View a markdown version of this page

DescribeIdentityStore - Identity Store

DescribeIdentityStore

Retrieves details about the specified identity store, including its Amazon Resource Name (ARN) and network configuration.

Request Syntax

{ "IdentityStoreId": "string" }

Request Parameters

For information about the parameters that are common to all actions, see Common Parameters.

The request accepts the following data in JSON format.

IdentityStoreId

The globally unique identifier for the identity store.

You can specify the identity store by ID or by Amazon Resource Name (ARN). For example, identity store ID d-1234567890 or identity store ARN arn:aws:identitystore::111122223333:identitystore/d-1234567890.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 93.

Pattern: (arn:aws[a-z-]*:identitystore::\d{12}:identitystore/)?(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})

Required: Yes

Response Syntax

{ "IdentityStoreArn": "string", "IdentityStoreId": "string", "NetworkConfiguration": { "ApiAllowSourceIps": [ "string" ], "ApiRestrictSourceVpcs": [ "string" ], "ScimAllowSourceIps": [ "string" ], "VpceAccessRequired": boolean } }

Response Elements

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.

IdentityStoreArn

The Amazon Resource Name (ARN) of the identity store. For example, arn:aws:identitystore::111122223333:identitystore/d-1234567890.

Type: String

Length Constraints: Minimum length of 62. Maximum length of 93.

Pattern: arn:aws[a-z-]*:identitystore::\d{12}:identitystore/(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})

IdentityStoreId

The globally unique identifier for the identity store.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 93.

Pattern: (arn:aws[a-z-]*:identitystore::\d{12}:identitystore/)?(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})

NetworkConfiguration

The network configuration of the identity store. This configuration controls whether access through a virtual private cloud (VPC) endpoint is required, and which source VPCs and IP addresses are allowed.

Type: NetworkConfigurationDetails object

Errors

For information about the errors that are common to all actions, see Common Error Types.

AccessDeniedException

You do not have sufficient access to perform this action.

Reason

Indicates the reason for an access denial when returned by KMS while accessing a Customer Managed KMS key. For non-KMS access-denied errors, this field is not included.

RequestId

The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.

HTTP Status Code: 400

InternalServerException

The request processing has failed because of an unknown error, exception or failure with an internal server.

RequestId

The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.

RetryAfterSeconds

The number of seconds to wait before retrying the next request.

HTTP Status Code: 500

ResourceNotFoundException

Indicates that a requested resource is not found.

Reason

Indicates the reason for a resource not found error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.

RequestId

The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.

ResourceId

The identifier for a resource in the identity store that can be used as UserId or GroupId. The format for ResourceId is either UUID or 1234567890-UUID, where UUID is a randomly generated value for each resource when it is created and 1234567890 represents the IdentityStoreId string value. In the case that the identity store is migrated from a legacy SSO identity store, the ResourceId for that identity store will be in the format of UUID. Otherwise, it will be in the 1234567890-UUID format.

ResourceType

An enum object indicating the type of resource in the identity store service. Valid values include USER, GROUP, GROUP_MEMBERSHIP, RESOURCE_POLICY, and IDENTITY_STORE.

HTTP Status Code: 400

ThrottlingException

Indicates that the principal has crossed the throttling limits of the API operations.

Reason

Indicates the reason for the throttling error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.

RequestId

The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.

RetryAfterSeconds

The number of seconds to wait before retrying the next request.

HTTP Status Code: 400

ValidationException

The request failed because it contains a syntax error.

Reason

Indicates the reason for the validation error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.

RequestId

The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.

HTTP Status Code: 400

Examples

Example 1

This example describes an identity store specified by its ID.

Sample Request

{ "IdentityStoreId": "d-1234567890" }

Sample Response

{ "IdentityStoreId": "d-1234567890", "IdentityStoreArn": "arn:aws:identitystore::111122223333:identitystore/d-1234567890", "NetworkConfiguration": { "VpceAccessRequired": true, "ApiRestrictSourceVpcs": ["vpc-0a1b2c3d4e5f67890"], "ApiAllowSourceIps": ["203.0.113.0/24"], "ScimAllowSourceIps": ["203.0.113.0/24"] } }

Example 2

This example describes the same identity store specified by its Amazon Resource Name (ARN) instead of its ID.

Sample Request

{ "IdentityStoreId": "arn:aws:identitystore::111122223333:identitystore/d-1234567890" }

Sample Response

{ "IdentityStoreId": "d-1234567890", "IdentityStoreArn": "arn:aws:identitystore::111122223333:identitystore/d-1234567890", "NetworkConfiguration": { "VpceAccessRequired": true, "ApiRestrictSourceVpcs": ["vpc-0a1b2c3d4e5f67890"], "ApiAllowSourceIps": ["203.0.113.0/24"], "ScimAllowSourceIps": ["203.0.113.0/24"] } }

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: