updateTenant

Prev Next

이 가이드는 API 명세를 기반으로 AI가 자동 생성했습니다.

Classic/VPC 환경에서 이용 가능합니다.

Ncloud 표준 표현을 적용한 API입니다.

Tenant 정보를 수정합니다. 요청 본문의 모든 필드는 필수이며, 전달한 값이 기존 값을 대체합니다.

요청

요청 형식을 설명합니다. 요청 형식은 다음과 같습니다.

메서드 URI
PUT /tenant

요청 헤더

Ncloud Single Sign-On API에서 공통으로 사용하는 헤더에 대한 정보는 Ncloud Single Sign-On 요청 헤더를 참조해 주십시오.

요청 바디

요청 바디에 대한 설명은 다음과 같습니다.

필드 타입 필수 여부 설명
tenantAlias String Required Tenant Alias(별칭). 수정 시 URL이 변경되어 External IdP 재설정이 필요합니다. 별칭 중복은 대소문자를 구분하여 검사합니다.
  • 패턴: ^[A-Za-z0-9]+[A-Za-z0-9_-]*$
  • 길이: 2 ~ 100
  • <예시> example-tenant
memberLoginPolicy String Required 메인 계정 로그인 허용 여부
  • UNUSED | ALLOW | DENY
    • UNUSED: Application별 설정을 따름
    • ALLOW: 허용
    • DENY: 거부
  • <예시> UNUSED

요청 예시

요청 예시는 다음과 같습니다.

curl --location --request PUT 'https://sso.apigw.ntruss.com/api/v2/tenant' \
--header 'x-ncp-apigw-timestamp: {Timestamp}' \
--header 'x-ncp-iam-access-key: {Access Key}' \
--header 'x-ncp-apigw-signature-v2: {API Gateway Signature}' \
--header 'Content-Type: application/json' \
--data '{
  "tenantAlias": "example-tenant",
  "memberLoginPolicy": "UNUSED"
}'

응답

응답 형식을 설명합니다.

응답 바디

응답 바디에 대한 설명은 다음과 같습니다.

필드 타입 필수 여부 설명
tenantId String (uuid) - Tenant 아이디
  • <예시> 8d9e0f10-8888-4123-9456-789abcdef012
tenantAlias String - Tenant 별칭
  • <예시> example-tenant
memberLoginPolicy String - 메인 계정 로그인 허용 여부
  • ALLOW | DENY | UNUSED
    • UNUSED: Application별 설정을 따름
    • ALLOW: 허용
    • DENY: 거부
  • <예시> ALLOW
idleSessionExpirationSeconds Integer (int32) - 로그인한 외부 계정의 유휴 세션 만료 시간(초)
  • 600 | 1800 | 3600 | 10800
  • <예시> 600
multipleLoginAllowed Boolean - 중복 로그인 허용 여부
  • true | false
    • true: 허용
    • false: 허용 안 함
  • <예시> true
organizationEnabled Boolean - Organization 연동 상태
  • true | false
    • true: 연동 완료
    • false: 연동 해제
  • <예시> true
organizationEnableDateTime String (date-time) - Organization 연동 일시
  • <예시> 2025-01-02T09:00:00Z
protocols List<String> - 지원 프로토콜
  • 항목 OAUTH2 | OIDC | SAML
    • OAUTH2: OAuth 2.0
    • OIDC: OpenID Connect
    • SAML: SAML 2.0
supportedApplicationTypes List<String> - Application 유형
  • 항목 APP | WEB
    • WEB: 웹
    • APP: 앱
oauth2 Object<OauthTenantResponseV2> - Tenant OAuth 설정 정보
idpExists Boolean - External IdP 생성 여부
  • true | false
    • true: 생성됨
    • false: 생성되지 않음
  • <예시> true
createdDateTime String (date-time) - Tenant 생성 일시
  • <예시> 2025-01-02T09:00:00Z
possessionAuthenticationEnabled Boolean - 점유 인증 적용 여부
  • true | false
    • true: 적용
    • false: 미적용
  • <예시> true
possessionAuthenticationTypes List<String> - 점유 인증 수단 유형
  • 항목 SMS | EMAIL
multiFactorAuthenticationEnabled Boolean - 2차 인증 적용 여부
  • true | false
    • true: 적용
    • false: 미적용
  • <예시> true

OauthTenantResponseV2

Tenant OAuth 설정 정보

필드 타입 필수 여부 설명
supportedGrantTypes List<String> - 지원하는 권한 부여 방식
  • 항목 authorization_code | implicit | refresh_token | client_credentials | password
    • authorization_code: 자체 생성한 Authorization code로 Access Token 발급
    • implicit: Authorization code 없이 바로 Access Token 발급. 자격 증명을 안전하게 저장하기 힘든 Client 환경에 최적화
    • refresh_token: Access Token 만료 후 재로그인 없이 새 Access Token 발급
    • client_credentials: 사용자 개입 없이 Client 자격 증명만으로 Access Token 발급
    • password: 사용자의 아이디와 비밀번호로 직접 Access Token 발급
supportedResponseTypes List<String> - OAuth 2.0 및 OpenID Connect 프로토콜에서 지원하는 응답 유형
  • 항목 code | token | id_token | none
    • code: Authorization Code 반환
    • token: Access Token 반환
    • id_token: ID Token 반환
    • none: 토큰을 반환하지 않음
supportedScopes List<String> - 지원하는 Application 접근 가능 정보 범위
  • 항목 openid | offline_access | email | address | phone | profile | groups
    • openid: 계정 구분, 로그인 아이디, 회원 고유 식별자, 사용자 이름
    • profile: 계정 구분, 로그인 아이디, 회원 고유 식별자, 사용자 이름
    • email: 계정 구분, 로그인 아이디, 회원 고유 식별자, 사용자 이름, 이메일
    • groups: 계정 구분, 로그인 아이디, 회원 고유 식별자, 사용자 이름, 그룹
    • phone: 전화번호
    • address: 주소
    • offline_access: Refresh Token 발급
supportedClientAuthMethods List<String> - 지원하는 Application 인증 방식
  • 항목 client_secret_basic | client_secret_post | none
    • client_secret_basic: Client 자격 증명을 HTTP Basic 인증 헤더로 전달
    • client_secret_post: Client 아이디와 Secret을 POST 요청 본문에 포함
    • none: 인증 안 함
supportedAccessTypes List<String> - 지원하는 Application 접근 방식
  • 항목 public | confidential
    • confidential: Client 아이디 및 Secret으로 인증 후 접근
    • public: Client 아이디로 인증 후 접근

응답 상태 코드

Ncloud Single Sign-On API에서 공통으로 사용하는 응답 상태 코드에 대한 정보는 Ncloud Single Sign-On 응답 상태 코드를 참조해 주십시오.

이 API에만 해당하는 응답 상태 코드는 다음과 같습니다.

HTTP 상태 코드 코드 메시지 설명
200 - - 요청 처리 성공
404 NotFound One or more of the resources in the request does not exist in the system. 잘못된 URL 요청, 마스터 계정에 Organization이 존재하지 않음, 존재하지 않는 관리형 정책(System Managed) 아이디 입력, SSO User에 MFA Device가 존재하지 않음
404 ResourceNotFound The specified resource could not be found. 생성된 Tenant가 없음, 존재하지 않는 자원 아이디 입력
409 AlreadyExists The resource with the name requested already exists. 이미 사용 중인 이름·Tenant 별칭·로그인 아이디 입력, 이미 생성된 External IdP 또는 이미 등록된 IdP 인증서

응답 예시

응답 예시는 다음과 같습니다.

{
  "tenantId": "8d9e0f10-8888-4123-9456-789abcdef012",
  "tenantAlias": "example-tenant",
  "memberLoginPolicy": "ALLOW",
  "idleSessionExpirationSeconds": 600,
  "multipleLoginAllowed": true,
  "organizationEnabled": true,
  "organizationEnableDateTime": "2025-01-02T09:00:00Z",
  "protocols": [
    "OAUTH2"
  ],
  "supportedApplicationTypes": [
    "APP"
  ],
  "oauth2": {
    "supportedGrantTypes": [
      "authorization_code"
    ],
    "supportedResponseTypes": [
      "code"
    ],
    "supportedScopes": [
      "openid"
    ],
    "supportedClientAuthMethods": [
      "client_secret_basic"
    ],
    "supportedAccessTypes": [
      "public"
    ]
  },
  "idpExists": true,
  "createdDateTime": "2025-01-02T09:00:00Z",
  "possessionAuthenticationEnabled": true,
  "possessionAuthenticationTypes": [
    "SMS"
  ],
  "multiFactorAuthenticationEnabled": true
}