Zum Inhalt springen

Create, manage and delete federated identity providers

  1. Navigate to IAM and Management > Service accounts.
  2. Select the service account you want to create a federation for.
  3. Navigate to Federated identity providers.
  4. Select + Add a federated identity provider.
  5. Provide a short, unique name for the federation.
  6. Specify the issuer URL for the trusted identity provider. This must be the exact iss value found in tokens from this provider. It must use HTTPS and must not include a trailing slash.
  7. Add a series of assertions that will define the behaviour or claims within the this Federated Identity Provider for it to be accepted.
    • Assertions define an Item, an Operator, and a Value. Items that can be defined include, for example, subject and audience and currently only the equality operator is supported.
    • An assertion for the audience (aud) is required and must be always provided. If not provided the federation cannot be created.
    • Tokens are accepted only when all assertion conditions are met.
    • For example, assertions might require sub (subject) to be shop-api AND aud (audience) to be clients.
  8. Select Create.
  1. Navigate to IAM and Management > Service accounts.
  2. Select the service account whose federated identity providers you want to list.
  3. Navigate to Federated identity providers.

You see an overview of federated identity providers, the issuer URL, and the creation and last update dates.

Show details of a federated identity provider

Section titled “Show details of a federated identity provider”
  1. Navigate to IAM and Management > Service accounts.
  2. Select the service account whose federated identity providers you want to view.
  3. Navigate to Federated identity providers.
  4. Select the federated identity provider you want details for.

You see the name, issuer URL, and assertions.

  1. Navigate to IAM and Management > Service accounts.
  2. Select the service account whose federations you want to update.
  3. Navigate to Federated identity providers.
  4. Select the federated identity provider you want to change.
  1. Navigate to IAM and Management > Service accounts.
  2. Select the service account whose federations you want to delete.
  3. Navigate to Federated identity providers.
  4. Select the three dots at the end of the row for the federated identity provider you want to delete.
  5. Select Delete provider.
  6. Select Delete to confirm.