Updated on 2026-07-22 GMT+08:00

Adding Tags to IAM Resources

Function

This API is used to add tags to IAM resources.

Authorization Information

Each account root user has all the permissions required to call all APIs, but IAM users must be assigned the following required identity policy-based permissions. For details about the required permissions, see Permissions Policies and Supported Actions.

Action

Access Level

Resource Type (*: required)

Condition Key

Alias

Dependencies

iam::tagForResourceV5

Tagging

agency

g:ResourceTag/<tag-key>

-

-

user

  • g:ResourceTag/<tag-key>

  • iam:ResourceIsRootUser

samlProvider

g:ResourceTag/<tag-key>

oidcProvider

g:ResourceTag/<tag-key>

-

  • g:RequestTag/<tag-key>

  • g:TagKeys

URI

POST /v5/{resource_type}/{resource_id}/tags/create

Table 1 Path Parameters

Parameter

Mandatory

Type

Description

resource_id

Yes

String

Definition:

Resource ID.

Constraints:

The value can contain 1 to 64 characters. Only letters, digits, and hyphens (-) are allowed.

Range:

N/A

Default Value:

N/A

resource_type

Yes

String

Definition

Resource type.

Constraints

The value can be trust agency, user, or provider.

Range

The value can be agency or user.

Default Value

N/A

Request Parameters

Table 2 Request body parameters

Parameter

Mandatory

Type

Description

tags

No

Array of Tag objects

Definition:

List of custom tags.

Constraints:

N/A

Range:

N/A

Default Value:

N/A

Table 3 Tag

Parameter

Mandatory

Type

Description

tag_key

Yes

String

Definition:

Tag key.

Constraints:

The value can contain 1 to 128 characters. Letters, digits, spaces, and the following special characters are allowed: _.:=+-@. It cannot start with a space or _sys_ or end with a space.

Range:

N/A

Default Value:

N/A

tag_value

Yes

String

Definition:

Tag value.

Constraints:

The value can be an empty string or contain 0 to 255 characters. Letters, digits, spaces, and the following special characters are allowed: _.:/=+-@.

Range:

N/A

Default Value:

N/A

Response Parameters

Status code: 200

Table 4 Response body parameters

Parameter

Type

Description

tags

Array of tags objects

Definition:

List of custom tags.

Range:

N/A

Table 5 tags

Parameter

Type

Description

tag_key

String

Definition:

Tag key.

Range:

N/A

tag_value

String

Definition:

Tag value.

Range:

N/A

Status code: 400

Table 6 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Status code: 403

Table 7 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

encoded_authorization_message

String

Definition :

Encrypted details returned when the authentication fails, which are used to locate authentication problems. The STS5 decryption API can be used for decryption. For details, see API link.

Range:

N/A.

Status code: 404

Table 8 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Status code: 409

Table 9 Response body parameters

Parameter

Type

Description

error_code

String

Definition :

Error code. For details, see Error Code.

Range:

The format is PAP5.XXXX, for example, PAP5.0012.

error_msg

String

Definition :

Error message. For details, see Error Message.

Range:

N/A.

request_id

String

Definition:

Unique identifier of an API request, which is used to locate API calling exceptions.

Range:

N/A

Example Requests

Adding a tag to a specified IAM resource, with tag key key and tag value value

POST https://{endpoint}/v5/{resource_type}/{resource_id}/tags/create

{
  "tags" : [ {
    "tag_key" : "key",
    "tag_value" : "value"
  } ]
}

Example Responses

Status code: 200

Successful

{
  "tags" : [ {
    "tag_key" : "key",
    "tag_value" : "value"
  } ]
}

Status Codes

Status Code

Description

200

Successful

400

Bad request

403

Forbidden

404

Not found

409

Conflict

Error Codes

See Error Codes.