Updated on 2026-07-22 GMT+08:00

Replacing the OIDC Provider Fingerprint List

Function

This API is used to replace the existing fingerprint list associated with an OIDC provider with a new one. Generally, you need to update the fingerprint only when the identity provider certificate is changed. This rarely occurs. However, if the provider's certificate changes and you do not update the fingerprint, any attempt to switch to a trust agency associated with the OIDC provider will fail.

Note:

IAM uses its own trusted root Certificate Authorities (CAs) library to verify the TLS certificate of the JSON Web Key Set (JWKS) endpoint. This ensures secure communication with OIDC IdPs. If your OIDC IdP relies on a certificate that is not signed by one of these trusted CAs, we will use the fingerprint set in the IdP configuration to ensure secure communication.

Authorization Information

Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

iam:oidcProviders:updateThumbprintV5

Write

oidcProvider *

g:ResourceTag/<tag-key>

-

-

URI

PUT /v5/oidc-providers/{provider_id}/thumbprint

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

provider_id

Yes

String

Definition

Provider ID.

Constraints

N/A

Range

The value must contain 1 to 64 characters, including only letters, digits, and hyphens (-).

Default Value

N/A

Request Parameters

Table 2 Request body parameters

Parameter

Mandatory

Type

Description

thumbprints

Yes

Array of strings

Definition

List of server certificate fingerprints of an OIDC identity provider.

Constraints

The list contains 1 to 5 elements, and each element contains 64 characters.

Range

N/A

Default Value

N/A

Response Parameters

Status code: 200

Request succeeded.

Status code: 400

Table 3 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Status code: 403

Table 4 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

encoded_authorization_message

String

Definition :

Encrypted details returned when the authentication fails, which are used to locate authentication problems. The STS5 decryption API can be used for decryption. For details, see API link.

Range:

N/A.

Status code: 404

Table 5 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Status code: 409

Table 6 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Example Requests

Replacing the OIDC provider fingerprint list

PUT https://{endpoint}/v5/oidc-providers/{provider_id}/thumbprint

{
  "thumbprints" : [ "stringstringstringstringstringstringstringstringstringstringstri" ]
}

Example Responses

None

Status Codes

Status Code

Description

200

Request succeeded.

400

Abnormal request body.

403

No operation permissions.

404

No resources found.

409

Request conflict.

Error Codes

See Error Codes.