이 가이드는 API 명세를 기반으로 AI가 자동 생성했습니다.
Classic/VPC 환경에서 이용 가능합니다.
Ncloud 표준 표현을 적용한 API입니다.
SSO User와 Permission Set을 연결하여 외부 계정의 권한 범위를 정의합니다.
요청
요청 형식을 설명합니다. 요청 형식은 다음과 같습니다.
| 메서드 | URI |
|---|---|
| POST | /assignments |
요청 헤더
Ncloud Single Sign-On API에서 공통으로 사용하는 헤더에 대한 정보는 Ncloud Single Sign-On 요청 헤더를 참조해 주십시오.
요청 바디
요청 바디에 대한 설명은 다음과 같습니다.
| 필드 | 타입 | 필수 여부 | 설명 |
|---|---|---|---|
assignmentName |
String | Required | Assignment 이름. 이름 중복은 대소문자를 구분하지 않고 검사합니다(예: Assign 과 assign 은 같은 이름).
|
accountMemberNo |
Integer (int64) | Required | 계정 회원 번호
|
permissionSetId |
String (uuid) | Required | Permission Set 아이디
|
description |
String | null | Optional | Assignment 설명
|
consoleAccessAllowed |
Boolean | Required | 콘솔 접근 허용 여부
|
apiAccessAllowed |
Boolean | Required | API Gateway 접근 허용 여부
|
tags |
Map<String> | null | Optional | Assignment의 태그. {tagKey}:{tagValue} 형식
|
tags.<키> |
String | - | 태그 값
|
요청 예시
요청 예시는 다음과 같습니다.
curl --location --request POST 'https://sso.apigw.ntruss.com/api/v2/assignments' \
--header 'x-ncp-apigw-timestamp: {Timestamp}' \
--header 'x-ncp-iam-access-key: {Access Key}' \
--header 'x-ncp-apigw-signature-v2: {API Gateway Signature}' \
--header 'Content-Type: application/json' \
--data '{
"assignmentName": "example-assignment",
"accountMemberNo": 1234567,
"permissionSetId": "5e6f7081-5555-4ef0-8123-456789abcdef",
"consoleAccessAllowed": true,
"apiAccessAllowed": true
}'
응답
응답 형식을 설명합니다.
응답 바디
응답 바디에 대한 설명은 다음과 같습니다.
| 필드 | 타입 | 필수 여부 | 설명 |
|---|---|---|---|
assignmentId |
String (uuid) | - | Assignment 아이디
|
assignmentName |
String | - | Assignment 이름
|
description |
String | - | Assignment 설명
|
nrn |
String | - | Assignment에 대한 네이버 클라우드 플랫폼 리소스 식별 값
|
status |
String | - | Assignment 상태
|
iamRoleNrn |
String | - | Sub Account 서비스에 생성된 SSO 역할 NRN
|
consoleAccessAllowed |
Boolean | - | 콘솔 접근 허용 여부
|
consoleAccessRestricted |
Boolean | - | 콘솔 접근 제한 여부
|
apiAccessAllowed |
Boolean | - | API Gateway 접근 허용 여부
|
apiAccessRestricted |
Boolean | - | API Gateway 접근 제한 여부
|
createdDateTime |
String (date-time) | - | Assignment 생성 일시
|
updatedDateTime |
String (date-time) | - | Assignment 최종 수정 일시
|
accountMemberNo |
Integer (int64) | - | 계정 회원 번호(MemberNo)
|
accountName |
String | - | 계정 사용자 이름
|
accountAlias |
String | - | 계정 별칭
|
accountGroup |
String | - | 계정 그룹
|
accountType |
String | - | 계정 유형
|
accountLoginId |
String (email) | - | 계정 로그인 아이디
|
permissionSetId |
String (uuid) | - | Permission Set 아이디
|
permissionSetName |
String | - | Permission Set 이름
|
permissionSetNrn |
String | - | Permission Set에 대한 네이버 클라우드 플랫폼 리소스 식별 값
|
permissionSetDescription |
String | - | Permission Set 설명
|
permissionCreatedDateTime |
String (date-time) | - | Permission Set 생성 일시
|
응답 상태 코드
Ncloud Single Sign-On API에서 공통으로 사용하는 응답 상태 코드에 대한 정보는 Ncloud Single Sign-On 응답 상태 코드를 참조해 주십시오.
이 API에만 해당하는 응답 상태 코드는 다음과 같습니다.
| HTTP 상태 코드 | 코드 | 메시지 | 설명 |
|---|---|---|---|
| 201 | - | - | 자원 생성 성공 |
| 400 | ResourceLimitExceeded | The request exceeds the resource limit. | 생성 가능한 자원 수 초과, SP·IdP 인증서 2장 초과 |
| 404 | NotFound | One or more of the resources in the request does not exist in the system. | 잘못된 URL 요청, 마스터 계정에 Organization이 존재하지 않음, 존재하지 않는 관리형 정책(System Managed) 아이디 입력, SSO User에 MFA Device가 존재하지 않음 |
| 404 | ResourceNotFound | The specified resource could not be found. | 생성된 Tenant가 없음, 존재하지 않는 자원 아이디 입력 |
| 404 | PermissionSetNotFound | The specified permission set could not be found. | 존재하지 않는 Permission Set 아이디 입력 |
| 409 | AlreadyExists | The resource with the name requested already exists. | 이미 사용 중인 이름·Tenant 별칭·로그인 아이디 입력, 이미 생성된 External IdP 또는 이미 등록된 IdP 인증서 |
| 409 | Conflict | The request could not be processed because of a conflict in the current status of the resource. | 이미 추가된 타깃 정보 입력, 이미 추가한 IP ACL 아이디 입력, 이미 MFA Device 가 등록된 SSO User |
응답 예시
응답 예시는 다음과 같습니다.
{
"assignmentId": "3c4d5e6f-3333-4cde-8f01-23456789abcd",
"assignmentName": "example-assignment",
"description": "example description",
"nrn": "nrn:PUB:SSO::1234567:Assignment/3c4d5e6f-3333-4cde-8f01-23456789abcd",
"status": "ACTIVATED",
"iamRoleNrn": "nrn:PUB:IAM::1234567:Role/385550d0-1111-4abc-8def-005056a79baa",
"consoleAccessAllowed": true,
"consoleAccessRestricted": true,
"apiAccessAllowed": true,
"apiAccessRestricted": true,
"createdDateTime": "2025-01-02T09:00:00Z",
"updatedDateTime": "2025-01-02T09:00:00Z",
"accountMemberNo": 1234567,
"accountName": "example-account",
"accountAlias": "example-account",
"accountGroup": "example-group",
"accountType": "MASTER",
"accountLoginId": "user@example.com",
"permissionSetId": "5e6f7081-5555-4ef0-8123-456789abcdef",
"permissionSetName": "example-permissionset",
"permissionSetNrn": "nrn:PUB:SSO::1234567:PermissionSet/5e6f7081-5555-4ef0-8123-456789abcdef",
"permissionSetDescription": "example description",
"permissionCreatedDateTime": "2025-01-02T09:00:00Z"
}