

# CreateGroup
<a name="API_CreateGroup"></a>

Creates a group within the specified identity store.

## Request Syntax
<a name="API_CreateGroup_RequestSyntax"></a>

```
{
   "Description": "{{string}}",
   "DisplayName": "{{string}}",
   "IdentityStoreId": "{{string}}"
}
```

## Request Parameters
<a name="API_CreateGroup_RequestParameters"></a>

For information about the parameters that are common to all actions, see [Common Parameters](CommonParameters.md).

The request accepts the following data in JSON format.

 ** [Description](#API_CreateGroup_RequestSyntax) **   <a name="singlesignon-CreateGroup-request-Description"></a>
A string containing the description of the group.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 1024.  
Pattern: `[\p{L}\p{M}\p{S}\p{N}\p{P}\t\n\r  　]+`   
Required: No

 ** [DisplayName](#API_CreateGroup_RequestSyntax) **   <a name="singlesignon-CreateGroup-request-DisplayName"></a>
A string containing the name of the group. This value is commonly displayed when the group is referenced. `Administrator` and `AWSAdministrators` are reserved names and can't be used for users or groups.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 1024.  
Pattern: `[\p{L}\p{M}\p{S}\p{N}\p{P}\t\n\r  　]+`   
Required: No

 ** [IdentityStoreId](#API_CreateGroup_RequestSyntax) **   <a name="singlesignon-CreateGroup-request-IdentityStoreId"></a>
The globally unique identifier for the identity store.  
You can specify the identity store by ID or by Amazon Resource Name (ARN). For example, identity store ID `d-1234567890` or identity store ARN `arn:aws:identitystore::111122223333:identitystore/d-1234567890`.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 93.  
Pattern: `(arn:aws[a-z-]*:identitystore::\d{12}:identitystore/)?(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})`   
Required: Yes

## Response Syntax
<a name="API_CreateGroup_ResponseSyntax"></a>

```
{
   "GroupArn": "string",
   "GroupId": "string",
   "IdentityStoreId": "string",
   "Revision": "string"
}
```

## Response Elements
<a name="API_CreateGroup_ResponseElements"></a>

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.

 ** [GroupArn](#API_CreateGroup_ResponseSyntax) **   <a name="singlesignon-CreateGroup-response-GroupArn"></a>
The Amazon Resource Name (ARN) of the newly created group in the identity store. For example, `arn:aws:identitystore:::group/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222`.  
Type: String  
Length Constraints: Minimum length of 60. Maximum length of 100.  
Pattern: `arn:aws[a-z-]*:identitystore:::(user|group|membership)/([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}` 

 ** [GroupId](#API_CreateGroup_ResponseSyntax) **   <a name="singlesignon-CreateGroup-response-GroupId"></a>
The identifier of the newly created group in the identity store.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 100.  
Pattern: `(arn:aws[a-z-]*:identitystore:::(user|group|membership)/)?([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}` 

 ** [IdentityStoreId](#API_CreateGroup_ResponseSyntax) **   <a name="singlesignon-CreateGroup-response-IdentityStoreId"></a>
The globally unique identifier for the identity store.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 93.  
Pattern: `(arn:aws[a-z-]*:identitystore::\d{12}:identitystore/)?(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})` 

 ** [Revision](#API_CreateGroup_ResponseSyntax) **   <a name="singlesignon-CreateGroup-response-Revision"></a>
The revision of the newly created group in the identity store.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 64.  
Pattern: `[0-9]+` 

## Errors
<a name="API_CreateGroup_Errors"></a>

For information about the errors that are common to all actions, see [Common Error Types](CommonErrors.md).

 ** AccessDeniedException **   
You do not have sufficient access to perform this action.    
 ** Reason **   
Indicates the reason for an access denial when returned by KMS while accessing a Customer Managed KMS key. For non-KMS access-denied errors, this field is not included.  
 ** RequestId **   
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
HTTP Status Code: 400

 ** ConflictException **   
This request cannot be completed for one of the following reasons:  
+ Performing the requested operation would violate an existing uniqueness claim in the identity store. Resolve the conflict before retrying this request.
+ The requested resource was being concurrently modified by another request.  
 ** Reason **   
Indicates the reason for the conflict error. `UNIQUENESS_CONSTRAINT_VIOLATION` indicates that the request would violate an existing uniqueness constraint, such as a user name or other unique attribute that is already in use. `CONCURRENT_MODIFICATION` indicates that the resource was modified by another request during this operation.  
 ** RequestId **   
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
HTTP Status Code: 400

 ** InternalServerException **   
The request processing has failed because of an unknown error, exception or failure with an internal server.    
 ** RequestId **   
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.  
 ** RetryAfterSeconds **   
The number of seconds to wait before retrying the next request.
HTTP Status Code: 500

 ** ResourceNotFoundException **   
Indicates that a requested resource is not found.    
 ** Reason **   
Indicates the reason for a resource not found error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.  
 ** RequestId **   
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.  
 ** ResourceId **   
The identifier for a resource in the identity store that can be used as `UserId` or `GroupId`. The format for `ResourceId` is either `UUID` or `1234567890-UUID`, where `UUID` is a randomly generated value for each resource when it is created and `1234567890` represents the ` IdentityStoreId` string value. In the case that the identity store is migrated from a legacy SSO identity store, the `ResourceId` for that identity store will be in the format of `UUID`. Otherwise, it will be in the `1234567890-UUID` format.  
 ** ResourceType **   
An enum object indicating the type of resource in the identity store service. Valid values include USER, GROUP, GROUP\_MEMBERSHIP, RESOURCE\_POLICY, and IDENTITY\_STORE.
HTTP Status Code: 400

 ** ServiceQuotaExceededException **   
The request would cause the number of users or groups in the identity store to exceed the maximum allowed.    
 ** RequestId **   
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
HTTP Status Code: 400

 ** ThrottlingException **   
Indicates that the principal has crossed the throttling limits of the API operations.    
 ** Reason **   
Indicates the reason for the throttling error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.  
 ** RequestId **   
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.  
 ** RetryAfterSeconds **   
The number of seconds to wait before retrying the next request.
HTTP Status Code: 400

 ** ValidationException **   
The request failed because it contains a syntax error.    
 ** Reason **   
Indicates the reason for the validation error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.  
 ** RequestId **   
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
HTTP Status Code: 400

## Examples
<a name="API_CreateGroup_Examples"></a>

### Example
<a name="API_CreateGroup_Example_1"></a>

This example creates a new group called Developers in the specified identity store.

#### Sample Request
<a name="API_CreateGroup_Example_1_Request"></a>

```
{
    "IdentityStoreId": "d-1234567890",
    "DisplayName": "Developers",
    "Description": "Group that contains all developers"
}
```

#### Sample Response
<a name="API_CreateGroup_Example_1_Response"></a>

```
{
    "IdentityStoreId": "d-1234567890",
    "GroupId": "a1b2c3d4-5678-90ab-cdef-EXAMPLE22222",
    "GroupArn": "arn:aws:identitystore:::group/a1b2c3d4-5678-90ab-cdef-EXAMPLE22222",
    "Revision": "1699564800000"
}
```

## See Also
<a name="API_CreateGroup_SeeAlso"></a>

For more information about using this API in one of the language-specific AWS SDKs, see the following:
+  [AWS Command Line Interface V2](https://docs.aws.amazon.com/goto/cli2/identitystore-2020-06-15/CreateGroup) 
+  [AWS SDK for .NET V4](https://docs.aws.amazon.com/goto/DotNetSDKV4/identitystore-2020-06-15/CreateGroup) 
+  [AWS SDK for C\+\+](https://docs.aws.amazon.com/goto/SdkForCpp/identitystore-2020-06-15/CreateGroup) 
+  [AWS SDK for Go v2](https://docs.aws.amazon.com/goto/SdkForGoV2/identitystore-2020-06-15/CreateGroup) 
+  [AWS SDK for Java V2](https://docs.aws.amazon.com/goto/SdkForJavaV2/identitystore-2020-06-15/CreateGroup) 
+  [AWS SDK for JavaScript V3](https://docs.aws.amazon.com/goto/SdkForJavaScriptV3/identitystore-2020-06-15/CreateGroup) 
+  [AWS SDK for Kotlin](https://docs.aws.amazon.com/goto/SdkForKotlin/identitystore-2020-06-15/CreateGroup) 
+  [AWS SDK for PHP V3](https://docs.aws.amazon.com/goto/SdkForPHPV3/identitystore-2020-06-15/CreateGroup) 
+  [AWS SDK for Python (Boto3)](https://docs.aws.amazon.com/goto/boto3/identitystore-2020-06-15/CreateGroup) 
+  [AWS SDK for Ruby V3](https://docs.aws.amazon.com/goto/SdkForRubyV3/identitystore-2020-06-15/CreateGroup) 