You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell或Azure CLI创建Azure API Management授权/凭据提供商

Azure API Management 授权/凭据提供商的PowerShell与Azure CLI创建方案

PowerShell 实现方式

创建授权服务器(OAuth2/OpenID Connect)

使用Az.ApiManagement模块的New-AzApiManagementAuthorizationServer命令,示例如下:

# 连接Azure账户
Connect-AzAccount

# 定义参数
$resourceGroupName = "你的资源组名称"
$apiServiceName = "你的APIM实例名称"
$authServerName = "自定义授权服务器名称"
$clientId = "客户端ID"
$clientSecret = "客户端密钥"
$authorizationEndpoint = "https://你的授权端点"
$tokenEndpoint = "https://你的令牌端点"
$clientRegistrationEndpoint = "https://你的客户端注册端点(可选)"

# 创建授权服务器
New-AzApiManagementAuthorizationServer -ResourceGroupName $resourceGroupName `
    -ServiceName $apiServiceName `
    -Name $authServerName `
    -ClientId $clientId `
    -ClientSecret $clientSecret `
    -AuthorizationEndpoint $authorizationEndpoint `
    -TokenEndpoint $tokenEndpoint `
    -ClientRegistrationEndpoint $clientRegistrationEndpoint `
    -GrantType "authorization_code" # 支持authorization_code/client_credentials等类型

自定义凭据提供商(无直接命令时用REST API调用)

如果需要创建自定义凭据提供商,可通过PowerShell调用Azure REST API实现:

# 获取APIM实例的访问令牌
$accessToken = (Get-AzAccessToken -ResourceUrl "https://management.azure.com").Token

# 定义API请求参数
$subscriptionId = "你的订阅ID"
$resourceGroupName = "你的资源组名称"
$apiServiceName = "你的APIM实例名称"
$credentialProviderName = "自定义凭据提供商名称"
$apiUrl = "https://management.azure.com/subscriptions/$subscriptionId/resourceGroups/$resourceGroupName/providers/Microsoft.ApiManagement/service/$apiServiceName/credentials/$credentialProviderName?api-version=2023-03-01-preview"

# 构建请求体(以OAuth2凭据为例)
$requestBody = @{
    properties = @{
        type = "OAuth2"
        credentials = @{
            clientId = "客户端ID"
            clientSecret = "客户端密钥"
        }
        oauth2 = @{
            authorizationEndpoint = "https://你的授权端点"
            tokenEndpoint = "https://你的令牌端点"
            scope = "所需权限范围"
        }
    }
} | ConvertTo-Json -Depth 10

# 发送POST请求创建凭据提供商
Invoke-RestMethod -Uri $apiUrl -Method Put -Headers @{
    "Authorization" = "Bearer $accessToken"
    "Content-Type" = "application/json"
} -Body $requestBody

Azure CLI 实现方式

创建授权服务器

使用az apim authorization-server create命令,示例如下:

# 登录Azure账户
az login

# 创建授权服务器
az apim authorization-server create \
    --resource-group "你的资源组名称" \
    --service-name "你的APIM实例名称" \
    --name "自定义授权服务器名称" \
    --client-id "客户端ID" \
    --client-secret "客户端密钥" \
    --authorization-endpoint "https://你的授权端点" \
    --token-endpoint "https://你的令牌端点" \
    --grant-types "authorization_code" \
    --client-registration-endpoint "https://你的客户端注册端点(可选)"

自定义凭据提供商(无直接命令时用REST API调用)

通过Azure CLI调用REST API,先获取访问令牌再发送请求:

# 获取访问令牌
access_token=$(az account get-access-token --resource "https://management.azure.com" --query accessToken -o tsv)

# 定义参数
subscription_id=$(az account show --query id -o tsv)
resource_group="你的资源组名称"
apim_name="你的APIM实例名称"
credential_name="自定义凭据提供商名称"
api_url="https://management.azure.com/subscriptions/$subscription_id/resourceGroups/$resource_group/providers/Microsoft.ApiManagement/service/$apim_name/credentials/$credential_name?api-version=2023-03-01-preview"

# 构建请求体
request_body='{
    "properties": {
        "type": "OAuth2",
        "credentials": {
            "clientId": "客户端ID",
            "clientSecret": "客户端密钥"
        },
        "oauth2": {
            "authorizationEndpoint": "https://你的授权端点",
            "tokenEndpoint": "https://你的令牌端点",
            "scope": "所需权限范围"
        }
    }
}'

# 发送请求
curl -X PUT "$api_url" \
    -H "Authorization: Bearer $access_token" \
    -H "Content-Type: application/json" \
    -d "$request_body"

注意事项

  • 确保使用的PowerShell Az.ApiManagement模块版本为最新(可通过Update-Module -Name Az.ApiManagement更新)
  • Azure CLI需升级至最新版本(az upgrade),部分命令仅在新版本中支持
  • 预览版API可能存在变动,使用时请确认对应API版本的兼容性

内容的提问来源于stack exchange,提问作者One Developer

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.06 10:10:18