IdentityStore / Client / describe_identity_store
describe_identity_store¶
- IdentityStore.Client.describe_identity_store(**kwargs)¶
Retrieves details about the specified identity store, including its Amazon Resource Name (ARN) and network configuration.
See also: AWS API Documentation
Request Syntax
response = client.describe_identity_store( IdentityStoreId='string' )
- Parameters:
IdentityStoreId (string) –
[REQUIRED]
The globally unique identifier for the identity store.
You can specify the identity store by ID or by Amazon Resource Name (ARN). For example, identity store ID
d-1234567890or identity store ARNarn:aws:identitystore::111122223333:identitystore/d-1234567890.- Return type:
dict
- Returns:
Response Syntax
{ 'IdentityStoreId': 'string', 'IdentityStoreArn': 'string', 'NetworkConfiguration': { 'VpceAccessRequired': True|False, 'ApiRestrictSourceVpcs': [ 'string', ], 'ApiAllowSourceIps': [ 'string', ], 'ScimAllowSourceIps': [ 'string', ] } }
Response Structure
(dict) –
IdentityStoreId (string) –
The globally unique identifier for the identity store.
IdentityStoreArn (string) –
The Amazon Resource Name (ARN) of the identity store. For example,
arn:aws:identitystore::111122223333:identitystore/d-1234567890.NetworkConfiguration (dict) –
The network configuration of the identity store. This configuration controls whether access through a virtual private cloud (VPC) endpoint is required, and which source VPCs and IP addresses are allowed.
VpceAccessRequired (boolean) –
Specifies whether the identity store can be accessed only through a virtual private cloud (VPC) endpoint. When set to
true, requests must originate from a VPC endpoint.ApiRestrictSourceVpcs (list) –
A list of virtual private cloud (VPC) IDs that are allowed to access the identity store API operations. A request is denied unless it originates from a VPC in this list, or from an IP address in
ApiAllowSourceIpsif one is configured. If this field is empty, access isn’t restricted to specific VPCs, but the VPC endpoint requirement fromVpceAccessRequiredstill applies.(string) –
ApiAllowSourceIps (list) –
A list of IP address CIDR ranges that are allowed to access the identity store API operations. A request from an IP address in this list bypasses the identity store’s other API network controls: it’s permitted even if it doesn’t come through a VPC endpoint required by
VpceAccessRequired, and even if it doesn’t originate from a VPC inApiRestrictSourceVpcs. If this field is empty, no such IP address exception applies.(string) –
ScimAllowSourceIps (list) –
A list of IP address CIDR ranges that are allowed to access the identity store through the System for Cross-domain Identity Management (SCIM) protocol. Requests from IP addresses outside these ranges are denied. If this field is empty, SCIM requests remain subject to the identity store’s other network controls, such as the VPC endpoint requirement.
(string) –
Exceptions
IdentityStore.Client.exceptions.ResourceNotFoundExceptionIdentityStore.Client.exceptions.ThrottlingExceptionIdentityStore.Client.exceptions.AccessDeniedExceptionIdentityStore.Client.exceptions.InternalServerExceptionIdentityStore.Client.exceptions.ValidationException