' operationId: ListAuthTokens parameters: - $ref: '#/parameters/UserIdPathParam' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/AuthToken' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListAuthTokens tags: - identity post: description: 'Creates a new auth token for the specified user. For information about what auth tokens are for, see [Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm). You must specify a *description* for the auth token (although it can be an empty string). It does not have to be unique, and you can change it anytime with [UpdateAuthToken](#/en/identity/20160918/AuthToken/UpdateAuthToken). Every user has permission to create an auth token for *their own user ID*. An administrator in your organization does not need to write a policy to give users this ability. To compare, administrators who have permission to the tenancy can use this operation to create an auth token for any user, including themselves. ' operationId: CreateAuthToken parameters: - description: Request object for creating a new auth token. in: body name: createAuthTokenDetails required: true schema: $ref: '#/definitions/CreateAuthTokenDetails' - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The new auth token is being created. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/AuthToken' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateAuthToken tags: - identity /users/{userId}/authTokens/{authTokenId}: delete: description: 'Deletes the specified auth token for the specified user. ' operationId: DeleteAuthToken parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/AuthTokenIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The auth token is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteAuthToken tags: - identity put: description: 'Updates the specified auth token''s description. ' operationId: UpdateAuthToken parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/AuthTokenIdPathParam' - description: Request object for updating an auth token. in: body name: updateAuthTokenDetails required: true schema: $ref: '#/definitions/UpdateAuthTokenDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The auth token object was updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/AuthToken' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateAuthToken tags: - identity /users/{userId}/capabilities/: put: description: 'Updates the capabilities of the specified user. ' operationId: UpdateUserCapabilities parameters: - $ref: '#/parameters/UserIdPathParam' - description: Request object for updating user capabilities. in: body name: UpdateUserCapabilitiesDetails required: true schema: $ref: '#/definitions/UpdateUserCapabilitiesDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The user's capability was updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/User' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateUserCapabilities tags: - identity /users/{userId}/customerSecretKeys/: get: description: 'Lists the secret keys for the specified user. The returned object contains the secret key''s OCID, but not the secret key itself. The actual secret key is returned only upon creation. ' operationId: ListCustomerSecretKeys parameters: - $ref: '#/parameters/UserIdPathParam' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/CustomerSecretKeySummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListCustomerSecretKeys tags: - identity post: description: 'Creates a new secret key for the specified user. Secret keys are used for authentication with the Object Storage Service''s Amazon S3 compatible API. The secret key consists of an Access Key/Secret Key pair. For information, see [Managing User Credentials](/Content/Identity/access/managing-user-credentials.htm). You must specify a *description* for the secret key (although it can be an empty string). It does not have to be unique, and you can change it anytime with [UpdateCustomerSecretKey](#/en/identity/20160918/CustomerSecretKeySummary/UpdateCustomerSecretKey). Every user has permission to create a secret key for *their own user ID*. An administrator in your organization does not need to write a policy to give users this ability. To compare, administrators who have permission to the tenancy can use this operation to create a secret key for any user, including themselves. ' operationId: CreateCustomerSecretKey parameters: - description: Request object for creating a new secret key. in: body name: createCustomerSecretKeyDetails required: true schema: $ref: '#/definitions/CreateCustomerSecretKeyDetails' - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The new secret key is being created. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/CustomerSecretKey' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateCustomerSecretKey tags: - identity /users/{userId}/customerSecretKeys/{customerSecretKeyId}: delete: description: 'Deletes the specified secret key for the specified user. ' operationId: DeleteCustomerSecretKey parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/CustomerSecretKeyIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The secret key is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteCustomerSecretKey tags: - identity put: description: 'Updates the specified secret key''s description. ' operationId: UpdateCustomerSecretKey parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/CustomerSecretKeyIdPathParam' - description: Request object for updating a secret key. in: body name: updateCustomerSecretKeyDetails required: true schema: $ref: '#/definitions/UpdateCustomerSecretKeyDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: Summary for the secret key that was updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/CustomerSecretKeySummary' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateCustomerSecretKey tags: - identity /users/{userId}/dbCredentials/: get: description: 'Lists the DB credentials for the specified user. The returned object contains the credential''s OCID ' operationId: ListDbCredentials parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/FilterByNameQueryParam' - $ref: '#/parameters/SortByQueryParam' - $ref: '#/parameters/SortOrderQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/DbCredential/lifecycleState' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/DbCredentialSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListDbCredentials tags: - identity x-related-resource: '#/definitions/User' post: description: 'Creates a new DB credential for the specified user. ' operationId: CreateDbCredential parameters: - description: Request object for creating a new DB credential with the user. in: body name: CreateDbCredentialDetails required: true schema: $ref: '#/definitions/CreateDbCredentialDetails' - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The new DB credential is being created. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/DbCredential' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateDbCredential tags: - identity x-example: "POST /20160918/users/ocid1.user.dev..aaaaaaaaghj3exampleuniqueID/dbCredentials/\n\ Host: identity.us-phoenix-1.oraclecloud.com\n<authorization and other\ \ headers>\n{\n 'description': 'DB credential'\n 'password': 'Pas$$1234word'\n\ }\n" x-related-resource: '#/definitions/User' /users/{userId}/dbCredentials/{dbCredentialId}: delete: description: 'Deletes the specified DB credential for the specified user. ' operationId: DeleteDbCredential parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/DbCredentialIdPathParam' - $ref: '#/parameters/RequestIdHeader' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The Db credential is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteDbCredential tags: - identity x-related-resource: '#/definitions/User' /users/{userId}/mfaTotpDevices: get: description: 'Lists the MFA TOTP devices for the specified user. The returned object contains the device''s OCID, but not the seed. The seed is returned only upon creation or when the IAM service regenerates the MFA seed for the device. ' operationId: ListMfaTotpDevices parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/SortByQueryParam' - $ref: '#/parameters/SortOrderQueryParam' responses: 200: description: The list of MFA TOTP devices. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/MfaTotpDeviceSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListMfaTotpDevices tags: - identity post: description: 'Creates a new MFA TOTP device for the user. A user can have one MFA TOTP device. ' operationId: CreateMfaTotpDevice parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The new MFA TOTP device has been created. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/MfaTotpDevice' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateMfaTotpDevice tags: - identity /users/{userId}/mfaTotpDevices/{mfaTotpDeviceId}: delete: description: 'Deletes the specified MFA TOTP device for the specified user. ' operationId: DeleteMfaTotpDevice parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/MfaTotpDeviceIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The MFA TOTP device is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteMfaTotpDevice tags: - identity x-related-resource: '#/definitions/MfaTotpDevice' get: description: 'Get the specified MFA TOTP device for the specified user. ' operationId: GetMfaTotpDevice parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/MfaTotpDeviceIdPathParam' responses: 200: description: The MFA TOTP device. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/MfaTotpDeviceSummary' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetMfaTotpDevice tags: - identity /users/{userId}/mfaTotpDevices/{mfaTotpDeviceId}/actions/activate: post: description: 'Activates the specified MFA TOTP device for the user. Activation requires manual interaction with the Console. ' operationId: ActivateMfaTotpDevice parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/MfaTotpDeviceIdPathParam' - description: MFA TOTP token in: body name: MfaTotpToken required: true schema: $ref: '#/definitions/MfaTotpToken' - $ref: '#/parameters/IfMatchHeader' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: Summary for the MFA TOTP device that was activated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/MfaTotpDeviceSummary' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ActivateMfaTotpDevice tags: - identity /users/{userId}/mfaTotpDevices/{mfaTotpDeviceId}/actions/generateSeed: post: description: 'Generate seed for the MFA TOTP device. ' operationId: GenerateTotpSeed parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/MfaTotpDeviceIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: Details for the MFA TOTP device that was activated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/MfaTotpDevice' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GenerateTotpSeed tags: - identity /users/{userId}/oauth2ClientCredentials: get: description: 'List of Oauth tokens for the user ' operationId: ListOAuthClientCredentials parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - description: 'A filter to only return resources that match the given lifecycle state. The state value is case-insensitive. ' in: query name: lifecycleState required: false type: string x-obmcs-enumref: '#/definitions/OAuth2ClientCredentialSummary/lifecycleState' responses: 200: description: The list of Oauth tokens. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/OAuth2ClientCredentialSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: List of Oauth tokens for the user tags: - identity x-related-resource: '#/definitions/User' post: description: 'Creates Oauth token for the user ' operationId: CreateOAuthClientCredential parameters: - $ref: '#/parameters/UserIdPathParam' - description: Request object containing the information required to generate an Oauth token. in: body name: CreateOAuth2ClientCredentialDetails required: true schema: $ref: '#/definitions/CreateOAuth2ClientCredentialDetails' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The new Oauth token created. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/OAuth2ClientCredential' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Creates Oauth token for the user tags: - identity x-related-resource: '#/definitions/User' /users/{userId}/oauth2ClientCredentials/{oauth2ClientCredentialId}: delete: description: 'Delete Oauth token for the user ' operationId: DeleteOAuthClientCredential parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/Oauth2ClientCredentialIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The Oauth token is deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 412: $ref: '#/responses/412' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Delete Oauth token for the user tags: - identity x-related-resource: '#/definitions/User' put: description: 'Updates Oauth token for the user ' operationId: UpdateOAuthClientCredential parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/Oauth2ClientCredentialIdPathParam' - $ref: '#/parameters/IfMatchHeader' - description: Request object containing the information required to generate an Oauth token. in: body name: UpdateOAuth2ClientCredentialDetails required: true schema: $ref: '#/definitions/UpdateOAuth2ClientCredentialDetails' responses: 200: description: The Oauth token is updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/OAuth2ClientCredential' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: Updates Oauth token for the user tags: - identity x-related-resource: '#/definitions/User' /users/{userId}/smtpCredentials/: get: description: 'Lists the SMTP credentials for the specified user. The returned object contains the credential''s OCID, the SMTP user name but not the SMTP password. The SMTP password is returned only upon creation. ' operationId: ListSmtpCredentials parameters: - $ref: '#/parameters/UserIdPathParam' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/SmtpCredentialSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListSmtpCredentials tags: - identity post: description: 'Creates a new SMTP credential for the specified user. An SMTP credential has an SMTP user name and an SMTP password. You must specify a *description* for the SMTP credential (although it can be an empty string). It does not have to be unique, and you can change it anytime with [UpdateSmtpCredential](#/en/identity/20160918/SmtpCredentialSummary/UpdateSmtpCredential). ' operationId: CreateSmtpCredential parameters: - description: Request object for creating a new SMTP credential with the user. in: body name: createSmtpCredentialDetails required: true schema: $ref: '#/definitions/CreateSmtpCredentialDetails' - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The new SMTP credential is being created. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/SmtpCredential' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateSmtpCredential tags: - identity /users/{userId}/smtpCredentials/{smtpCredentialId}: delete: description: 'Deletes the specified SMTP credential for the specified user. ' operationId: DeleteSmtpCredential parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/SmtpCredentialIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The Smtp credential is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteSmtpCredential tags: - identity put: description: 'Updates the specified SMTP credential''s description. ' operationId: UpdateSmtpCredential parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/SmtpCredentialIdPathParam' - description: Request object for updating a SMTP credential. in: body name: updateSmtpCredentialDetails required: true schema: $ref: '#/definitions/UpdateSmtpCredentialDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The SMTP credential object was updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/SmtpCredentialSummary' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateSmtpCredential tags: - identity /users/{userId}/state/: put: description: 'Updates the state of the specified user. ' operationId: UpdateUserState parameters: - $ref: '#/parameters/UserIdPathParam' - description: Request object for updating a user state. in: body name: updateStateDetails required: true schema: $ref: '#/definitions/UpdateStateDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The user state was updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/User' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateUserState tags: - identity /users/{userId}/swiftPasswords/: get: description: '**Deprecated. Use [ListAuthTokens](#/en/identity/20160918/AuthToken/ListAuthTokens) instead.** Lists the Swift passwords for the specified user. The returned object contains the password''s OCID, but not the password itself. The actual password is returned only upon creation. ' operationId: ListSwiftPasswords parameters: - $ref: '#/parameters/UserIdPathParam' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/SwiftPassword' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListSwiftPasswords tags: - identity post: description: '**Deprecated. Use [CreateAuthToken](#/en/identity/20160918/AuthToken/CreateAuthToken) instead.** Creates a new Swift password for the specified user. For information about what Swift passwords are for, see [Managing User Credentials](/Content/Identity/Tasks/managingcredentials.htm). You must specify a *description* for the Swift password (although it can be an empty string). It does not have to be unique, and you can change it anytime with [UpdateSwiftPassword](#/en/identity/20160918/SwiftPassword/UpdateSwiftPassword). Every user has permission to create a Swift password for *their own user ID*. An administrator in your organization does not need to write a policy to give users this ability. To compare, administrators who have permission to the tenancy can use this operation to create a Swift password for any user, including themselves. ' operationId: CreateSwiftPassword parameters: - description: Request object for creating a new swift password. in: body name: createSwiftPasswordDetails required: true schema: $ref: '#/definitions/CreateSwiftPasswordDetails' - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The new Swift password is being created. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/SwiftPassword' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateSwiftPassword tags: - identity /users/{userId}/swiftPasswords/{swiftPasswordId}: delete: description: '**Deprecated. Use [DeleteAuthToken](#/en/identity/20160918/AuthToken/DeleteAuthToken) instead.** Deletes the specified Swift password for the specified user. ' operationId: DeleteSwiftPassword parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/SwiftPasswordIdPathParam' - $ref: '#/parameters/IfMatchHeader' responses: 204: description: The Swift password is being deleted. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: DeleteSwiftPassword tags: - identity put: description: '**Deprecated. Use [UpdateAuthToken](#/en/identity/20160918/AuthToken/UpdateAuthToken) instead.** Updates the specified Swift password''s description. ' operationId: UpdateSwiftPassword parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/SwiftPasswordIdPathParam' - description: Request object for updating a Swift password. in: body name: updateSwiftPasswordDetails required: true schema: $ref: '#/definitions/UpdateSwiftPasswordDetails' - $ref: '#/parameters/IfMatchHeader' responses: 200: description: The Swift password object was updated. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/SwiftPassword' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 412: $ref: '#/responses/412' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: UpdateSwiftPassword tags: - identity /users/{userId}/uiPassword: get: description: 'Gets the specified user''s console password information. The returned object contains the user''s OCID, but not the password itself. The actual password is returned only when created or reset. ' operationId: GetUserUIPasswordInformation parameters: - $ref: '#/parameters/UserIdPathParam' responses: 200: description: The user UI password information was retrieved. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/UIPasswordInformation' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetUserUIPasswordInformation tags: - identity post: description: 'Creates a new Console one-time password for the specified user. For more information about user credentials, see [User Credentials](/Content/Identity/usercred/usercredentials.htm). Use this operation after creating a new user, or if a user forgets their password. The new one-time password is returned to you in the response, and you must securely deliver it to the user. They''ll be prompted to change this password the next time they sign in to the Console. If they don''t change it within 7 days, the password will expire and you''ll need to create a new one-time password for the user. (For tenancies that support identity domains) Resetting a user''s password generates a reset password email with a link that the user must follow to reset their password. If the user does not reset their password before the link expires, you''ll need to reset the user''s password again. **Note:** The user''s Console login is the unique name you specified when you created the user (see [CreateUser](#/en/identity/20160918/User/CreateUser)). ' operationId: CreateOrResetUIPassword parameters: - $ref: '#/parameters/UserIdPathParam' - $ref: '#/parameters/RetryTokenHeader' responses: 200: description: The new UI password is being created. headers: etag: description: For optimistic concurrency control. See `if-match`. type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/UIPassword' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 403: $ref: '#/responses/403' 404: $ref: '#/responses/404' 409: $ref: '#/responses/409' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: CreateOrResetUIPassword tags: - identity /workRequests/: get: description: 'Lists the work requests in compartment. ' operationId: ListWorkRequests parameters: - $ref: '#/parameters/CompartmentIdQueryParam' - $ref: '#/parameters/PaginationTokenQueryParam' - $ref: '#/parameters/PaginationLimitQueryParam' - $ref: '#/parameters/ResourceIdentifierQueryParam' responses: 200: description: The list is being retrieved. headers: opc-next-page: description: 'For pagination of a list of items. When paging through a list, if this header appears in the response, then a partial list might have been returned. Include this value as the `page` parameter for the subsequent GET request to get the next batch of items. ' type: string opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: items: $ref: '#/definitions/WorkRequestSummary' type: array 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: ListWorkRequests tags: - identity /workRequests/{workRequestId}: get: description: 'Gets details on a specified work request. The workRequestID is returned in the opc-work-request-id header for any asynchronous operation in the compartment service. ' operationId: GetWorkRequest parameters: - $ref: '#/parameters/WorkRequestIdPathParam' responses: 200: description: The work request was retrieved. headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string retry-after: description: 'The number of seconds that the client should wait before polling again. ' format: float type: number schema: $ref: '#/definitions/WorkRequest' 400: $ref: '#/responses/400' 401: $ref: '#/responses/401' 404: $ref: '#/responses/404' 429: $ref: '#/responses/429' 500: $ref: '#/responses/500' default: $ref: '#/responses/DefaultError' summary: GetWorkRequest tags: - identity produces: - application/json responses: DefaultError: description: 'An error has occurred. ' headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Error' 400: description: Bad Request headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Error' 401: description: Unauthorized headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Error' 403: description: Forbidden headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Error' 404: description: Not Found headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Error' 409: description: Conflict headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Error' 412: description: Precondition Failed headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Error' 429: description: Too Many Requests headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Error' 500: description: Internal Server Error headers: opc-request-id: description: 'Unique Oracle-assigned identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. ' type: string schema: $ref: '#/definitions/Error' schemes: - http swagger: '2.0' x-obmcs-client-circuit-breaker-enabled: true x-obmcs-client-retries-enabled: true x-oracle-package: com.oracle.pic.identity