Help Center/ IAM Identity Center/ CLI Reference/ CLI Command Reference (IAM Identity Center Store)
Updated on 2026-09-30 GMT+08:00

CLI Command Reference (IAM Identity Center Store)

User Management

API Name

Command

Description

Operation

Listing Users

hcloud IdentityCenterStore ListUsers

This API is used to list IAM Identity Center users in a specified IdentityStore. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Creating a User

hcloud IdentityCenterStore CreateUser

This API is used to create an IAM Identity Center user in a specified IdentityStore. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting a User

hcloud IdentityCenterStore DeleteUser

This API is used to delete an IAM Identity Center user based on the user ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying User Details

hcloud IdentityCenterStore DescribeUser

This API is used to query details about an IAM Identity Center user based on the user ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating a User

hcloud IdentityCenterStore UpdateUser

This API is used to update the attributes of an IAM Identity Center user based on the user ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying a User ID

hcloud IdentityCenterStore GetUserId

This API is used to query a user ID in exact match based on either the username or the external identity source ID. They cannot be both specified. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying Details About Specified Users in Batches

hcloud IdentityCenterStore DescribeUsers

This API is used to query details about specified users in batches. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Sending a Password Reset Link by Email or Generating a One-Time Password for a User

hcloud IdentityCenterStore ResetPwdMode

This API is used to send a password reset link by email or generate a one-time password for a user. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Enabling a User

hcloud IdentityCenterStore EnableUser

This API is used to enable an IAM Identity Center user.

Go debug

Disabling a User

hcloud IdentityCenterStore DisableUser

This API is used to disable an IAM Identity Center user. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Verifying a User Email Address

hcloud IdentityCenterStore VerifyEmail

This API is used to verify a user's email address. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Registering an MFA device

hcloud IdentityCenterStore RegisterMfaDeviceForUser

This API is used to register an MFA device for a user and return an MFA registration address. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing MFA Devices of a User

hcloud IdentityCenterStore BatchListMfaDevicesForUser

This API is used to list MFA devices of a specified user. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating the Display Name of an MFA Device

hcloud IdentityCenterStore UpdateMfaDeviceForUser

This API is used to update the display name of an MFA device. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting an MFA Device

hcloud IdentityCenterStore DeleteMfaDeviceForUser

This API is used to delete an MFA device of a user. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing User Login Sessions

hcloud IdentityCenterStore ListSessions

This API is used to query the login session information of a specified user. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting User Login Sessions in Batches

hcloud IdentityCenterStore BatchDeleteSessions

This API is used to delete user login sessions in batches. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

User Group Management

API Name

Command

Description

Operation

Creating a User Group

hcloud IdentityCenterStore CreateGroup

This API is used to create an IAM Identity Center user group in a specified IdentityStore. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing User Groups

hcloud IdentityCenterStore ListGroups

This API is used to list IAM Identity Center user groups in a specified IdentityStore. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting a User Group

hcloud IdentityCenterStore DeleteGroup

This API is used to delete an IAM Identity Center user group based on the group ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating a User Group

hcloud IdentityCenterStore UpdateGroup

This API is used to update the attributes of an IAM Identity Center user group based on the group ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying User Group Details

hcloud IdentityCenterStore DescribeGroup

This API is used to query details about an IAM Identity Center user group based on the group ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying a Group ID

hcloud IdentityCenterStore GetGroupId

This API is used to query the group ID in exact match based on either the display name or the external identity source ID. They cannot be both specified. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying Details About Specified User Groups in Batches

hcloud IdentityCenterStore DescribeGroups

This API is used to query details about specified user groups in batches. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Group Membership Management

API Name

Command

Description

Operation

Adding a User to a Group

hcloud IdentityCenterStore CreateGroupMembership

This API is used to add a user to a group. The user and the group must be in the same identity source. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Users in a Group

hcloud IdentityCenterStore ListGroupMemberships

This API is used to query users in a user group based on the group ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Groups to which a User is Added

hcloud IdentityCenterStore ListGroupMembershipsForMember

This API is used to query the groups to which a user is added. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying the Group Membership ID

hcloud IdentityCenterStore GetGroupMembershipId

This API is used to query the group membership ID based on the user ID and group ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying Whether a User Is a Member of a Group

hcloud IdentityCenterStore IsMemberInGroups

This API is used to query whether a user is a member of a group based on the user ID and group ID list. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Removing a User from a Group

hcloud IdentityCenterStore DeleteGroupMembership

This API is used to remove a user from a group based on the group membership ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying the Group Membership

hcloud IdentityCenterStore DescribeGroupMembership

This API is used to query details about the group membership based on the group membership ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Identity Provider Management

API Name

Command

Description

Operation

Creating External Identity Provider Configurations

hcloud IdentityCenterStore CreateExternalIdPConfigurationForDirectory

This API is used to create configurations for an external identity provider. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying External Identity Provider Configurations

hcloud IdentityCenterStore ListExternalIdPConfigurationsForDirectory

This API is used to query configurations for an external identity provider. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Enabling an External Identity Provider

hcloud IdentityCenterStore EnableExternalIdPConfigurationForDirectory

This API is used to enable an external identity provider. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Disabling an External Identity Provider

hcloud IdentityCenterStore DisableExternalIdPConfigurationForDirectory

This API is used to disable an external identity provider. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting Configurations of an External Identity Provider

hcloud IdentityCenterStore DeleteExternalIdPConfigurationForDirectory

This API is used to delete configurations of an external identity provider. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating Configurations of an External Identity Provider

hcloud IdentityCenterStore UpdateExternalIdPConfigurationForDirectory

This API is used to update configurations of an external identity provider. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing External Identity Provider Certificates

hcloud IdentityCenterStore ListExternalIdPCertificates

This API is used to list certificates of an external identity provider. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Importing External Identity Provider Certificates

hcloud IdentityCenterStore ImportExternalIdPCertificate

This API is used to import external identity provider certificates. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting External Identity Provider Certificates

hcloud IdentityCenterStore DeleteExternalIdPCertificate

This API is used to delete external identity provider certificates. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Service Provider Management

API Name

Command

Description

Operation

Querying Service Provider Configurations

hcloud IdentityCenterStore GetSpConfigurationForDirectory

This API is used to query service provider configurations. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Creating a Service Provider Certificate

hcloud IdentityCenterStore CreateSpCertificate

This API is used to create a SAML signing certificate for a service provider. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Service Provider Certificates

hcloud IdentityCenterStore ListSpCertificates

This API is used to query the SAML signing certificate of a service provider.

Go debug

Deleting a Service Provider Certificate

hcloud IdentityCenterStore DeleteSpCertificate

This API is used to delete a SAML signing certificate of a service provider. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Activating a Service Provider Certificate

hcloud IdentityCenterStore UpdateSpActiveCertificate

This API is used to activate a SAML signing certificate of a service provider. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Automatic Provisioning Management

API Name

Command

Description

Operation

Enabling Automatic Provisioning

hcloud IdentityCenterStore CreateProvisioningTenant

This API is used to enable automatic provisioning and automatic SCIM synchronization. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Checking Automatic Provisioning

hcloud IdentityCenterStore ListProvisioningTenants

This API is used to check whether SCIM automatic provisioning is enabled. It returns detailed provisioning information if the function is enabled. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting Automatic Provisioning

hcloud IdentityCenterStore DeleteProvisioningTenant

This API is used to delete automatic provisioning. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Creating an Access Token

hcloud IdentityCenterStore CreateBearerToken

This API is used to create an access token. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Access Tokens

hcloud IdentityCenterStore ListBearerTokens

This API is used to list access tokens. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting an Access Token

hcloud IdentityCenterStore DeleteBearerToken

This API is used to delete an access token. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Identity Source Quota Management

API Name

Command

Description

Operation

Querying Identity Source Quotas

hcloud IdentityCenterStore GetIdentityStoreSummary

This API is used to query identity source quotas. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Custom Password Policy Management

API Name

Command

Description

Operation

Querying Custom Password Policies

hcloud IdentityCenterStore DescribePasswordPolicy

This API is used to query custom password policies. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating Custom Password Policies

hcloud IdentityCenterStore UpdatePasswordPolicy

This API is used to update custom password policies. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug