Authorize devices

更新时间:
复制 MD 格式

You can authorize a device to another Alibaba Cloud account. After authorization, the grantee can view the device, perform operations on it, and use the product to which it belongs.

Prerequisites

  • The product to which the device belongs is published.

    If the product is not published, publish it first. On the Product Details page, click Publish in the upper-right corner. Check that the product is ready to be published, and then click Publish.

  • Your Alibaba Cloud account is added to the whitelist.

    Important

    You can no longer add accounts to the whitelist.

Limitations

  • Device authorization is supported only between legacy public instances in the China (Shanghai) region.

    For more information, see Instance overview.

  • You can revoke the authorization at any time.

  • Authorizing a device to another Alibaba Cloud account does not change the device ownership. The grantee can view device information (excluding the device secret and TSL model snapshot data), information about the product, and perform operations on the device.

  • For the same product or device, you can use the authorization and transfer features at the same time, but not the authorization and distribution features.

Procedure for the grantor

  1. Log on to the IoT Platform console.

  2. On the Overview page, find the instance that you want to manage and click the instance ID or instance name.

  3. In the left-side navigation pane, choose Device Assignment > Device Authorization.
  4. On the Device authorization page, click Authorize Device.

  5. In the dialog box, select the device to authorize, enter the grantee's Alibaba Cloud account ID, and then click OK.

    Parameter

    Description

    Product

    Select the device's product.

    Device

    Select the device to authorize.

    Authorization Method

    Select whether to authorize by target account name or target account ID, and then enter the grantee's Alibaba Cloud account name or ID.

    To find their account ID, the grantee can log on to the Alibaba Cloud official website with their primary account and click the profile icon in the upper-right corner.

  6. Click OK to complete the authorization.

    The grantee can now view and operate on the device, and also view the product to which it belongs.

    Authorized devices are displayed on the Device tab, and their corresponding products are displayed on the Product tab.

    The list includes columns such as Authorized User, Alibaba Cloud account ID, DeviceName, ProductKey, and Authorization Time. In the Actions column, you can click Revoke Authorization to revoke the device's permissions.

  7. (Optional) In the list, find the device or product and click Revoke Authorization. In the message that appears, confirm the action. The grantee immediately loses the corresponding permissions.

    Note

    To revoke authorization for a product, you must first revoke the authorization for all of its devices.

View authorized products and devices

After the authorization is complete, the grantee can view the authorized devices and their products.

  1. As the grantee, log on to the IoT Platform console.

  2. On the Overview page, find the instance that you want to manage and click the instance ID or instance name.

  3. In the left-side navigation pane, choose Device Management > Products.
  4. On the Product page, click the Authorized products tab. Then, on the Product list tab, click User in the upper-right corner to view products authorized for your account.

  5. Find the product and click View in the Actions column. On the Product details page, you can view the product's basic information, Topic categories, and TSL model, and also configure server-side subscriptions.

    Note

    If a grantee needs to use an AMQP server-side subscription for an authorized product or device, the grantee must configure the AMQP server-side subscription.

    The AMQP server-side subscription configurations of the grantee and the grantor do not affect each other.

  6. On the Product details page, choose Device management > Authorized device list.

    The authorized device list displays columns such as DeviceName, Product, Node type, Status, and Last online time. You can click View to see the device details.

  7. Find the device and click View in the Actions column. On the Device details page, you can view device information and Topic lists.

    Important

    Currently, grantees cannot view the TSL model snapshot data of authorized devices. The TSL data tab does not display the snapshot data reported by the device.

    This page also includes the Device shadow, File management, Log Service, and Online debug tabs. The Device information tab displays basic device properties (such as ProductKey, DeviceName, Node Type, Authentication Method, Creation Time, Activation Time, Last Online Time, and Current Status), extended device information, and tag information.