Cloudera IAM API

Users, machine users, groups, roles, resource roles, access keys, SAML identity providers and SCIM access tokens for a CDP account. 79 operations.

Operations 79

POST /iam/getUser Gets information on a user. #
POST /iam/listUsers Lists users. #
POST /iam/createUser Creates a user in CDP. #
POST /iam/updateUser Updates a user. #
POST /iam/deleteUser Deletes a user and all associated resources. #
POST /iam/createUserAccessKey Creates a new access key for a user. #
POST /iam/createMachineUserAccessKey Creates a new access key for a machine user. #
POST /iam/deleteAccessKey Deletes an access key. #
POST /iam/updateAccessKey Updates an access key. #
POST /iam/getAccessKey Gets information on an access key. #
POST /iam/listAccessKeys Lists access keys. #
POST /iam/listRoles Lists all the available roles. #
POST /iam/listResourceRoles Lists all the available resource roles. #
POST /iam/setAccountMessages Set messages for an account. #
POST /iam/getAccountMessages Get account messages. #
POST /iam/assignUserRole Assign a role to a user. #
POST /iam/unassignUserRole Unassign a role from a user. #
POST /iam/assignUserResourceRole Assign a resource role to a user. #
POST /iam/unassignUserResourceRole Unassign a resource role from a user. #
POST /iam/listUserAssignedRoles Lists the user's assigned roles. #
POST /iam/listUserAssignedResourceRoles Lists a user's assigned resource roles. #
POST /iam/assignMachineUserRole Assign a role to a machine user. #
POST /iam/unassignMachineUserRole Unassign a role from a machine user. #
POST /iam/assignMachineUserResourceRole Assign a resource role to a machine user. #
POST /iam/unassignMachineUserResourceRole Unassign a resource role from a machine user. #
POST /iam/listMachineUserAssignedRoles Lists the machine user's assigned roles. #
POST /iam/listMachineUserAssignedResourceRoles Lists a machine user's assigned resource roles. #
POST /iam/listResourceAssignees List the resource assignees and their respective resource roles for the resource. #
POST /iam/createMachineUser Create a machine user. #
POST /iam/listMachineUsers Lists machine users. #
POST /iam/deleteMachineUser Delete a machine user. #
POST /iam/createSamlProvider Creates a SAML provider in CDP. #
POST /iam/deleteSamlProvider Deletes a SAML provider in CDP account. #
POST /iam/listSamlProviders Lists SAML providers in CDP account. #
POST /iam/describeSamlProvider Describes one SAML provider. #
POST /iam/updateSamlProvider Updates a SAML provider in CDP. #
POST /iam/enableClouderaSSOLogin Enables interactive login using Cloudera SSO for this account. #
POST /iam/disableClouderaSSOLogin Disables interactive login using Cloudera SSO for this account. #
POST /iam/getAccount Retrieves information about the CDP account. #
POST /iam/createGroup Create a group. #
POST /iam/deleteGroup Delete a group. #
POST /iam/listGroups Lists groups. #
POST /iam/updateGroup Update a group. #
POST /iam/addUserToGroup Add a user to a group. #
POST /iam/addMachineUserToGroup Add a machine user to group. #
POST /iam/removeUserFromGroup Remove a user from a group. #
POST /iam/removeMachineUserFromGroup Remove a machine user from a group. #
POST /iam/listGroupMembers List the members of a group. #
POST /iam/listGroupsForUser List the groups that the user belongs to. #
POST /iam/listGroupsForMachineUser List the groups that the machine user belongs to. #
POST /iam/assignGroupRole Assign a role to a group. #
POST /iam/unassignGroupRole Unassign a role from a group. #
POST /iam/assignGroupResourceRole Assign a resource role to a group. #
POST /iam/unassignGroupResourceRole Unassign a resource role from a group. #
POST /iam/listGroupAssignedRoles Lists the group's assigned roles. #
POST /iam/listGroupAssignedResourceRoles Lists a group's assigned resource roles. #
POST /iam/setWorkloadPassword Set the workload password for an actor. #
POST /iam/unsetWorkloadPasswordMinLifetime Removes workload password minimum lifetime date for an actor. #
POST /iam/setWorkloadPasswordPolicy Set the workload password policy for the account. #
POST /iam/unsetWorkloadPasswordPolicy Unset workload password policy for the account. #
POST /iam/addSshPublicKey Adds an SSH public key for an actor. #
POST /iam/listSshPublicKeys Lists SSH public keys for an actor. #
POST /iam/describeSshPublicKey Describes an SSH public key for an actor. #
POST /iam/deleteSshPublicKey Deletes an SSH public key for an actor. #
POST /iam/updateLdapProvider UpdateLdapProvider #
POST /iam/createLdapProvider CreateLdapProvider #
POST /iam/getDefaultIdentityProvider Retrieves the CRN of the default identity provider. #
POST /iam/setDefaultIdentityProvider Sets the default identity provider. #
POST /iam/generateWorkloadAuthToken Generates an authentication token for workload APIs. #
POST /iam/createScimAccessToken Creates a SCIM access token for a SCIM enabled identity provider. #
POST /iam/listScimAccessTokens Lists SCIM access tokens for a SCIM enabled identity provider. #
POST /iam/deleteScimAccessToken Deletes a SCIM access token. #
POST /iam/unlockUserInControlPlane Unlocks user in the CDP control plane. #
POST /iam/unlockMachineUserInControlPlane Unlocks machine user in the CDP control plane. #
POST /iam/setSamlAuthnRequestSigningKey Sets the SAML AuthnRequest signing key and verification certificate. #
POST /iam/migrateUsersToIdentityProvider Migrates all users from an identity provider connector to a different identity provider connector. #
POST /iam/setSamlResponseDecryptionKey Sets encryption certificate and decryption key for SAML response sent from customer's Identity Provider to CDP. #
POST /iam/enableUserWorkloadPasswordChangedNotifications Enables sending user workload password changed email notifications for the account. #
POST /iam/disableUserWorkloadPasswordChangedNotifications Disables sending user workload password changed email notifications for the account. #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/cloudera-iam-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

cloudera-iam-openapi.yml Raw ↑
swagger: '2.0'
x-endpoint-name: iam
x-products: ALTUS,CDP
x-form-factors: public,private
x-altus-releases: PUBLIC
x-cdp-releases: PUBLIC
x-audit: true
x-extensions: pvcapipath
info:
  version: 0.9.163
  title: Cloudera IAM Service
  license:
    name: Apache 2.0
  description: Cloudera CDP IAM is a web service that you can use to manage users and user permissions under your CDP account.
  termsOfService: https://www.cloudera.com/legal/commercial-terms-and-conditions.html
schemes:
  - https
consumes:
  - application/json
produces:
  - application/json
paths:
  /iam/getUser:
    post:
      summary: Gets information on a user.
      description: Gets information on a user. If no user name is specified. The user name is determined from the access key used to make the request.
      operationId: getUser
      x-form-factors: public,private
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/GetUserRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/GetUserResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/listUsers:
    post:
      summary: Lists users.
      description: Lists users.
      operationId: listUsers
      x-form-factors: public,private
      x-right: iam/listUsers
      x-paging-default-max-items: 100
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/ListUsersRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/ListUsersResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/createUser:
    post:
      summary: Creates a user in CDP.
      description: Creates a user in CDP.
      operationId: createUser
      x-form-factors: public,private
      x-right: iam/createUser
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/CreateUserRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/CreateUserResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/updateUser:
    post:
      summary: Updates a user.
      description: Updates a user. Updates request fields provided. An error is returned if no field updates are defined in the request.
      operationId: updateUser
      x-right: iam/updateUser
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/UpdateUserRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/UpdateUserResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/deleteUser:
    post:
      summary: Deletes a user and all associated resources.
      description: Deletes a user. This includes deleting all associated access keys and unassigning all roles and resource roles assigned to the user. The user is also removed from all groups it belongs to. If the call succeeds the user will not be able to login interactively, or use any access keys to access the CDP control plane. This feature is under development and some resources may be left behind after a successful call. Note that user-sync is not triggered yet by this call and the caller must trigger that to ensure that the user loses access to all environments as soon as possible.
      operationId: deleteUser
      x-form-factors: public,private
      x-right: iam/deleteUser
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/DeleteUserRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/DeleteUserResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/createUserAccessKey:
    post:
      summary: Creates a new access key for a user.
      description: Creates a new access key for a user.
      operationId: createUserAccessKey
      x-form-factors: public,private
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/CreateUserAccessKeyRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/CreateUserAccessKeyResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/createMachineUserAccessKey:
    post:
      summary: Creates a new access key for a machine user.
      description: Creates a new access key for a machine user.
      operationId: createMachineUserAccessKey
      x-form-factors: public,private
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/CreateMachineUserAccessKeyRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/CreateMachineUserAccessKeyResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/deleteAccessKey:
    post:
      summary: Deletes an access key.
      description: Deletes an access key.
      operationId: deleteAccessKey
      x-form-factors: public,private
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/DeleteAccessKeyRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/DeleteAccessKeyResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/updateAccessKey:
    post:
      summary: Updates an access key.
      description: Updates an access key.
      operationId: updateAccessKey
      x-form-factors: public,private
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/UpdateAccessKeyRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/UpdateAccessKeyResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/getAccessKey:
    post:
      summary: Gets information on an access key.
      description: Gets information on an access key. If no access key ID is specified. Information on the access key used to make the request is returned.
      operationId: getAccessKey
      x-form-factors: public,private
      x-right: iam/getAccessKey
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/GetAccessKeyRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/GetAccessKeyResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/listAccessKeys:
    post:
      summary: Lists access keys.
      description: Lists access keys.
      operationId: listAccessKeys
      x-form-factors: public,private
      x-right: iam/listAccessKeys
      x-paging-default-max-items: 100
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/ListAccessKeysRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/ListAccessKeysResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/listRoles:
    post:
      summary: Lists all the available roles.
      description: Lists all the available roles. Roles grant rights to users via policies that are attached to the roles.
      operationId: listRoles
      x-form-factors: public,private
      x-right: iam/listRoles
      x-paging-default-max-items: 100
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/ListRolesRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/ListRolesResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/listResourceRoles:
    post:
      summary: Lists all the available resource roles.
      description: Lists all the available resource roles. Resource roles grant rights over certain resources.
      operationId: listResourceRoles
      x-form-factors: public,private
      x-right: iam/listResourceRoles
      x-paging-default-max-items: 100
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/ListResourceRolesRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/ListResourceRolesResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/setAccountMessages:
    post:
      summary: Set messages for an account.
      description: Set messages for an account.
      operationId: setAccountMessages
      x-form-factors: public
      x-right: iam/setAccountMessages
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/SetAccountMessagesRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/SetAccountMessagesResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/getAccountMessages:
    post:
      summary: Get account messages.
      description: Get account messages.
      operationId: getAccountMessages
      x-form-factors: public
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/GetAccountMessagesRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/GetAccountMessagesResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/assignUserRole:
    post:
      summary: Assign a role to a user.
      description: Assign a role to a user. If the role is already assigned to the user the request will fail.
      operationId: assignUserRole
      x-form-factors: public,private
      x-right: iam/assignRole
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/AssignUserRoleRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/AssignUserRoleResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/unassignUserRole:
    post:
      summary: Unassign a role from a user.
      description: Unassign a role from a user. If the role is not currently assigned to the user the request will fail.
      operationId: unassignUserRole
      x-form-factors: public,private
      x-right: iam/unassignRole
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/UnassignUserRoleRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/UnassignUserRoleResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/assignUserResourceRole:
    post:
      summary: Assign a resource role to a user.
      description: Assign a resource role to a user. If the resource role is already assigned to the user the request will fail.
      operationId: assignUserResourceRole
      x-form-factors: public,private
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/AssignUserResourceRoleRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/AssignUserResourceRoleResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/unassignUserResourceRole:
    post:
      summary: Unassign a resource role from a user.
      description: Unassign a resource role from a user. If the resource role is not currently assigned to the user the request will fail.
      operationId: unassignUserResourceRole
      x-form-factors: public,private
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/UnassignUserResourceRoleRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/UnassignUserResourceRoleResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/listUserAssignedRoles:
    post:
      summary: Lists the user's assigned roles.
      description: Lists the user's assigned roles.
      operationId: listUserAssignedRoles
      x-form-factors: public,private
      x-right: iam/listAssignedRoles
      x-paging-default-max-items: 100
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/ListUserAssignedRolesRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/ListUserAssignedRolesResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/listUserAssignedResourceRoles:
    post:
      summary: Lists a user's assigned resource roles.
      description: Lists a user's assigned resource roles.
      operationId: listUserAssignedResourceRoles
      x-form-factors: public,private
      x-right: iam/listAssignedResourceRoles
      x-paging-default-max-items: 100
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/ListUserAssignedResourceRolesRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/ListUserAssignedResourceRolesResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/assignMachineUserRole:
    post:
      summary: Assign a role to a machine user.
      description: Assign a role to a machine user. If the role is already assigned to the machine user the request will fail.
      operationId: assignMachineUserRole
      x-form-factors: public,private
      x-right: iam/assignRole
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/AssignMachineUserRoleRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/AssignMachineUserRoleResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/unassignMachineUserRole:
    post:
      summary: Unassign a role from a machine user.
      description: Unassign a role from a machine user. If the role is not currently assigned to the machine user the request will fail.
      operationId: unassignMachineUserRole
      x-form-factors: public,private
      x-right: iam/unassignRole
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/UnassignMachineUserRoleRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/UnassignMachineUserRoleResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/assignMachineUserResourceRole:
    post:
      summary: Assign a resource role to a machine user.
      description: Assign a resource role to a machine user. If the resource role is already assigned to the machine user the request will fail.
      operationId: assignMachineUserResourceRole
      x-form-factors: public,private
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/AssignMachineUserResourceRoleRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/AssignMachineUserResourceRoleResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/unassignMachineUserResourceRole:
    post:
      summary: Unassign a resource role from a machine user.
      description: Unassign a resource role from a machine user. If the resource role is not currently assigned to the machine user the request will fail.
      operationId: unassignMachineUserResourceRole
      x-form-factors: public,private
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/UnassignMachineUserResourceRoleRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/UnassignMachineUserResourceRoleResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/listMachineUserAssignedRoles:
    post:
      summary: Lists the machine user's assigned roles.
      description: Lists the machine user's assigned roles.
      operationId: listMachineUserAssignedRoles
      x-form-factors: public,private
      x-right: iam/listAssignedRoles
      x-paging-default-max-items: 100
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/ListMachineUserAssignedRolesRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/ListMachineUserAssignedRolesResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/listMachineUserAssignedResourceRoles:
    post:
      summary: Lists a machine user's assigned resource roles.
      description: Lists a machine user's assigned resource roles.
      operationId: listMachineUserAssignedResourceRoles
      x-form-factors: public,private
      x-right: iam/listAssignedResourceRoles
      x-paging-default-max-items: 100
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/ListMachineUserAssignedResourceRolesRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/ListMachineUserAssignedResourceRolesResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/listResourceAssignees:
    post:
      summary: List the resource assignees and their respective resource roles for the resource.
      description: List the resource assignees and their respective resource roles for the resource.
      operationId: listResourceAssignees
      x-form-factors: public,private
      x-right: iam/listResourceAssignees
      x-paging-default-max-items: 100
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/ListResourceAssigneesRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/ListResourceAssigneesResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/createMachineUser:
    post:
      summary: Create a machine user.
      description: Creates a machine user in the account. A machine user can be used to access CDP API. A machine user can have access keys associated with it and can be assigned roles and resource roles. A machine user cannot login to the CDP console.
      operationId: createMachineUser
      x-form-factors: public,private
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/CreateMachineUserRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/CreateMachineUserResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/listMachineUsers:
    post:
      summary: Lists machine users.
      description: Lists machine users in the account.
      operationId: listMachineUsers
      x-form-factors: public,private
      x-right: iam/listMachineUsers
      x-paging-default-max-items: 100
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/ListMachineUsersRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/ListMachineUsersResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/deleteMachineUser:
    post:
      summary: Delete a machine user.
      description: Deletes a machine user. This includes deleting all associated access keys and unassigning all roles and resource roles assigned to the machine user. The machine user is also removed from all groups it belongs to. If the call succeeds the machine user will not be able to use any access keys to access the CDP control plane. Note that user-sync is not triggered yet by this call and the caller must trigger that to ensure that the machine user loses access to all environments as soon as possible.
      operationId: deleteMachineUser
      x-form-factors: public,private
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/DeleteMachineUserRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/DeleteMachineUserResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/createSamlProvider:
    post:
      summary: Creates a SAML provider in CDP.
      description: Creates a SAML provider in CDP.
      operationId: createSamlProvider
      x-form-factors: public,private
      x-right: iam/createSamlProvider
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/CreateSamlProviderRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/CreateSamlProviderResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/deleteSamlProvider:
    post:
      summary: Deletes a SAML provider in CDP account.
      description: Deletes a SAML provider in CDP account.
      operationId: deleteSamlProvider
      x-form-factors: public,private
      x-right: iam/deleteSamlProvider
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/DeleteSamlProviderRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/DeleteSamlProviderResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/listSamlProviders:
    post:
      summary: Lists SAML providers in CDP account.
      description: Lists SAML providers in CDP account.
      operationId: listSamlProviders
      x-form-factors: public,private
      x-right: iam/listSamlProviders
      x-paging-default-max-items: 100
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/ListSamlProvidersRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/ListSamlProvidersResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/describeSamlProvider:
    post:
      summary: Describes one SAML provider.
      description: Describes one SAML provider.
      operationId: describeSamlProvider
      x-form-factors: public,private
      x-right: iam/listSamlProviders
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/DescribeSamlProviderRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/DescribeSamlProviderResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/updateSamlProvider:
    post:
      summary: Updates a SAML provider in CDP.
      description: Updates a SAML provider in CDP.
      operationId: updateSamlProvider
      x-form-factors: public,private
      x-right: iam/updateSamlProvider
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/UpdateSamlProviderRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/UpdateSamlProviderResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/enableClouderaSSOLogin:
    post:
      summary: Enables interactive login using Cloudera SSO for this account.
      description: Enables interactive login using Cloudera SSO for this account. This is a no-op if login using Cloudera SSO are already enabled.
      operationId: enableClouderaSSOLogin
      x-form-factors: public
      x-right: iam/manageClouderaSSOLogin
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/EnableClouderaSSOLoginRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/EnableClouderaSSOLoginResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/disableClouderaSSOLogin:
    post:
      summary: Disables interactive login using Cloudera SSO for this account.
      description: Disables interactive login using Cloudera SSO for this account. When disabled, only users who are designated account administrators will be able to use Cloudera SSO to interactively login to the CDP account. All other users will only be able to interactively login using SAML providers defined for the account. This is a no-op if login using Cloudera SSO are already disabled.
      operationId: disableClouderaSSOLogin
      x-form-factors: public
      x-right: iam/manageClouderaSSOLogin
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/DisableClouderaSSOLoginRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/DisableClouderaSSOLoginResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/getAccount:
    post:
      summary: Retrieves information about the CDP account.
      description: Retrieves information about the CDP account.
      operationId: getAccount
      x-form-factors: public,private
      x-mutating: false
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/GetAccountRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/GetAccountResponse'
        default:
          description: The default response on an error.
          schema:
            $ref: '#/definitions/Error'
  /iam/createGroup:
    post:
      summary: Create a group.
      description: Create a group. A group is a named collection of users and machine users. Roles and resource roles can be assigned to a group impacting all members of the group.
      operationId: createGroup
      x-form-factors: public,private
      x-right: iam/createGroup
      x-mutating: true
      parameters:
        - name: input
          in: body
          required: true
          schema:
            $ref: '#/definitions/CreateGroupRequest'
      responses:
        200:
          description: Expected response to a valid request.
          schema:
            $ref: '#/definitions/CreateGroupResponse'
        default:
          description: The default response on an e

# --- truncated at 32 KB (161 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/cloudera/refs/heads/main/openapi/cloudera-iam-openapi.yml