Docs
EN
Docs
Console
Sign in
IAM
Document
IAM
IAM
Document
Overview
Product introduction
Basic concept
Usage restrictions
Quickstarts
Create a user and authorize it
Grant user API key management permissions
User Guide
Identities
User management
User group management
Role Management
Identity Provider Management
Single Sign-on
Single sign-on (SSO) overview
Multiple login methods for single sign-on
Scenarios for User SSO and Role SSO
User SSO
User SSO Overview
User SSO based on SAML
Volcano Engine Configuration of User SSO Based on SAML 2.0
Enterprise IDP Configuration of User SSO Based on SAML 2.0
SAML response from user SSO
Examples
Example of configuring SAML user SSO using Okta
Example of Configuring SAML User SSO with KeyCloak
User SSO based on Oauth
Single sign-on configuration based on Oauth 2.0
Oauth 2.0 single sign-on interface standard
Role SSO
Role SSO Overview
Volcano Engine Configuration for Role SSO Based on SAML 2.0
Enterprise IDP Configuration of Role SSO Based on SAML 2.0
SAML Response for Role SSO
Example
Example of configuring SAML role SSO using okta
Example of Configuring SAML Role SSO with KeyCloak
Permission Policy
Policy Overview
Common System Default Policies
Job function policies
Delegate by project
Create custom policy
Policy Grammar
Basic structure
Authority Statement
Effect
Action
Resources
Conditions
Trusted Identity (Principal)
Variables and wild-card
Logical non-syntax (NotAction, etc.)
Cloud as a Service Supported Condition Keys
Custom policy example
Access key
API Access Key Management
Project
Resource project management
Tutorials
Use of common system preset policies
API Key (Access Key) Practice Recommendation
Policy Example
Allow access to the specified service
Allows access to specified services for specified operations
Deny access to the specified service
Limit the range of resources that can be operated
Control permissions based on access IP (SourceIP)
Control permissions based on PrincipalTag
Control permissions based on resource tags
Control permissions based on RequestTag
Control permissions based on access time (CurrentTime)
Control permissions based on region of access
Control permissions based on console access (ViaConsole)
Control permissions based on access identity (PrincipalTrn)
Control permissions based on IAM username (UserName)
Using conditional keys as variables
API Reference
API Overview
STS
AssumeRoleWithOIDC
AssumeRoleWithSAML
SDK Reference
SDK Overview
FAQ
How to authorize based on a permissionless error message
How to deny users access to billing centers
How to solve the error when prompting a new custom policy
Why did the service association role deletion fail?
Why do IAM users fail to delete users?
Documentation
IAM
User Guide
Permission Policy
Policy Grammar
Cloud as a Service Supported Condition Keys
Copy page
Download PDF
Policy Grammar
Cloud as a Service Supported Condition Keys
Copy page
Download PDF
Cloud as a Service Supported Condition Keys
Last updated: 2025.06.23 19:21:30