DescribeIdentityStore
Retrieves details about the specified identity store, including its Amazon Resource Name (ARN) and network configuration.
Request Syntax
{
"IdentityStoreId": "string"
}
Request Parameters
For information about the parameters that are common to all actions, see Common Parameters.
The request accepts the following data in JSON format.
- IdentityStoreId
-
The globally unique identifier for the identity store.
You can specify the identity store by ID or by Amazon Resource Name (ARN). For example, identity store ID
d-1234567890or identity store ARNarn:aws:identitystore::111122223333:identitystore/d-1234567890.Type: String
Length Constraints: Minimum length of 1. Maximum length of 93.
Pattern:
(arn:aws[a-z-]*:identitystore::\d{12}:identitystore/)?(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})Required: Yes
Response Syntax
{
"IdentityStoreArn": "string",
"IdentityStoreId": "string",
"NetworkConfiguration": {
"ApiAllowSourceIps": [ "string" ],
"ApiRestrictSourceVpcs": [ "string" ],
"ScimAllowSourceIps": [ "string" ],
"VpceAccessRequired": boolean
}
}
Response Elements
If the action is successful, the service sends back an HTTP 200 response.
The following data is returned in JSON format by the service.
- IdentityStoreArn
-
The Amazon Resource Name (ARN) of the identity store. For example,
arn:aws:identitystore::111122223333:identitystore/d-1234567890.Type: String
Length Constraints: Minimum length of 62. Maximum length of 93.
Pattern:
arn:aws[a-z-]*:identitystore::\d{12}:identitystore/(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}) - IdentityStoreId
-
The globally unique identifier for the identity store.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 93.
Pattern:
(arn:aws[a-z-]*:identitystore::\d{12}:identitystore/)?(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}) - NetworkConfiguration
-
The network configuration of the identity store. This configuration controls whether access through a virtual private cloud (VPC) endpoint is required, and which source VPCs and IP addresses are allowed.
Type: NetworkConfigurationDetails object
Errors
For information about the errors that are common to all actions, see Common Error Types.
- AccessDeniedException
-
You do not have sufficient access to perform this action.
- Reason
-
Indicates the reason for an access denial when returned by KMS while accessing a Customer Managed KMS key. For non-KMS access-denied errors, this field is not included.
- RequestId
-
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
HTTP Status Code: 400
- InternalServerException
-
The request processing has failed because of an unknown error, exception or failure with an internal server.
- RequestId
-
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
- RetryAfterSeconds
-
The number of seconds to wait before retrying the next request.
HTTP Status Code: 500
- ResourceNotFoundException
-
Indicates that a requested resource is not found.
- Reason
-
Indicates the reason for a resource not found error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.
- RequestId
-
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
- ResourceId
-
The identifier for a resource in the identity store that can be used as
UserIdorGroupId. The format forResourceIdis eitherUUIDor1234567890-UUID, whereUUIDis a randomly generated value for each resource when it is created and1234567890represents theIdentityStoreIdstring value. In the case that the identity store is migrated from a legacy SSO identity store, theResourceIdfor that identity store will be in the format ofUUID. Otherwise, it will be in the1234567890-UUIDformat. - ResourceType
-
An enum object indicating the type of resource in the identity store service. Valid values include USER, GROUP, GROUP_MEMBERSHIP, RESOURCE_POLICY, and IDENTITY_STORE.
HTTP Status Code: 400
- ThrottlingException
-
Indicates that the principal has crossed the throttling limits of the API operations.
- Reason
-
Indicates the reason for the throttling error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.
- RequestId
-
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
- RetryAfterSeconds
-
The number of seconds to wait before retrying the next request.
HTTP Status Code: 400
- ValidationException
-
The request failed because it contains a syntax error.
- Reason
-
Indicates the reason for the validation error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.
- RequestId
-
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
HTTP Status Code: 400
Examples
Example 1
This example describes an identity store specified by its ID.
Sample Request
{
"IdentityStoreId": "d-1234567890"
}
Sample Response
{
"IdentityStoreId": "d-1234567890",
"IdentityStoreArn": "arn:aws:identitystore::111122223333:identitystore/d-1234567890",
"NetworkConfiguration": {
"VpceAccessRequired": true,
"ApiRestrictSourceVpcs": ["vpc-0a1b2c3d4e5f67890"],
"ApiAllowSourceIps": ["203.0.113.0/24"],
"ScimAllowSourceIps": ["203.0.113.0/24"]
}
}
Example 2
This example describes the same identity store specified by its Amazon Resource Name (ARN) instead of its ID.
Sample Request
{
"IdentityStoreId": "arn:aws:identitystore::111122223333:identitystore/d-1234567890"
}
Sample Response
{
"IdentityStoreId": "d-1234567890",
"IdentityStoreArn": "arn:aws:identitystore::111122223333:identitystore/d-1234567890",
"NetworkConfiguration": {
"VpceAccessRequired": true,
"ApiRestrictSourceVpcs": ["vpc-0a1b2c3d4e5f67890"],
"ApiAllowSourceIps": ["203.0.113.0/24"],
"ScimAllowSourceIps": ["203.0.113.0/24"]
}
}
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: