View a markdown version of this page

CreateUser - Identity Store

CreateUser

Creates a user within the specified identity store.

Request Syntax

{ "Addresses": [ { "Country": "string", "Formatted": "string", "Locality": "string", "PostalCode": "string", "Primary": boolean, "Region": "string", "StreetAddress": "string", "Type": "string" } ], "Birthdate": "string", "DisplayName": "string", "Emails": [ { "Primary": boolean, "Type": "string", "Value": "string" } ], "Extensions": { "string" : JSON value }, "IdentityStoreId": "string", "Locale": "string", "Name": { "FamilyName": "string", "Formatted": "string", "GivenName": "string", "HonorificPrefix": "string", "HonorificSuffix": "string", "MiddleName": "string" }, "NickName": "string", "PhoneNumbers": [ { "Primary": boolean, "Type": "string", "Value": "string" } ], "Photos": [ { "Display": "string", "Primary": boolean, "Type": "string", "Value": "string" } ], "PreferredLanguage": "string", "ProfileUrl": "string", "Roles": [ { "Primary": boolean, "Type": "string", "Value": "string" } ], "Timezone": "string", "Title": "string", "UserName": "string", "UserType": "string", "Website": "string" }

Request Parameters

For information about the parameters that are common to all actions, see Common Parameters.

The request accepts the following data in JSON format.

Addresses

A list of Address objects containing addresses associated with the user.

Type: Array of Address objects

Array Members: Fixed number of 1 item.

Required: No

Birthdate

The user's birthdate in YYYY-MM-DD format. This field supports standard date format for storing personal information.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Pattern: [\p{L}\p{M}\p{S}\p{N}\p{P}\t\n\r   ]+

Required: No

DisplayName

A string containing the name of the user. This value is typically formatted for display when the user is referenced. For example, "John Doe." When used in IAM Identity Center, this parameter is required.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Pattern: [\p{L}\p{M}\p{S}\p{N}\p{P}\t\n\r   ]+

Required: No

Emails

A list of Email objects containing email addresses associated with the user.

Type: Array of Email objects

Array Members: Fixed number of 1 item.

Required: No

Extensions

A map with additional attribute extensions for the user. Each map key corresponds to an extension name, while map values represent extension data in Document type (not supported by Java V1, Go V1 and older versions of the AWS CLI). aws:identitystore:enterprise is the only supported extension name.

Type: String to JSON value map

Map Entries: Maximum number of 10 items.

Key Length Constraints: Minimum length of 1. Maximum length of 50.

Key Pattern: aws:identitystore:[a-z]{1,20}

Required: No

IdentityStoreId

The globally unique identifier for the identity store.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 36.

Pattern: d-[0-9a-f]{10}$|^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}

Required: Yes

Locale

A string containing the geographical region or location of the user.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Pattern: [\p{L}\p{M}\p{S}\p{N}\p{P}\t\n\r   ]+

Required: No

Name

An object containing the name of the user. When used in IAM Identity Center, this parameter is required.

Type: Name object

Required: No

NickName

A string containing an alternate name for the user.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Pattern: [\p{L}\p{M}\p{S}\p{N}\p{P}\t\n\r   ]+

Required: No

PhoneNumbers

A list of PhoneNumber objects containing phone numbers associated with the user.

Type: Array of PhoneNumber objects

Array Members: Fixed number of 1 item.

Required: No

Photos

A list of photos associated with the user. You can add up to 3 photos per user. Each photo can include a value, type, display name, and primary designation.

Type: Array of Photo objects

Array Members: Minimum number of 1 item. Maximum number of 3 items.

Required: No

PreferredLanguage

A string containing the preferred language of the user. For example, "American English" or "en-us."

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Pattern: [\p{L}\p{M}\p{S}\p{N}\p{P}\t\n\r   ]+

Required: No

ProfileUrl

A string containing a URL that might be associated with the user.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Pattern: [\p{L}\p{M}\p{S}\p{N}\p{P}\t\n\r   ]+

Required: No

Roles

A list of Role objects containing roles associated with the user.

Type: Array of Role objects

Array Members: Fixed number of 1 item.

Required: No

Timezone

A string containing the time zone of the user.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Pattern: [\p{L}\p{M}\p{S}\p{N}\p{P}\t\n\r   ]+

Required: No

Title

A string containing the title of the user. Possible values are left unspecified. The value can vary based on your specific use case.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Pattern: [\p{L}\p{M}\p{S}\p{N}\p{P}\t\n\r   ]+

Required: No

UserName

A unique string used to identify the user. The length limit is 128 characters. This value can consist of letters, accented characters, symbols, numbers, and punctuation. This value is specified at the time the user is created and stored as an attribute of the user object in the identity store. Administrator and AWSAdministrators are reserved names and can't be used for users or groups.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 128.

Pattern: [\p{L}\p{M}\p{S}\p{N}\p{P}]+

Required: No

UserType

A string indicating the type of user. Possible values are left unspecified. The value can vary based on your specific use case.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Pattern: [\p{L}\p{M}\p{S}\p{N}\p{P}\t\n\r   ]+

Required: No

Website

The user's personal website or blog URL. This field allows users to provide a link to their personal or professional website.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 1024.

Pattern: [\p{L}\p{M}\p{S}\p{N}\p{P}\t\n\r   ]+

Required: No

Response Syntax

{ "IdentityStoreId": "string", "UserId": "string" }

Response Elements

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.

IdentityStoreId

The globally unique identifier for the identity store.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 36.

Pattern: d-[0-9a-f]{10}$|^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}

UserId

The identifier of the newly created user in the identity store.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 47.

Pattern: ([0-9a-f]{10}-|)[A-Fa-f0-9]{8}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{4}-[A-Fa-f0-9]{12}

Errors

For information about the errors that are common to all actions, see Common Error Types.

AccessDeniedException

You do not have sufficient access to perform this action.

Reason

Indicates the reason for an access denial when returned by KMS while accessing a Customer Managed KMS key. For non-KMS access-denied errors, this field is not included.

RequestId

The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.

HTTP Status Code: 400

ConflictException

This request cannot be completed for one of the following reasons:

  • Performing the requested operation would violate an existing uniqueness claim in the identity store. Resolve the conflict before retrying this request.

  • The requested resource was being concurrently modified by another request.