WSO2 APIM 4.1.0:如何通过API创建角色?求有效API文档
WSO2 APIM 4.1.0 无UI创建用户/角色方案
关键说明
WSO2 APIM 4.1.0的用户、角色管理已统一使用Identity Server的SCIM 2.0标准API,旧版Carbon Portal API已不再适用,直接调用SCIM接口即可完成操作。
前置步骤
- 使用具备用户管理权限的账号(如admin)
- 获取认证令牌:调用APIM的OAuth2令牌端点,示例命令:
curl -k -d "grant_type=password&username=admin&password=admin&scope=internal_user_mgt_view internal_user_mgt_create" -H "Content-Type: application/x-www-form-urlencoded" https://<你的APIM主机>:9443/oauth2/token
创建角色
发送POST请求到https://<你的APIM主机>:9443/scim2/Roles,请求头需携带Authorization: Bearer <获取到的令牌>和Content-Type: application/json,请求体示例:
{ "displayName": "自定义APIM角色", "schemas": ["urn:ietf:params:scim:schemas:core:2.0:Role"], "attributes": [ { "name": "apim_role", "value": "true" } ] }
创建用户
发送POST请求到https://<你的APIM主机>:9443/scim2/Users,请求头同上,请求体示例(需替换<角色ID>为创建角色时返回的ID):
{ "schemas": ["urn:ietf:params:scim:schemas:core:2.0:User"], "userName": "new_user@example.com", "password": "StrongPass123!", "emails": [ { "value": "new_user@example.com", "primary": true } ], "roles": [ { "value": "<角色ID>" } ] }
注意点
- 测试时可添加
-k参数跳过SSL证书验证 - 令牌请求的
scope需包含用户管理相关权限(如internal_user_mgt_create) - 角色的
apim_role属性设为true,才能被APIM识别为平台专属角色
内容的提问来源于stack exchange,提问作者Oussama Nairi
相关产品推荐
相关产品推荐

