UpdateUser
Updates the specified user metadata and attributes in the specified identity store.
Request Syntax
{
"IdentityStoreId": "string",
"Operations": [
{
"AttributePath": "string",
"AttributeValue": JSON value
}
],
"Revision": "string",
"UserId": "string"
}
Request Parameters
For information about the parameters that are common to all actions, see Common Parameters.
The request accepts the following data in JSON format.
- IdentityStoreId
-
The globally unique identifier for the identity store.
You can specify the identity store by ID or by Amazon Resource Name (ARN). For example, identity store ID
d-1234567890or identity store ARNarn:aws:identitystore::111122223333:identitystore/d-1234567890.Type: String
Length Constraints: Minimum length of 1. Maximum length of 93.
Pattern:
(arn:aws[a-z-]*:identitystore::\d{12}:identitystore/)?(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})Required: Yes
- Operations
-
A list of
AttributeOperationobjects to apply to the requested user. These operations might add, replace, or remove an attribute. For more information on the attributes that can be added, replaced, or removed, see User.Type: Array of AttributeOperation objects
Array Members: Minimum number of 1 item. Maximum number of 100 items.
Required: Yes
- Revision
-
The expected current revision of the user. When you provide this value, the update is applied only if it matches the current revision of the user in the identity store, which prevents you from overwriting concurrent changes. If the value doesn't match, the operation fails with a
ConflictException. If you don't provide this value, the update is applied unconditionally.Type: String
Length Constraints: Minimum length of 1. Maximum length of 64.
Pattern:
[0-9]+Required: No
- UserId
-
The identifier for a user in the identity store.
You can specify the user by ID or by Amazon Resource Name (ARN). For example, user ID
a1b2c3d4-5678-90ab-cdef-EXAMPLE11111or user ARNarn:aws:identitystore:::user/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111.Type: String
Length Constraints: Minimum length of 1. Maximum length of 100.
Pattern:
(arn:aws[a-z-]*:identitystore:::(user|group|membership)/)?([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}Required: Yes
Response Syntax
{
"IdentityStoreId": "string",
"Revision": "string",
"UserArn": "string",
"UserId": "string"
}
Response Elements
If the action is successful, the service sends back an HTTP 200 response.
The following data is returned in JSON format by the service.
- IdentityStoreId
-
The globally unique identifier for the identity store.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 93.
Pattern:
(arn:aws[a-z-]*:identitystore::\d{12}:identitystore/)?(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}) - Revision
-
The revision of the user after the requested update is applied.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 64.
Pattern:
[0-9]+ - UserArn
-
The Amazon Resource Name (ARN) of the user in the identity store. For example,
arn:aws:identitystore:::user/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111.Type: String
Length Constraints: Minimum length of 60. Maximum length of 100.
Pattern:
arn:aws[a-z-]*:identitystore:::(user|group|membership)/([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12} - UserId
-
The identifier for a user in the identity store.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 100.
Pattern:
(arn:aws[a-z-]*:identitystore:::(user|group|membership)/)?([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}
Errors
For information about the errors that are common to all actions, see Common Error Types.
- AccessDeniedException
-
You do not have sufficient access to perform this action.
- Reason
-
Indicates the reason for an access denial when returned by KMS while accessing a Customer Managed KMS key. For non-KMS access-denied errors, this field is not included.
- RequestId
-
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
HTTP Status Code: 400
- ConflictException
-
This request cannot be completed for one of the following reasons:
-
Performing the requested operation would violate an existing uniqueness claim in the identity store. Resolve the conflict before retrying this request.
-
The requested resource was being concurrently modified by another request.
- Reason
-
Indicates the reason for the conflict error.
UNIQUENESS_CONSTRAINT_VIOLATIONindicates that the request would violate an existing uniqueness constraint, such as a user name or other unique attribute that is already in use.CONCURRENT_MODIFICATIONindicates that the resource was modified by another request during this operation. - RequestId
-
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
HTTP Status Code: 400
-
- InternalServerException
-
The request processing has failed because of an unknown error, exception or failure with an internal server.
- RequestId
-
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
- RetryAfterSeconds
-
The number of seconds to wait before retrying the next request.
HTTP Status Code: 500
- ResourceNotFoundException
-
Indicates that a requested resource is not found.
- Reason
-
Indicates the reason for a resource not found error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.
- RequestId
-
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
- ResourceId
-
The identifier for a resource in the identity store that can be used as
UserIdorGroupId. The format forResourceIdis eitherUUIDor1234567890-UUID, whereUUIDis a randomly generated value for each resource when it is created and1234567890represents theIdentityStoreIdstring value. In the case that the identity store is migrated from a legacy SSO identity store, theResourceIdfor that identity store will be in the format ofUUID. Otherwise, it will be in the1234567890-UUIDformat. - ResourceType
-
An enum object indicating the type of resource in the identity store service. Valid values include USER, GROUP, GROUP_MEMBERSHIP, RESOURCE_POLICY, and IDENTITY_STORE.
HTTP Status Code: 400
- ServiceQuotaExceededException
-
The request would cause the number of users or groups in the identity store to exceed the maximum allowed.
- RequestId
-
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
HTTP Status Code: 400
- ThrottlingException
-
Indicates that the principal has crossed the throttling limits of the API operations.
- Reason
-
Indicates the reason for the throttling error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.
- RequestId
-
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
- RetryAfterSeconds
-
The number of seconds to wait before retrying the next request.
HTTP Status Code: 400
- ValidationException
-
The request failed because it contains a syntax error.
- Reason
-
Indicates the reason for the validation error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.
- RequestId
-
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
HTTP Status Code: 400
Examples
Example 1
This example updates the specified user's nickname to Johnny and the user name to
John Doe. It passes the current Revision so that your update is applied
only if the user hasn't changed since you last read it (optimistic locking); the
response returns the new Revision.
Sample Request
{
"IdentityStoreId": "d-1234567890",
"UserId": "a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"Revision": "1699564800000",
"Operations": [
{
"AttributePath": "nickName",
"AttributeValue": "Johnny"
},
{
"AttributePath": "userName",
"AttributeValue": "John Doe"
}
]
}
Sample Response
{
"IdentityStoreId": "d-1234567890",
"UserId": "a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"UserArn": "arn:aws:identitystore:::user/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"Revision": "1699651200000"
}
Example 2
This example updates the family name of the specified user to Smith. If you omit
Revision, your update is applied unconditionally.
Sample Request
{
"IdentityStoreId": "d-1234567890",
"UserId": "a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"Operations": [
{
"AttributePath": "name.familyName",
"AttributeValue": "Smith"
}
]
}
Sample Response
{
"IdentityStoreId": "d-1234567890",
"UserId": "a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"UserArn": "arn:aws:identitystore:::user/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"Revision": "1699651200000"
}
Example 3
This example updates the phone number for the specified user.
Sample Request
{
"IdentityStoreId": "d-1234567890",
"UserId": "a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"Operations": [
{
"AttributePath": "phoneNumbers",
"AttributeValue": [
{
"Value": "832-555-0100",
"Type": "home",
"Primary": true
}
]
}
]
}
Sample Response
{
"IdentityStoreId": "d-1234567890",
"UserId": "a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"UserArn": "arn:aws:identitystore:::user/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"Revision": "1699651200000"
}
Example 4
This example replaces all attributes in aws:identitystore:enterprise extension for the specified user.
Sample Request
{
"IdentityStoreId": "d-1234567890",
"UserId": "a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"Operations": [
{
"AttributePath": "aws:identitystore:enterprise",
"AttributeValue": {
"employeeNumber": "701984",
"costCenter": "4130"
}
}
]
}
Sample Response
{
"IdentityStoreId": "d-1234567890",
"UserId": "a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"UserArn": "arn:aws:identitystore:::user/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"Revision": "1699651200000"
}
Example 5
This example replaces only department in aws:identitystore:enterprise extension for the specified user.
Sample Request
{
"IdentityStoreId": "d-1234567890",
"UserId": "a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"Operations": [
{
"AttributePath": "aws:identitystore:enterprise.department",
"AttributeValue": "Park Admissions"
}
]
}
Sample Response
{
"IdentityStoreId": "d-1234567890",
"UserId": "a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"UserArn": "arn:aws:identitystore:::user/a1b2c3d4-5678-90ab-cdef-EXAMPLE11111",
"Revision": "1699651200000"
}
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: