如何通过OneLogin API更新用户应用ID与密码?寻求自动化方案
Absolutely—you can automate this manual process using OneLogin's REST API! The functionality you need is covered by their User App Assignments and Credential Management endpoints, which let you programmatically update a user's application-specific ID and password. Let me break this down step by step:
Prerequisites First
Before you start, make sure you have:
- A OneLogin API client with manage_users or update_user permissions (create this in OneLogin's Admin Portal under Developers > API Credentials)
- The target user's
user_id(you can fetch this via the/api/2/usersendpoint if you don't have it already) - The target application's
app_id(found in the app's settings in OneLogin)
Step 1: Get an API Access Token
First, authenticate to get a valid OAuth2 token using the client credentials flow:
curl -X POST "https://<your-onelogin-subdomain>.onelogin.com/auth/oauth2/v2/token" \ -H "Content-Type: application/json" \ -d '{ "grant_type": "client_credentials", "client_id": "YOUR_CLIENT_ID", "client_secret": "YOUR_CLIENT_SECRET" }'
This will return an access_token you'll use for all subsequent requests.
Step 2: Fetch the User's App Assignment ID
Each user-app pairing has a unique assignment_id (this is different from the app's global app_id). To get this, call the endpoint to list the user's assigned apps:
curl -X GET "https://<your-onelogin-subdomain>.onelogin.com/api/2/users/{user_id}/apps" \ -H "Authorization: Bearer YOUR_ACCESS_TOKEN"
Look for the entry matching your target app's app_id—the id field in that entry is your assignment_id.
Step 3: Update the App ID and Password
Use a PUT request to the user-app assignment endpoint to update the credentials. You have two options:
Option 1: Set Custom ID and Password
curl -X PUT "https://<your-onelogin-subdomain>.onelogin.com/api/2/users/{user_id}/apps/{assignment_id}" \ -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "username": "CUSTOM_APP_USER_ID", "password": "CUSTOM_APP_PASSWORD", "password_never_expires": true }'
Option 2: Auto-Generate Password
If you don't want to specify a password, let OneLogin generate a secure one automatically:
curl -X PUT "https://<your-onelogin-subdomain>.onelogin.com/api/2/users/{user_id}/apps/{assignment_id}" \ -H "Authorization: Bearer YOUR_ACCESS_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "username": "CUSTOM_APP_USER_ID", "generate_password": true, "password_never_expires": true }'
Key Notes
- Some applications might restrict API-based credential updates—double-check the app's settings in OneLogin to ensure "Allow API to manage user credentials" is enabled.
- For bulk updates, you can loop through user IDs and repeat these steps programmatically.
- Always handle the access token securely (avoid hardcoding credentials) and add error handling for cases like invalid tokens or missing permissions.
内容的提问来源于stack exchange,提问作者Andy Juram Lee

