The following table describes common scenarios and the API operations that can be called in those scenarios.
Scenario | Description | API selection | Difference |
---|---|---|---|
User management | Manage Resource Access Management (RAM) users, AccessKey pairs, logon passwords, and multi-factor authentication (MFA) devices. |
|
|
User group management | Manage RAM user groups, and add or remove RAM users in RAM user groups. | ||
Security settings | Manage password policies, global security preferences, default domain names, user credential reports, and security reports of Alibaba Cloud accounts. | ||
Policy management | Manage policies and grant permissions to or revoke permissions from a RAM user, RAM role, or RAM user group. |
|
|
Role management | Manage RAM roles. | ||
Role usage | Assume a RAM role by using a Security Token Service (STS) token. | STS API | None. |
Single sign-on (SSO) management | Manage identity providers (IdPs) for user-based SSO and role-based SSO. | IMS API | None. |
Role-based SSO usage | Use an STS token for role-based SSO. | STS API | None. |
Open authorization (OAuth ) management | Manage applications and application secrets. | IMS API | None. |