Help Center/ IAM Identity Center/ CLI Reference/ CLI Command Reference (IAM Identity Center)
Updated on 2026-09-30 GMT+08:00

CLI Command Reference (IAM Identity Center)

Instance Management

API Name

Command

Description

Operation

Listing Instances

hcloud IdentityCenter ListInstances

This API is used to list IAM Identity Center instances. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Query the Region Where a Service Instance Is Enabled

hcloud IdentityCenter DescribeRegisteredRegions

This API is used to query the region where the IAM Identity Center instance is enabled. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Selecting a Region for Enabling the Service Instance

hcloud IdentityCenter RegisterRegion

This API is used to select a region where an IAM Identity Center service instance is to be enabled. This API can be called only from the organization's management account.

Go debug

Querying the Service Instance Status

hcloud IdentityCenter GetIdentityCenterServiceStatus

This API is used to query the status of an IAM Identity Center service instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Enabling an IAM Identity Center Instance

hcloud IdentityCenter StartIdentityCenter

This API is used to enable an IAM Identity Center service instance. This API can be called only from the organization's management account.

Go debug

Deleting a Service Instance

hcloud IdentityCenter DeleteIdentityCenter

This API is used to delete an IAM Identity Center service instance. This API can be called only from the organization's management account.

Go debug

Obtaining Identity Source Configurations

hcloud IdentityCenter ListIdentityStoreAssociation

This API is used to obtain identity source configurations of an IAM Identity Center service instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Setting a Custom Portal URL

hcloud IdentityCenter CreateAlias

This API is used to set a custom portal URL. The default URL format is idcenter.huaweicloud.com/d-xxxxxxxxxx/portal. You can change it to idcenter.huaweicloud.com/your_subdomain/portal. Setting a custom portal URL is a one-time operation and cannot be undone. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating HA Function Configurations

hcloud IdentityCenter UpdateHaConfiguration

This API is used to enable or disable HA function configurations. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying HA Configurations

hcloud IdentityCenter GetHaConfiguration

This API is used to query configurations of the high availability (HA) function. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Access Control Attribute Management

API Name

Command

Description

Operation

Enabling Access Control for a Specified Instance

hcloud IdentityCenter CreateInstanceAccessControlAttributeConfiguration

This API is used to enable access control for a specified instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Obtaining Access Control Attributes of a Specified Instance

hcloud IdentityCenter DescribeInstanceAccessControlAttributeConfiguration

This API is used to return IAM Identity Center identity storage attributes that are used with ABAC of a specified IAM Identity Center instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating the Access Control Attributes of a Specified Instance

hcloud IdentityCenter UpdateInstanceAccessControlAttributeConfiguration

This API is used to update IAM Identity Center identity storage attributes that can be used with IAM Identity Center instances for ABAC. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Disabling Access Control Attributes for a Specified Instance

hcloud IdentityCenter DeleteInstanceAccessControlAttributeConfiguration

This API is used to disable ABAC for a specified IAM Identity Center instance and delete all configured attribute mappings. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Permission Set Management

API Name

Command

Description

Operation

Adding a System-defined Identity Policy

hcloud IdentityCenter AttachManagedPolicyToPermissionSet

This API is used to add a system-defined identity policy to a specified permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying the pre-assignment status details of a permission set

hcloud IdentityCenter DescribePermissionSetProvisioningStatus

This API is used to query details about the pre-assignment status of a permission set based on the request ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Detaching a System-defined Identity Policy from a Permission Set

hcloud IdentityCenter DetachManagedPolicyFromPermissionSet

This API is used to detach a system-defined identity policy from a specified permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Accounts Associated with a Permission Set

hcloud IdentityCenter ListAccountsForProvisionedPermissionSet

This API is used to list the accounts associated with a specified permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing System-defined Identity Policies Attached to a Permission Set

hcloud IdentityCenter ListManagedPoliciesInPermissionSet

This API is used to list system-defined identity policies attached to a specified permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Pre-assignment Statuses of Permission Sets

hcloud IdentityCenter ListPermissionSetProvisioningStatus

This API is used to list pre-assignment statuses of permission sets in a specified instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Permission Sets

hcloud IdentityCenter ListPermissionSets

This API is used to list permission sets of a specified instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Creating a Permission Set

hcloud IdentityCenter CreatePermissionSet

This API is used to create a permission set in a specified IAM Identity Center instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

This API is used to list permission sets assigned to an account.

hcloud IdentityCenter ListPermissionSetsProvisionedToAccount

This API is used to list the permission sets provisioned to a specified account. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Pre-provisioning a Permission Set

hcloud IdentityCenter ProvisionPermissionSet

This API is used to pre-provision a specified permission set to a specified account. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting a Permission Set

hcloud IdentityCenter DeletePermissionSet

This API is used to delete a specified permission set based on the permission set ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying Permission Set Details

hcloud IdentityCenter DescribePermissionSet

This API is used to query details about a specified permission set based on the permission set ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating a permission set

hcloud IdentityCenter UpdatePermissionSet

This API is used to update the attributes of a specified permission set based on the permission set ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Obtaining custom policies attached to a permission set

hcloud IdentityCenter GetCustomRoleForPermissionSet

This API is used to obtain custom policies attached to a permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Attaching a Custom Policy to a Permission Set

hcloud IdentityCenter PutCustomRoleToPermissionSet

This API is used to attach a custom policy to a permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting a Custom Policy from a Specified Permission Set

hcloud IdentityCenter DeleteCustomRoleFromPermissionSet

This API is used to delete a custom policy from a specified permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Obtaining Custom Identity Policies Attached to a Permission Set

hcloud IdentityCenter GetCustomPolicyForPermissionSet

This API is used to obtain custom identity policies attached to a permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Attaching a custom identity policy to a permission set

hcloud IdentityCenter PutCustomPolicyToPermissionSet

This API is used to attach a custom identity policy to a permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting a Custom Identity Policy from a Specified Permission Set

hcloud IdentityCenter DeleteCustomPolicyFromPermissionSet

This API is used to delete a custom identity policy from a specified permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Attaching a System-defined Policy to a Permission Set

hcloud IdentityCenter AttachManagedRoleToPermissionSet

This API is used to attach a system-defined policy to a permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Detaching a System-defined Policy from a Permission Set

hcloud IdentityCenter DetachManagedRoleFromPermissionSet

This API is used to detach a system-defined policy from a specified permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing System-Defined Policies Attached to a Permission Set

hcloud IdentityCenter ListManagedRolesInPermissionSet

This API is used to list system-defined policies attached to a specified permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying Permission Set Quotas

hcloud IdentityCenter GetPermissionSetSummary

This API is used to query permission set quotas. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Account Authorization Management

API Name

Command

Description

Operation

Removing Account Authorization

hcloud IdentityCenter DeleteAccountAssignment

This API is used to remove a principal's access from a specified permission set provisioned to a specified account. The principal can be either a user or a group in IAM Identity Center. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying Details about the Account Authorization Creation Status

hcloud IdentityCenter DescribeAccountAssignmentCreationStatus

This API is used to query details about the account authorization creation status of a specified IAM Identity Center instance based on the request ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Account Authorization Creation Statuses

hcloud IdentityCenter ListAccountAssignmentCreationStatus

This API is used to list the creation statuses of account authorizations in a specified IAM Identity Center instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Account Authorization Deletion Statuses

hcloud IdentityCenter ListAccountAssignmentDeletionStatus

This API is used to list the deletion statuses of account authorizations in a specified IAM Identity Center instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Users or Groups Associated with an Account and a Permission Set

hcloud IdentityCenter ListAccountAssignments

This API is used to list the users or groups associated with a specified account and a specified permission set. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Creating an Account Authorization

hcloud IdentityCenter CreateAccountAssignment

This API is used to assign access permissions to a specified permission set and provision it to a principal for a specified account. The principal can be either a user or a group in IAM Identity Center. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying Details about the Account Authorization Deletion Status

hcloud IdentityCenter DescribeAccountAssignmentDeletionStatus

This API is used to query details about the account authorization deletion status of a specified IAM Identity Center instance based on the request ID. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Disassociating All Account Authorizations from a User or Group

hcloud IdentityCenter DisassociateProfile

This API is used to disassociate all account authorizations from a user or group. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Accounts Associated with a User or User Group

hcloud IdentityCenter ListAccountAssignmentsForPrincipal

This API is used to list accounts associated with a user or user group. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Tag Management

API Name

Command

Description

Operation

Listing Tags of a Specified Resource

hcloud IdentityCenter ListTagResources

This API is used to list tags attached to a specified resource. You can attach tags to the permission set of an instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Adding Tags to a Specified Resource

hcloud IdentityCenter CreateTagResource

This API is used to add one or more tags to a specified resource. Currently, you can attach tags to the permission set of an instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting Tags with a Specified Key from a Specified Resource

hcloud IdentityCenter DeleteTagResource

This API is used to delete any tags with a specified key from a specified resource. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Application Management

API Name

Command

Description

Operation

Creating an Application Instance

hcloud IdentityCenter CreateApplicationInstance

This API is used to create an application instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Application Instances

hcloud IdentityCenter ListApplicationInstances

This API is used to list application instances. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Preset Application Templates in the Application Directory

hcloud IdentityCenter ListCatalogApplications

This API is used to list preset application templates in the application directory. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Application Providers

hcloud IdentityCenter ListApplicationProviders

This API is used to list application providers. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Application Templates

hcloud IdentityCenter ListApplicationTemplates

This API is used to list application templates. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying Configurations of Application Assignment Attributes

hcloud IdentityCenter GetApplicationAssignmentConfiguration

This API is used to query configurations of application assignment attributes to assign application access permissions to users or user groups. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating the Display Information of an Application Instance

hcloud IdentityCenter UpdateApplicationInstanceDisplayData

This API is used to update the display information of an application instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Uploading an Application Instance Metadata File

hcloud IdentityCenter ImportApplicationInstanceServiceProviderMetadata

This API is used to upload an application instance metadata file. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating Application Attribute Configurations

hcloud IdentityCenter UpdateApplicationInstanceResponseConfiguration

This API is used to update application attribute configurations, including the attribute mapping, relay state, and session expiration time in the application. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating Schema Attribute Mapping Configurations of an Application

hcloud IdentityCenter UpdateApplicationInstanceResponseSchemaConfiguration

This API is used to update schema attribute mapping configurations of an application to support Subject attribute mapping and the Subject NameID format in SAML assertions. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating Service Provider Configurations for an Application Instance

hcloud IdentityCenter UpdateApplicationInstanceServiceProviderConfiguration

This API is used to update service provider configurations for an application instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating the Application Instance Status

hcloud IdentityCenter UpdateApplicationInstanceStatus

This API is used to update the application instance status. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Updating Certificate Configurations of an Application Instance

hcloud IdentityCenter UpdateApplicationInstanceSecurityConfiguration

This API is used to update certificate configurations of an application instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying Application Details

hcloud IdentityCenter DescribeApplication

This API is used to query application details. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Applications

hcloud IdentityCenter ListApplications

This API is used to list applications. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying Application Instance Details

hcloud IdentityCenter GetApplicationInstance

This API is used to query application instance details. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting an Application Instance

hcloud IdentityCenter DeleteApplicationInstance

This API is used to delete an application instance. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying Application Provider Details

hcloud IdentityCenter DescribeApplicationProvider

This API is used to query application provider details. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Associations Between an Application Instance and a User or User Group

hcloud IdentityCenter ListProfiles

This API is used to list associations between an application instance and a user or user group. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting the Association Between an Application Instance and a User or User Group

hcloud IdentityCenter DeleteProfile

This API is used to delete the association between an application instance and a user or user group. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Application Authorization Management

API Name

Command

Description

Operation

Listing Users or User Groups Assigned to an Application

hcloud IdentityCenter ListApplicationAssignments

This API is used to list users or user groups assigned to an application. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Assigning Users or User Groups to an Application

hcloud IdentityCenter CreateApplicationAssignment

This API is used to assign users or user groups to an application. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting Users or User Groups Assigned to an Application

hcloud IdentityCenter DeleteApplicationAssignment

This API is used to delete users or user groups assigned to an application. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Applications Associated with a User or User Group

hcloud IdentityCenter ListApplicationAssignmentsForPrincipal

This API is used to list applications associated with a user or user group. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Application Certificate Management

API Name

Command

Description

Operation

Activating Application Instance Certificates

hcloud IdentityCenter UpdateApplicationInstanceActiveCertificate

This API is used to activate application instance certificates to implement certificate rotation. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Deleting an Application Instance Certificate

hcloud IdentityCenter DeleteApplicationInstanceCertificate

This API is used to delete an application instance certificate. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Creating an Application Instance Certificate

hcloud IdentityCenter CreateApplicationInstanceCertificate

This API is used to create an application instance certificate. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Listing Application Instance Certificates

hcloud IdentityCenter ListApplicationInstanceCertificates

This API is used to list application instance certificates. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Login Configuration Management

API Name

Command

Description

Operation

Configuring an Instance

hcloud IdentityCenter UpdateSsoConfiguration

This API is used to configure an IAM Identity Center instance, including identity authentication configuration and session management. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Querying Instance Configurations

hcloud IdentityCenter GetSsoConfiguration

This API is used to query configurations of an IAM Identity Center instance, including identity authentication and session management configurations. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

MFA Configuration Management

API Name

Command

Description

Operation

Querying MFA Management Configurations

hcloud IdentityCenter GetMfaDeviceManagementForIdentityStore

This API is used to query MFA management configurations. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug

Configuring MFA Management

hcloud IdentityCenter PutMfaDeviceManagementForIdentityStore

This API is used to configure MFA management. This API can be called only from the organization's management account or from a delegated administrator account of a cloud service.

Go debug