Updated on 2025-08-21 GMT+08:00

Querying Instance Configurations

Function

This API is used to query the configurations of an IAM Identity Center instance, including identity authentication and session management. It can be called only from the organization's management account or from a delegated administrator account of a cloud service.

URI

GET /v1/instances/{instance_id}/sso-configuration

Table 1 Path parameters

Parameter

Mandatory

Type

Description

instance_id

Yes

String

Globally unique ID of an IAM Identity Center instance.

Request Parameters

Table 2 Parameters in the request header

Parameter

Mandatory

Type

Description

X-Security-Token

No

String

Security token (session token) of your temporary security credentials. If a temporary security credential is used, this header is required.

Response Parameters

Status code: 200

Table 3 Parameters in the response body

Parameter

Type

Description

sso_configuration

SSOConfigurationDto object

IAM Identity Center instance configuration.

Table 4 SSOConfigurationDto

Parameter

Type

Description

mfa_mode

String

Effective mode of MFA.

no_mfa_signin_behavior

String

Available login behavior when an MFA device is not registered.

no_password_signin_behavior

String

Login without a password.

allowed_mfa_types

Array of strings

Allowed MFA types.

session_configuration

SessionConfigurationDto object

Session validity configuration.

Table 5 SessionConfigurationDto

Parameter

Type

Description

max_authentication_age

String

Effective time of a session.

Status code: 400

Table 6 Parameters in the response body

Parameter

Type

Description

error_code

String

Error code.

error_msg

String

Error message.

request_id

String

Unique ID of a request.

Status code: 403

Table 7 Parameters in the response body

Parameter

Type

Description

error_code

String

Error code.

error_msg

String

Error message.

request_id

String

Unique ID of a request.

encoded_authorization_message

String

Encrypted error message.

Status code: 404

Table 8 Parameters in the response body

Parameter

Type

Description

error_code

String

Error code.

error_msg

String

Error message.

request_id

String

Unique ID of a request.

Example Request

Querying configurations of an IAM Identity Center instance, including identity authentication and session management

GET https://{hostname}/v1/instances/{instance_id}/sso-configuration

Example Response

Status code: 200

Successful.

{
  "sso_configuration" : {
    "mfa_mode" : "ALWAYS_ON",
    "no_mfa_signin_behavior" : "ALLOWED",
    "no_password_signin_behavior" : "BLOCKED",
    "allowed_mfa_types" : [ "TOTP" ],
    "session_configuration" : {
      "max_authentication_age" : "PT8H"
    }
  }
}

Status Codes

Status Code

Description

200

Successful.

400

Bad request.

403

Forbidden.

404

Forbidden.

Error Codes

For details, see Error Codes.