Import RAM users through the Qoder CN RAM OAuth application

更新时间:
复制 MD 格式

This topic describes how to batch-import RAM users under an Alibaba Cloud account into the Qoder CN enterprise subscription (Teams or Enterprise edition) member list through the Qoder CN RAM OAuth application.

Qoder CN enterprise subscriptions (Teams and Enterprise editions) support three methods for adding members: SSO, email invitation, and Alibaba Cloud RAM sign-in.

If you want to import RAM users under an Alibaba Cloud account ID into your enterprise subscription, follow the instructions in this topic.

Qoder CN RAM OAuth application

Alibaba Cloud RAM (Resource Access Management) supports user authentication and application authorization through OAuth applications using the OAuth 2.0 and OAuth 2.1 protocols.

Qoder CN has published an official application in the RAM OAuth marketplace. After authorization, users can sign in to Qoder CN products (such as Qoder CN Desktop, Qoder CN CLI, and the Qoder CN JetBrains plugin) with their RAM identities.

Installation and activation steps:

1. The enterprise instance administrator signs in to the Alibaba Cloud RAM console using the Alibaba Cloud account ID, and goes to OAuth Applications > Third-Party Applications.

image.png

  1. After installation, the Qoder CN application appears in the application list.image.png

  2. Open the Qoder CN application and configure the assignment type: assign to all users or assign on demand.

image.png

  • Assign to all: All RAM users under the Alibaba Cloud account ID can sign in to Qoder CN applications. If the number of seats is less than the number of RAM users, seats are allocated on a first-come, first-served basis.

  • Assign on demand: You create an assignment and select specific RAM users to authorize them to sign in to the Qoder CN website and applications using their Alibaba Cloud RAM accounts.

  1. The administrator signs in to the Qoder CN website, goes to Settings, and then goes to Security & Identity. Select Alibaba Cloud RAM Sign-in and enable it.

image.png

5. Click Settings, confirm that the first two steps shown are completed, and then click Confirm and Enable.

image.png

Sign-in steps:

The administrator instructs the relevant RAM users to select "Enterprise Member RAM Account Sign-in", which redirects them to the Alibaba Cloud user authorization page.

image.png

image.png

FAQ

Activation

Q: Why is the Settings button for Alibaba Cloud RAM Sign-in grayed out?

A: A grayed-out button indicates that the Alibaba Cloud primary account you are using has already enabled Alibaba Cloud RAM Sign-in in another enterprise instance.

A single Alibaba Cloud primary account's Qoder CN OAuth application can only be bound to one enterprise instance at a time. When it is already in use by another instance, your current instance cannot enable it.

Q: Can a single Alibaba Cloud account ID enable RAM Sign-in for multiple enterprise instances simultaneously?

A: You can purchase multiple enterprise subscriptions under the same Alibaba Cloud account ID through the Alibaba Cloud console. However, the Qoder CN admin panel generates a different configuration administrator account (such as rootXX) for each enterprise subscription.

Q: Can RAM users under a single Alibaba Cloud account ID join multiple enterprise instances (i.e., be members of multiple organizations)?

A: No. The core constraint of Alibaba Cloud RAM Sign-in is cross-instance mutual exclusion:

  • A single Alibaba Cloud primary account's Qoder CN OAuth application can only be bound to one enterprise instance at any given time.

  • If instance A has already enabled it, instances B and C using the same Alibaba Cloud primary account will show "Cannot enable".

Q: I want to enable RAM Sign-in for my current instance, but it says the application is already in use. What should I do?

A: Follow these steps:

  1. Identify which enterprise instance currently has Alibaba Cloud RAM Sign-in enabled for this primary account.

  2. Go to that enterprise instance and disable Alibaba Cloud RAM Sign-in in its settings.

  3. After disabling, the primary account is released. Return to your current instance and click Settings to enable it.

In short: to enable it on a new instance, you must first disable it on the original instance.

Deactivation

Q: What happens after I disable Alibaba Cloud RAM Sign-in?

A: The change takes effect immediately. All members of this enterprise instance will no longer be able to sign in to Qoder CN using their Alibaba Cloud RAM accounts.

Before disabling, make sure to notify affected members so they can switch to an alternative sign-in method.

Q: After disabling RAM Sign-in, is the OAuth application in the Alibaba Cloud RAM console deleted?

A: No. Disabling only unbinds the current enterprise instance from the OAuth application. The application itself remains in your Alibaba Cloud RAM console.

This makes it easy to re-enable later or switch the primary account to a different enterprise instance.

Q: Can I re-enable RAM Sign-in after disabling it?

A: Yes. As long as the primary account's OAuth application is not in use by another instance, you can re-enable it at any time by clicking Settings in your current instance.

Q: If none of our enterprise instances will use RAM Sign-in anymore, how do we fully clean up?

A: If none of your enterprise instances require Alibaba Cloud RAM Sign-in, we recommend uninstalling the Qoder CN OAuth application from the Alibaba Cloud RAM console for a complete cleanup.

After uninstalling, the primary account is fully released, and any enterprise instance can re-enable it in the future.

Q: What is the difference between "disabling" Alibaba Cloud RAM Sign-in in the Qoder CN admin panel and "uninstalling the OAuth application" in the Alibaba Cloud console?

A: Disabling releases the lock but preserves the application; uninstalling completely removes the application.

Action

Scope

Result

Disable

(in the Qoder CN enterprise instance)

Unbinds the current instance only

Members of this instance can no longer sign in with RAM. The OAuth application is preserved, the primary account is released, and other instances can enable it.

Uninstall OAuth application

(in the RAM console)

Alibaba Cloud primary account level

Completely removes the application. No instance can use it until it is reinstalled.