Create, manage and delete federated identity providers
Create a federated identity provider
Section titled “Create a federated identity provider”- Navigate to IAM and Management > Service accounts.
- Select the service account you want to create a federation for.
- Navigate to Federated identity providers.
- Select + Add a federated identity provider.
- Provide a short, unique name for the federation.
- Specify the issuer URL for the trusted identity provider. This must be the exact
issvalue found in tokens from this provider. It must use HTTPS and must not include a trailing slash. - Add a series of assertions that will define the behaviour or claims within the this Federated Identity Provider for it to be accepted.
- Assertions define an Item, an Operator, and a Value. Items that can be defined include, for example, subject and audience and currently only the equality operator is supported.
- An assertion for the audience (aud) is required and must be always provided. If not provided the federation cannot be created.
- Tokens are accepted only when all assertion conditions are met.
- For example, assertions might require
sub(subject) to beshop-apiANDaud(audience) to beclients.
- Select Create.
Refer to the Create federated identity provider documentation in the API Explorer.
List all federated identity providers
Section titled “List all federated identity providers”- Navigate to IAM and Management > Service accounts.
- Select the service account whose federated identity providers you want to list.
- Navigate to Federated identity providers.
You see an overview of federated identity providers, the issuer URL, and the creation and last update dates.
Refer to the List federated identity providers documentation in the API Explorer.
Show details of a federated identity provider
Section titled “Show details of a federated identity provider”- Navigate to IAM and Management > Service accounts.
- Select the service account whose federated identity providers you want to view.
- Navigate to Federated identity providers.
- Select the federated identity provider you want details for.
You see the name, issuer URL, and assertions.
There is no specific endpoint to obtain the details of a given federated identity provider.
Update a federated identity provider
Section titled “Update a federated identity provider”- Navigate to IAM and Management > Service accounts.
- Select the service account whose federations you want to update.
- Navigate to Federated identity providers.
- Select the federated identity provider you want to change.
Refer to the Update federated identity provider documentation in the API Explorer.
Delete a federated identity provider
Section titled “Delete a federated identity provider”- Navigate to IAM and Management > Service accounts.
- Select the service account whose federations you want to delete.
- Navigate to Federated identity providers.
- Select the three dots at the end of the row for the federated identity provider you want to delete.
- Select Delete provider.
- Select Delete to confirm.
Refer to the Delete federated identity provider documentation in the API Explorer.