Skip to content

/AWS1/CL_WSW=>CREATEIDENTITYPROVIDER()

About CreateIdentityProvider

Creates an identity provider resource that is then associated with a web portal.

Method Signature

IMPORTING

Required arguments:

IV_PORTALARN TYPE /AWS1/WSWARN /AWS1/WSWARN

The ARN of the web portal.

IV_IDENTITYPROVIDERNAME TYPE /AWS1/WSWIDENTITYPROVIDERNAME /AWS1/WSWIDENTITYPROVIDERNAME

The identity provider name.

IV_IDENTITYPROVIDERTYPE TYPE /AWS1/WSWIDENTITYPROVIDERTYPE /AWS1/WSWIDENTITYPROVIDERTYPE

The identity provider type.

IT_IDENTITYPROVIDERDETAILS TYPE /AWS1/CL_WSWIDPVDRDETAILS_W=>TT_IDENTITYPROVIDERDETAILS TT_IDENTITYPROVIDERDETAILS

The identity provider details. The following list describes the provider detail keys for each identity provider type.

  • For Google and Login with Amazon:

    • client_id

    • client_secret

    • authorize_scopes

  • For Facebook:

    • client_id

    • client_secret

    • authorize_scopes

    • api_version

  • For Sign in with Apple:

    • client_id

    • team_id

    • key_id

    • private_key

    • authorize_scopes

  • For OIDC providers:

    • client_id

    • client_secret

    • attributes_request_method

    • oidc_issuer

    • authorize_scopes

    • authorize_url if not available from discovery URL specified by oidc_issuer key

    • token_url if not available from discovery URL specified by oidc_issuer key

    • attributes_url if not available from discovery URL specified by oidc_issuer key

    • jwks_uri if not available from discovery URL specified by oidc_issuer key

  • For SAML providers:

    • MetadataFile OR MetadataURL

    • IDPSignout (boolean) optional

    • IDPInit (boolean) optional

    • RequestSigningAlgorithm (string) optional - Only accepts rsa-sha256

    • EncryptedResponses (boolean) optional

Optional arguments:

IV_CLIENTTOKEN TYPE /AWS1/WSWCLIENTTOKEN /AWS1/WSWCLIENTTOKEN

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request. Idempotency ensures that an API request completes only once. With an idempotent request, if the original request completes successfully, subsequent retries with the same client token returns the result from the original successful request.

If you do not specify a client token, one is automatically generated by the Amazon Web Services SDK.

IT_TAGS TYPE /AWS1/CL_WSWTAG=>TT_TAGLIST TT_TAGLIST

The tags to add to the identity provider resource. A tag is a key-value pair.

RETURNING

OO_OUTPUT TYPE REF TO /AWS1/CL_WSWCREATEIDPVDRRSP /AWS1/CL_WSWCREATEIDPVDRRSP