CLI integration example

Updated at:
Copy as MD

The Alibaba Cloud Command Line Interface (CLI) is a general-purpose command-line tool built on OpenAPI. You can use the Alibaba Cloud CLI to automate the management and maintenance of Cloud Single Sign-On (CloudSSO). This topic describes the procedure and provides examples for a CloudSSO administrator to use the Alibaba Cloud CLI to call CloudSSO.

Prerequisites

If you are unfamiliar with the Alibaba Cloud CLI, see What is Alibaba Cloud CLI?.

Install the Alibaba Cloud CLI

You must install the Alibaba Cloud CLI before you can use it. Installation methods are available for Windows, Linux, and macOS. Choose the installation guide for your operating system.

You can also use Cloud Shell to debug Alibaba Cloud CLI commands. For more information about Cloud Shell, see What is Cloud Shell?.

Configure the Alibaba Cloud CLI

For more information, see Log on to CloudSSO and access Alibaba Cloud resources using the CLI.

Generate a sample CLI command

  1. Go to the CloudSSO API debugging list.

  2. On the API debugging page, search for the API you want to use in the search box on the left. In the Parameter Settings section, enter the parameters according to the API documentation. Click the CLI Example tab to the right of the Parameter Settings section to generate a sample command with the parameters.

    • Click the Run Command image button to open Cloud Shell and quickly debug the command.

    • Click the Copy image button to copy the sample CLI command to the clipboard. Then, paste the command into a local shell tool to run it.

      • When you copy the sample CLI command to a local shell tool for debugging, note the parameter format. For more information about the format of Alibaba Cloud CLI command parameters, see Parameter format.

      • The sample command generated by the OpenAPI Portal includes the --region option by default. When you run the command locally, the Alibaba Cloud CLI uses the specified region and ignores the region settings in your default identity credentials and environment variables. You can keep or remove this option as needed.

Call an API

Command structure

The general command structure for the Alibaba Cloud CLI is as follows. For more information, see Generate and call a command.

aliyun <command> <subcommand> [options and parameters]

Common command options

In the Alibaba Cloud CLI, you can use command-line options to change the default behavior of a command or add features. Common command options are as follows:

  • --profile <profileName>: If you use the --profile option and specify a valid configuration name profileName, the Alibaba Cloud CLI ignores the default identity credentials and environment variables. The CLI uses the specified configuration to run the command.

  • --help: To get help information for a command, enter the --help option at the command level. For more information, see Get help information.

For more information, see Command-line options.

Examples

Example 1: The following code example shows how to use the --help option to get a list of CloudSSO APIs that you can call using the Alibaba Cloud CLI. You can also view the supported APIs in API overview.

  1. Run the command.

    aliyun cloudsso --help
  2. The output is displayed.

    Usage:
      aliyun cloudsso <ApiName> --parameter1 value1 --parameter2 value2 ...
    Product: cloudsso (云SSO)
    Version: 2021-05-15
    Available Api List:
      AddExternalSAMLIdPCertificate                Adds a Security Assertion Markup Language (SAML) signing certificate.
      AddPermissionPolicyToAccessConfiguration     Adds a policy to an access configuration.
      AddUserToGroup                               Adds a user to a group.
      ClearExternalSAMLIdentityProvider            Clears the configurations of a Security Assertion Markup Language (SAML) identity provider (IdP).
      CreateAccessAssignment                       Assigns access permissions on an account in your resource directory to a user or a group by using access configuration.
      CreateAccessConfiguration                    Creates an access configuration.
      CreateDirectory                              Creates a directory.
      CreateGroup                                  Creates a group.

Example 2: The following code example shows how to use the Alibaba Cloud CLI to call the CreateUser command in CloudSSO to create a CloudSSO user named Alice.

  1. Run the command.

    aliyun cloudsso CreateUser --region cn-shanghai --DirectoryId 'd-00fc2p61****' --UserName Alice
  2. The output is displayed.

    {
      "User": {
        "Status": "Enabled",
        "UserName": "Alice",
        "Email": "",
        "Description": "",
        "UserId": "u-004ds*************",
        "FirstName": "",
        "CreateTime": "2024-05-16T10:49:27Z",
        "ProvisionType": "Manual",
        "DisplayName": "",
        "UpdateTime": "2024-05-16T10:49:27Z",
        "LastName": ""
      },
      "RequestId": "E5D5256C-3981-5EB8-AB9C-30DF641D4DC9"
    }
    Note

    If a CloudSSO API call returns an error, check whether the request parameters and their values are correct based on the returned error code.

    You can also record the RequestID or the SDK error message from the response and use the Alibaba Cloud OpenAPI Diagnostic Platform for self-service diagnosis.