1. Support
  2. Integrations
  3. Identity
Oracle Cloud 90 nodes

Identity

Oracle Cloud integration · 90 node(s).

00Overview

Manage your entire Oracle Cloud Identity and Access Management layer from a flow — create and update users, groups and memberships, write policy statements, and organise resources into compartments. Issue and revoke every kind of user credential, from API signing keys and auth tokens to SMTP, database, OAuth and S3-compatible secret keys, and manage dynamic groups, network sources, tag namespaces and SAML federation alongside them. Read-only actions cover the tenancy, its regions and availability domains, so a flow can discover its own environment before it acts.

Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.

01Connecting Identity

  1. In the Oracle Cloud Console, open the Profile menu (top-right) → User settings for the IAM user the flow will act as, then under Resources choose API Keys → Add API Key.
  2. Let the console Generate API Key Pair (or paste your own public key), download the private key, then copy the Configuration File Preview it shows — it lists the Tenancy OCID, User OCID, Key Fingerprint and Region for the key you just added.
  3. Back in the node, set Authentication: Connect Oracle Cloud (the default) lets you pick a saved account in the Oracle Cloud connection field and fills the signing details for you, while API signing key (advanced) instead exposes the Tenancy OCID, User OCID, Region, Key Fingerprint and Private Key (PEM) fields to paste in by hand.
  4. Set Region to your tenancy's home region (e.g. uk-london-1) — Identity is a global, home-region service, so IAM writes sent to any other region are rejected.
  5. In Flomation, store the downloaded key as an environment secret (e.g. identity_secret) and select it in the node's Private Key (PEM) field; supply the Private Key Passphrase only if the key is encrypted.
FieldTypeDetails
AuthenticationstringConnect Oracle Cloud, API signing key (advanced)
Oracle Cloud connectioncredentialPick a connected Oracle Cloud account
Regionstringthe tenancy home region, e.g. uk-london-1
Private Key (PEM)secretThe API signing private key — full PEM, incl. BEGIN/END lines
Private Key PassphrasesecretOnly if the key is encrypted (optional)
Tenancy OCIDstringocid1.tenancy.oc1..aaaa…
User OCIDstringocid1.user.oc1..aaaa… (the caller's user, for signing)
Key Fingerprintstringaa:bb:cc:… fingerprint of the uploaded API key
Good to know

Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.

02Api

OCI Identity: Delete API Key

oracle/identity/api_key_delete · Action

Remove an API signing key from an Oracle Cloud IAM user, identified by the target user's OCID and the key's fingerprint. This is permanent — the key can no longer sign requests.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCID (key owner)stringRequiredocid1.user.oc1..aaaa… of the user the key belongs to
API Key Fingerprint (to delete)stringRequiredaa:bb:cc:… fingerprint of the target user's API key to remove (NOT your signing key)

Returns: tool_result, id, success, error

OCI Identity: List API Keys

oracle/identity/api_key_list · Action

List the API signing keys uploaded for an Oracle Cloud IAM user — each key's fingerprint, OCID and lifecycle state.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCID (to read)stringRequiredocid1.user.oc1..aaaa… whose API keys to list

Returns: tool_result, api_keys, count, truncated, success, error

OCI Identity: Upload API Key

oracle/identity/api_key_upload · Action

Upload an API signing key (the PEM RSA public key) for an Oracle Cloud IAM user — the private half stays with the caller. Returns the key's fingerprint. Each user may hold at most three API keys.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the key belongs to
Public Key (PEM)textRequired-----BEGIN PUBLIC KEY----- … the RSA public key in PEM format

Returns: tool_result, api_key, fingerprint, id, success, error

03Auth

OCI Identity: Create Auth Token

oracle/identity/auth_token_create · Action

Create an auth token for an Oracle Cloud IAM user — a bearer credential for services that use token auth. The token value is returned ONCE here and never shown again, so capture it now.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the token belongs to
DescriptionstringRequiredWhat this token is for

Returns: tool_result, auth_token, token, id, success, error

OCI Identity: Delete Auth Token

oracle/identity/auth_token_delete · Action

Delete an auth token from an Oracle Cloud IAM user — permanently revokes that bearer credential. Give the user's OCID and the auth token's OCID.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the token belongs to
Auth Token OCIDstringRequiredocid1.credential.oc1..aaaa… of the token to delete

Returns: tool_result, id, success, error

OCI Identity: List Auth Tokens

oracle/identity/auth_token_list · Action

List the auth tokens belonging to an Oracle Cloud IAM user — their OCID, description, lifecycle state and expiry. The token secret itself is never returned by a list (only on create).

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… whose auth tokens to list

Returns: tool_result, auth_tokens, count, truncated, success, error

OCI Identity: Update Auth Token

oracle/identity/auth_token_update · Action

Change the description of an existing Oracle Cloud IAM auth token. The token secret is never re-shown — only the description is editable.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the token belongs to
Auth Token OCIDstringRequiredocid1.credential.oc1..aaaa… of the auth token to update
DescriptionstringRequiredThe new description for this auth token

Returns: tool_result, auth_token, id, success, error

04Authentication

OCI Identity: Get Authentication Policy

oracle/identity/authentication_policy_get · Action

Fetch the Oracle Cloud IAM authentication policy for a compartment (defaulting to the tenancy) — its password complexity rules and the network sources allowed to sign in.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (the authentication policy is read from this compartment)

Returns: tool_result, authentication_policy, compartment_id, success, error

OCI Identity: Update Authentication Policy

oracle/identity/authentication_policy_update · Action

Update the Oracle Cloud IAM authentication (password) policy for a compartment — minimum length and the character-class requirements. Reads the current policy first and overlays only the fields you set, leaving the rest (including the network policy) untouched.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (the policy applies at the tenancy root)
Minimum Password Lengthintegere.g. 12 (leave unset to keep unchanged)
Require Uppercase CharacterbooleanAt least one A–Z required (leave unset to keep unchanged)
Require Lowercase CharacterbooleanAt least one a–z required (leave unset to keep unchanged)
Require Numeric CharacterbooleanAt least one 0–9 required (leave unset to keep unchanged)
Require Special CharacterbooleanAt least one special character required (leave unset to keep unchanged)
Allow Username In PasswordbooleanPermit the user name to appear in the password (leave unset to keep unchanged)

Returns: tool_result, policy, compartment_id, success, error

05Availability

OCI Identity: List Availability Domains

oracle/identity/availability_domain_list · Action

List the availability domains visible to a compartment (the tenancy) — each one's name and OCID. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (availability domains are tenancy-scoped)

Returns: tool_result, availability_domains, count, truncated, success, error

06Compartment

OCI Identity: Create Compartment

oracle/identity/compartment_create · Action

Create an Oracle Cloud compartment under a parent (or the tenancy root) — the container that groups and isolates resources for access control and billing.

FieldTypeDetails
Parent Compartment OCIDstringLeave blank for the tenancy root — the parent to create under
Compartment NamestringRequiredUnique name within the parent, e.g. Prod
DescriptionstringRequiredWhat this compartment holds
Freeform Tags (JSON)string{"env":"prod"} (optional)

Returns: tool_result, compartment, id, success, error

OCI Identity: Delete Compartment

oracle/identity/compartment_delete · Action

Delete an Oracle Cloud compartment by OCID. The compartment must be empty first. Asynchronous — returns a work-request id; the compartment moves to DELETING then DELETED.

FieldTypeDetails
Parent Compartment OCIDstringLeave blank for the tenancy (scopes the compartment picker)
Compartment OCID (to delete)stringRequiredocid1.compartment.oc1..aaaa… of the compartment to delete

Returns: tool_result, id, work_request_id, success, error

OCI Identity: Get Compartment

oracle/identity/compartment_get · Action

Fetch a single Oracle Cloud IAM compartment by OCID — its name, description, parent, accessibility and lifecycle state.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the compartment picker)
Compartment OCID (to read)stringRequiredocid1.compartment.oc1..aaaa… of the compartment to fetch

Returns: tool_result, compartment, id, success, error

OCI Identity: List Compartments

oracle/identity/compartment_list · Action

List the Oracle Cloud compartments under a parent compartment (leave blank for the tenancy root). Optionally traverse the full subtree. Walks pagination up to a safe cap.

FieldTypeDetails
Parent Compartment OCIDstringLeave blank for the tenancy (lists the root's children)
Include SubtreebooleanList every descendant compartment, not just direct children (tenancy root only)

Returns: tool_result, compartments, count, truncated, success, error

OCI Identity: Move Compartment

oracle/identity/compartment_move · Action

Move an Oracle Cloud compartment (and its contents) into a different parent compartment. Asynchronous — returns a work-request id to track the move.

FieldTypeDetails
Parent Compartment OCIDstringLeave blank for the tenancy (scopes the compartment picker)
Compartment OCID (to move)stringRequiredocid1.compartment.oc1..aaaa… of the compartment to move
Destination Compartment OCIDstringRequiredocid1.compartment.oc1..aaaa… of the new parent (or the tenancy)

Returns: tool_result, id, work_request_id, success, error

OCI Identity: Recover Compartment

oracle/identity/compartment_recover · Action

Recover (un-delete) a previously deleted Oracle Cloud IAM compartment by OCID, returning it to the active state.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the compartment picker)
Compartment OCID (to recover)stringRequiredocid1.compartment.oc1..aaaa… of the deleted compartment

Returns: tool_result, compartment, id, success, error

OCI Identity: Update Compartment

oracle/identity/compartment_update · Action

Update an Oracle Cloud compartment's name, description and/or freeform tags — only the fields you supply are changed.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the compartment picker)
Compartment OCID (to update)stringRequiredocid1.compartment.oc1..aaaa… of the compartment to update
NamestringNew name — must be unique within the parent (leave blank to keep)
DescriptionstringNew description (leave blank to keep the current one)
Freeform Tags (JSON)string{"env":"prod"} — replaces all freeform tags (leave blank to keep)

Returns: tool_result, compartment, id, success, error

07Customer

OCI Identity: Create Customer Secret Key

oracle/identity/customer_secret_key_create · Action

Create a customer secret key for an Oracle Cloud IAM user — an access-key/secret-key pair for Object Storage's Amazon S3-compatible API. The secret key value is returned ONCE here and never shown again, so capture it now.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the secret key belongs to
Display NamestringRequiredA name for this secret key (need not be unique)

Returns: tool_result, customer_secret_key, key, id, success, error

OCI Identity: Delete Customer Secret Key

oracle/identity/customer_secret_key_delete · Action

Permanently delete a customer secret key (an S3-compatible Access Key / Secret Key pair) from an Oracle Cloud IAM user. Synchronous.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the secret key belongs to
Customer Secret Key OCIDstringRequiredocid1.credential.oc1..aaaa… of the secret key to delete

Returns: tool_result, id, success, error

OCI Identity: List Customer Secret Keys

oracle/identity/customer_secret_key_list · Action

List the customer secret keys belonging to an Oracle Cloud IAM user (used with Object Storage's S3-compatible API) — their OCID, display name, lifecycle state and creation time. The secret key itself is never returned by a list (only on create).

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… whose customer secret keys to list

Returns: tool_result, customer_secret_keys, count, truncated, success, error

08Db

OCI Identity: Create DB Credential

oracle/identity/db_credential_create · Action

Create a database credential for an Oracle Cloud IAM user — used to authenticate a cloud database to Identity. You supply the password here (it is not generated), so store it yourself; OCI never returns it again.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the DB credential belongs to
DescriptionstringRequiredWhat this DB credential is for
DB PasswordsecretRequiredThe password to set on the DB credential — store it yourself, OCI never returns it

Returns: tool_result, db_credential, id, success, error

OCI Identity: Delete DB Credential

oracle/identity/db_credential_delete · Action

Permanently delete a database (DB) credential from an Oracle Cloud IAM user. Synchronous.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the DB credential belongs to
DB Credential OCIDstringRequiredocid1.dbcredential.oc1..aaaa… of the DB credential to delete

Returns: tool_result, id, success, error

OCI Identity: List DB Credentials

oracle/identity/db_credential_list · Action

List the DB credentials belonging to an Oracle Cloud IAM user — their OCID, description, lifecycle state, creation and expiry times. The credential secret itself is never returned by a list (only on create).

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… whose DB credentials to list

Returns: tool_result, db_credentials, count, truncated, success, error

09Dynamic

OCI Identity: Create Dynamic Group

oracle/identity/dynamic_group_create · Action

Create an Oracle Cloud dynamic group — members are resources (compute instances, functions…) matched by a rule, so policies can grant permissions to workloads without static credentials.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (dynamic groups live in the root)
Dynamic Group NamestringRequiredUnique name, e.g. prod-instances
DescriptionstringRequiredWhat this dynamic group is for
Matching RuletextRequirede.g. ALL {instance.compartment.id = 'ocid1.compartment.oc1..aaaa…'}
Freeform Tags (JSON)string{"env":"prod"} (optional)

Returns: tool_result, dynamic_group, id, success, error

OCI Identity: Delete Dynamic Group

oracle/identity/dynamic_group_delete · Action

Permanently delete an Oracle Cloud IAM dynamic group by OCID. Any policies that grant it access stop matching once it is gone. Synchronous.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the dynamic group picker)
Dynamic Group OCID (to delete)stringRequiredocid1.dynamicgroup.oc1..aaaa… of the dynamic group to delete

Returns: tool_result, id, success, error

OCI Identity: Get Dynamic Group

oracle/identity/dynamic_group_get · Action

Fetch a single Oracle Cloud IAM dynamic group by OCID — its name, description, matching rule and lifecycle state.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the dynamic group picker)
Dynamic Group OCIDstringRequiredocid1.dynamicgroup.oc1..aaaa… of the dynamic group to fetch

Returns: tool_result, dynamic_group, id, success, error

OCI Identity: List Dynamic Groups

oracle/identity/dynamic_group_list · Action

List the Oracle Cloud IAM dynamic groups in a compartment (the tenancy), optionally filtered by exact name. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (IAM dynamic groups live in the root)
Name FilterstringOnly the dynamic group with this exact name (optional)

Returns: tool_result, dynamic_groups, count, truncated, success, error

OCI Identity: Update Dynamic Group

oracle/identity/dynamic_group_update · Action

Update an Oracle Cloud dynamic group's description, matching rule and/or freeform tags — only the fields you supply are changed.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (dynamic groups live in the root)
Dynamic Group OCIDstringRequiredocid1.dynamicgroup.oc1..aaaa… of the dynamic group to update
DescriptionstringNew description (leave blank to keep the current one)
Matching RuletextNew rule, e.g. ALL {instance.compartment.id = 'ocid1.compartment.oc1..aaaa…'} (leave blank to keep)
Freeform Tags (JSON)string{"env":"prod"} — replaces all freeform tags (leave blank to keep)

Returns: tool_result, dynamic_group, id, success, error

10Group

OCI Identity: Create Group

oracle/identity/group_create · Action

Create an Oracle Cloud IAM group in the tenancy — a named set of users that policies grant permissions to. Add users with Add User to Group.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (IAM groups live in the root)
Group NamestringRequiredUnique name, e.g. Administrators
DescriptionstringRequiredWhat this group is for
Freeform Tags (JSON)string{"team":"ops"} (optional)

Returns: tool_result, group, id, success, error

OCI Identity: Delete Group

oracle/identity/group_delete · Action

Permanently delete an Oracle Cloud IAM group by OCID. Remove its members first if OCI reports it is not empty. Synchronous.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the group picker)
Group OCID (to delete)stringRequiredocid1.group.oc1..aaaa… of the group to delete

Returns: tool_result, id, success, error

OCI Identity: Get Group

oracle/identity/group_get · Action

Fetch a single Oracle Cloud IAM group by OCID — its name, description, compartment and lifecycle state.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the group picker)
Group OCIDstringRequiredocid1.group.oc1..aaaa… of the group to fetch

Returns: tool_result, group, id, success, error

OCI Identity: List Groups

oracle/identity/group_list · Action

List the Oracle Cloud IAM groups in a compartment (the tenancy), optionally filtered by exact name. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (IAM groups live in the root)
Name FilterstringOnly the group with this exact name (optional)

Returns: tool_result, groups, count, truncated, success, error

OCI Identity: Update Group

oracle/identity/group_update · Action

Update an Oracle Cloud IAM group's description and/or freeform tags. Only the fields you supply are changed; the group name is immutable.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (IAM groups live in the root)
Group OCIDstringRequiredocid1.group.oc1..aaaa… of the group to update
DescriptionstringNew description (leave blank to keep the current one)
Freeform Tags (JSON)string{"team":"ops"} — replaces all freeform tags (leave blank to keep current)

Returns: tool_result, group, id, success, error

11Identity

OCI Identity: Create Identity Provider

oracle/identity/identity_provider_create · Action

Create a SAML2 federation identity provider in an Oracle Cloud tenancy — trust an external IdP (IDCS or ADFS) by supplying its SAML metadata XML so its users can federate in.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (identity providers live in the root)
NamestringRequiredUnique IdP name, cannot be changed later, e.g. corp-adfs
DescriptionstringRequiredWhat this identity provider is for
Product TypestringRequiredIDCS or ADFS
SAML Metadata XMLtextRequiredPaste the IdP's SAML 2.0 metadata XML (the full <EntityDescriptor>…</EntityDescriptor>)
Metadata URLstringURL the IdP metadata was retrieved from (optional)
Freeform Attributes (JSON)string{"clientId":"app_sf3kdjf3"} (optional)
Freeform Tags (JSON)string{"team":"ops"} (optional)

Returns: tool_result, identity_provider, id, success, error

OCI Identity: Delete Identity Provider

oracle/identity/identity_provider_delete · Action

Permanently delete an Oracle Cloud IAM identity provider by OCID. Remove its group mappings first if OCI reports they still exist. Synchronous.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the identity-provider picker)
Identity Provider OCID (to delete)stringRequiredocid1.saml2idp.oc1..aaaa… of the identity provider to delete

Returns: tool_result, id, success, error

OCI Identity: Get Identity Provider

oracle/identity/identity_provider_get · Action

Fetch a single Oracle Cloud IAM identity provider by OCID — its name, product type, protocol and (for SAML2) metadata/redirect URLs and signing certificate.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (identity providers live in the tenancy)
Identity Provider OCIDstringRequiredocid1.saml2idp.oc1..aaaa… of the identity provider to fetch

Returns: tool_result, identity_provider, id, success, error

OCI Identity: List Identity Providers

oracle/identity/identity_provider_list · Action

List the federated identity providers configured on an Oracle Cloud tenancy for a given federation protocol (e.g. SAML2). Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (identity providers live in the root)
ProtocolstringFederation protocol — SAML2 (default)

Returns: tool_result, identity_providers, count, truncated, success, error

12Idp

OCI Identity: Create IdP Group Mapping

oracle/identity/idp_group_mapping_create · Action

Map an Oracle Cloud identity provider (IdP) group to an IAM Service group, so federated users in that IdP group inherit the IAM group's access.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the group picker)
Identity Provider OCIDstringRequiredocid1.saml2idp.oc1..aaaa… the IdP to map from
IdP Group NamestringRequiredThe name of the group as defined in the identity provider
IAM Group OCIDstringRequiredocid1.group.oc1..aaaa… the IAM Service group to map to

Returns: tool_result, idp_group_mapping, id, success, error

OCI Identity: Delete IdP Group Mapping

oracle/identity/idp_group_mapping_delete · Action

Delete a single group mapping (the link between an identity-provider group and an Oracle Cloud IAM group) by its OCID. Synchronous.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the identity-provider picker)
Identity Provider OCIDstringRequiredocid1.saml2idp.oc1..aaaa… the mapping belongs to
Group Mapping OCID (to delete)stringRequiredocid1.idpgroupmapping.oc1..aaaa… of the mapping to delete

Returns: tool_result, id, success, error

OCI Identity: List IdP Group Mappings

oracle/identity/idp_group_mapping_list · Action

List the group mappings for an Oracle Cloud identity provider — each links one federated IdP group to one IAM group. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (not used by this action)
Identity Provider OCIDstringRequiredocid1.saml2idp.oc1..aaaa… of the IdP whose mappings to list

Returns: tool_result, mappings, count, truncated, success, error

13Membership

OCI Identity: Get Group Membership

oracle/identity/membership_get · Action

Fetch a single Oracle Cloud IAM user-group membership by OCID — the user, group and compartment it ties together, plus its lifecycle state.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the pickers)
Membership OCIDstringRequiredocid1.usergroupmembership.oc1..aaaa… of the membership to fetch

Returns: tool_result, membership, id, success, error

OCI Identity: List Group Memberships

oracle/identity/membership_list · Action

List the Oracle Cloud IAM user-group memberships in a compartment (the tenancy), optionally filtered by a user OCID and/or a group OCID. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (IAM memberships live in the root)
User OCID Filterstringocid1.user.oc1..aaaa… — only this user's memberships (optional)
Group OCID Filterstringocid1.group.oc1..aaaa… — only this group's memberships (optional)

Returns: tool_result, memberships, count, truncated, success, error

14Mfa

OCI Identity: Activate MFA TOTP Device

oracle/identity/mfa_totp_activate · Action

Activate a user's MFA TOTP device by submitting the 6-digit code from their authenticator app — the device must be activated before it can be used for sign-in.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCID (device owner)stringRequiredocid1.user.oc1..aaaa… of the user the device belongs to
MFA TOTP Device OCIDstringRequiredocid1.mfatotpdevice.oc1..aaaa…
TOTP CodestringRequiredthe 6-digit code from the authenticator app

Returns: tool_result, device, id, success, error

OCI Identity: Create MFA TOTP Device

oracle/identity/mfa_totp_create · Action

Register a multi-factor-authentication TOTP device for an Oracle Cloud IAM user. This starts enrolment: the device comes back in the CREATING state — you must then generate its seed and activate it (with a TOTP code) to finish, and MFA registration ultimately requires the Console.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the MFA device belongs to

Returns: tool_result, mfa_totp_device, id, success, error

OCI Identity: Delete MFA TOTP Device

oracle/identity/mfa_totp_delete · Action

Delete an MFA TOTP device from an Oracle Cloud IAM user — removes that authenticator so the user must re-enrol to use MFA again. Give the user's OCID and the MFA TOTP device's OCID.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the device belongs to
MFA TOTP Device OCIDstringRequiredocid1.mfatotpdevice.oc1..aaaa… of the device to delete

Returns: tool_result, id, success, error

OCI Identity: Get MFA TOTP Device

oracle/identity/mfa_totp_get · Action

Fetch a single Oracle Cloud IAM MFA TOTP device by OCID — its lifecycle state, whether it is activated, and its creation/expiry times.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCID (device owner)stringRequiredocid1.user.oc1..aaaa… of the user the MFA device belongs to
MFA TOTP Device OCIDstringRequiredocid1.mfatotpdevice.oc1..aaaa… of the device to fetch

Returns: tool_result, mfa_totp_device, id, success, error

OCI Identity: List MFA TOTP Devices

oracle/identity/mfa_totp_list · Action

List the MFA TOTP (authenticator-app) devices registered for an Oracle Cloud IAM user — each device's OCID, activation flag and lifecycle state. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCID (to read)stringRequiredocid1.user.oc1..aaaa… whose MFA TOTP devices to list

Returns: tool_result, mfa_totp_devices, count, truncated, success, error

15Network

OCI Identity: Create Network Source

oracle/identity/network_source_create · Action

Create an Oracle Cloud IAM network source — a named list of allowed public IPs/CIDR ranges you can reference in policy statements to restrict access by source IP.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (network sources live in the root compartment)
NamestringRequiredUnique network-source name (cannot be changed later)
DescriptionstringRequiredWhat this network source is for
Public Source ListstringComma-separated public IPs / CIDR ranges, e.g. 129.213.39.0/24, 203.0.113.5
ServicesstringComma-separated services, e.g. all (reserved by Oracle — usually left blank)

Returns: tool_result, network_source, id, success, error

OCI Identity: Delete Network Source

oracle/identity/network_source_delete · Action

Permanently delete an Oracle Cloud IAM network source by OCID. Detach it from any policies that reference it first if OCI reports it is in use. Synchronous.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the network source picker)
Network Source OCID (to delete)stringRequiredocid1.networksource.oc1..aaaa… of the network source to delete

Returns: tool_result, id, success, error

OCI Identity: Get Network Source

oracle/identity/network_source_get · Action

Fetch a single Oracle Cloud IAM network source by OCID — its name, description, allowed public IP/CIDR list, VCN source list and lifecycle state.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the network-source picker)
Network Source OCIDstringRequiredocid1.networksource.oc1..aaaa… of the network source to fetch

Returns: tool_result, network_source, id, success, error

OCI Identity: List Network Sources

oracle/identity/network_source_list · Action

List the Oracle Cloud IAM network sources in a compartment (the tenancy), optionally filtered by exact name — with their allowed public IP/CIDR and VCN source lists. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (network sources live in the root)
Name FilterstringOnly the network source with this exact name (optional)

Returns: tool_result, network_sources, count, truncated, success, error

OCI Identity: Update Network Source

oracle/identity/network_source_update · Action

Update an Oracle Cloud IAM network source — its description, allowed public IP/CIDR list or services. The IP list and services REPLACE wholesale, so leave one blank to keep the current values (they are re-sent unchanged for you, along with the untouched VCN/virtual source list).

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the network source picker)
Network Source OCIDstringRequiredocid1.networksource.oc1..aaaa… of the network source to update
DescriptionstringNew description (leave blank to keep the current one)
Public IP/CIDR List (comma-separated)string203.0.113.0/24, 198.51.100.5 — REPLACES the list (leave blank to keep it)
Services (comma-separated)stringReserved by Oracle — usually blank; REPLACES the list (leave blank to keep it)

Returns: tool_result, network_source, id, success, error

16Oauth

OCI Identity: Create OAuth Client Credential

oracle/identity/oauth_credential_create · Action

Create an OAuth 2.0 client credential for an Oracle Cloud IAM user — a client-id/secret pair for the OAuth client-credentials grant. The secret (password) is returned ONCE here and never shown again, so capture it now.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the OAuth credential belongs to
NamestringRequiredA label to tell this credential apart
DescriptionstringRequiredWhat this OAuth credential is for
ScopestextRequiredOne scope per line, as `audience, scope` — e.g. urn:oracle:db::id::ocid1.autonomousdatabase…, urn:opc:resource:consumer::all

Returns: tool_result, oauth_credential, password, id, success, error

OCI Identity: Delete OAuth Client Credential

oracle/identity/oauth_credential_delete · Action

Permanently delete an OAuth 2.0 client credential belonging to an Oracle Cloud IAM user, revoking its ability to obtain access tokens. Synchronous.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the OAuth credential belongs to
OAuth Credential OCIDstringRequiredocid1.credential.oc1..aaaa… of the OAuth client credential to delete

Returns: tool_result, id, success, error

OCI Identity: List OAuth Client Credentials

oracle/identity/oauth_credential_list · Action

List the OAuth 2.0 client credentials belonging to an Oracle Cloud IAM user — their OCID, name, description, scopes, expiry and lifecycle state. The client-secret value is never returned by a list (only once on create).

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… whose OAuth client credentials to list

Returns: tool_result, oauth_credentials, count, truncated, success, error

17Policy

OCI Identity: Create Policy

oracle/identity/policy_create · Action

Create an Oracle Cloud IAM policy in a compartment — one statement per line, e.g. "Allow group Admins to manage all-resources in tenancy". Statements are what actually grant access.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy — the compartment the policy governs
Policy NamestringRequiredUnique name, e.g. ops-team-access
DescriptionstringRequiredWhat this policy grants
Statements (one per line)textRequiredAllow group Admins to manage all-resources in tenancy Allow group Ops to read instances in compartment Prod
Freeform Tags (JSON)string{"team":"ops"} (optional)

Returns: tool_result, policy, id, success, error

OCI Identity: Delete Policy

oracle/identity/policy_delete · Action

Permanently delete an Oracle Cloud IAM policy by OCID — its statements stop granting access immediately. Synchronous.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the policy picker)
Policy OCID (to delete)stringRequiredocid1.policy.oc1..aaaa… of the policy to delete

Returns: tool_result, id, success, error

OCI Identity: Get Policy

oracle/identity/policy_get · Action

Fetch a single Oracle Cloud IAM policy by OCID — its name, description, compartment, statements and lifecycle state.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the policy picker)
Policy OCIDstringRequiredocid1.policy.oc1..aaaa… of the policy to fetch

Returns: tool_result, policy, id, success, error

OCI Identity: List Policies

oracle/identity/policy_list · Action

List the Oracle Cloud IAM policies in a compartment (the tenancy), optionally filtered by exact name. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (IAM policies live in the root)
Name FilterstringOnly the policy with this exact name (optional)

Returns: tool_result, policies, count, truncated, success, error

OCI Identity: Update Policy

oracle/identity/policy_update · Action

Update an Oracle Cloud IAM policy — its description, statements or freeform tags. Statements REPLACE the policy wholesale, so leave them blank to keep the current ones (they are re-sent unchanged for you).

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the policy picker)
Policy OCIDstringRequiredocid1.policy.oc1..aaaa… of the policy to update
DescriptionstringNew description (leave blank to keep the current one)
Statements (one per line)textLeave blank to keep the current statements. Anything you enter REPLACES them all. Allow group Ops to read instances in compartment Prod
Freeform Tags (JSON)string{"team":"ops"} — replaces the freeform tags (leave blank to keep them)

Returns: tool_result, policy, id, success, error

18Region

OCI Identity: List Regions

oracle/identity/region_list · Action

List every Oracle Cloud region in the catalogue — each region's 3-letter key (e.g. LHR) and name (e.g. uk-london-1).

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (not used — the region catalogue is global)

Returns: tool_result, regions, count, success, error

OCI Identity: List Region Subscriptions

oracle/identity/region_subscription_list · Action

List the Oracle Cloud regions this tenancy is subscribed to — each region's key, name, subscription status and whether it is the home region.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (region subscriptions are tenancy-scoped)

Returns: tool_result, regions, count, success, error

19Smtp

OCI Identity: Create SMTP Credential

oracle/identity/smtp_credential_create · Action

Create an SMTP credential for an Oracle Cloud IAM user — an Oracle-generated username/password pair for sending mail through Email Delivery. The password is returned ONCE here and never shown again, so capture it now.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the SMTP credential belongs to
DescriptionstringRequiredWhat this SMTP credential is for

Returns: tool_result, smtp_credential, username, password, id, success, error

OCI Identity: Delete SMTP Credential

oracle/identity/smtp_credential_delete · Action

Permanently delete an SMTP credential belonging to an Oracle Cloud IAM user, revoking its ability to send mail through the Email Delivery service. Synchronous.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the SMTP credential belongs to
SMTP Credential OCIDstringRequiredocid1.credential.oc1..aaaa… of the SMTP credential to delete

Returns: tool_result, id, success, error

OCI Identity: List SMTP Credentials

oracle/identity/smtp_credential_list · Action

List the SMTP credentials belonging to an Oracle Cloud IAM user — their OCID, SMTP username, description and lifecycle state. The credential password is never returned by a list (only once on create).

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… whose SMTP credentials to list

Returns: tool_result, smtp_credentials, count, truncated, success, error

20Swift

OCI Identity: Create Swift Password

oracle/identity/swift_password_create · Action

Create a Swift password for an Oracle Cloud IAM user — an Oracle-generated credential for Swift-client access to Object Storage. The password value is returned ONCE here and never shown again, so capture it now. (Swift passwords are deprecated in favour of auth tokens.)

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the Swift password belongs to
DescriptionstringRequiredWhat this Swift password is for

Returns: tool_result, swift_password, password, id, success, error

OCI Identity: Delete Swift Password

oracle/identity/swift_password_delete · Action

Delete a Swift password from an Oracle Cloud IAM user — permanently revokes that Object Storage Swift/RADOS credential. Give the user's OCID and the Swift password's OCID.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… the Swift password belongs to
Swift Password OCIDstringRequiredocid1.credential.oc1..aaaa… of the Swift password to delete

Returns: tool_result, id, success, error

OCI Identity: List Swift Passwords

oracle/identity/swift_password_list · Action

List the Swift passwords belonging to an Oracle Cloud IAM user — their OCID, description, lifecycle state, creation and expiry times. The password secret itself is never returned by a list (only on create). Swift passwords are deprecated in favour of auth tokens.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… whose Swift passwords to list

Returns: tool_result, swift_passwords, count, truncated, success, error

21Tag

OCI Identity: Create Tag Key

oracle/identity/tag_create · Action

Create a defined tag key inside an Oracle Cloud tag namespace. The name is unique within the namespace and cannot be changed later; enable cost tracking to have it appear on cost reports.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the picker)
Tag Namespace OCIDstringRequiredocid1.tagnamespace.oc1..aaaa… the tag key belongs to
Tag Key NamestringRequiredUnique in the namespace, e.g. CostCenter (cannot be changed later)
DescriptionstringRequiredWhat this tag key is for
Cost TrackingbooleanEnable this tag for cost tracking (default off)

Returns: tool_result, tag, id, success, error

OCI Identity: Delete Tag Key

oracle/identity/tag_delete · Action

Delete a tag key definition from an Oracle Cloud tag namespace, identified by the namespace OCID and the tag name. Asynchronous — returns a work-request id; the tag moves to DELETING then DELETED.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the picker)
Tag Namespace OCIDstringRequiredocid1.tagnamespace.oc1..aaaa… containing the tag
Tag NamestringRequiredthe tag key to delete, e.g. CostCentre

Returns: tool_result, id, work_request_id, success, error

OCI Identity: Get Tag Key

oracle/identity/tag_get · Action

Fetch a single Oracle Cloud tag key definition by its namespace OCID and tag name — its description, retired flag, cost-tracking flag and lifecycle state.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the picker)
Tag Namespace OCIDstringRequiredocid1.tagnamespace.oc1..aaaa… that contains the tag
Tag NamestringRequiredThe tag key name, e.g. CostCenter

Returns: tool_result, tag, id, success, error

OCI Identity: List Tag Keys

oracle/identity/tag_list · Action

List the tag key definitions in an Oracle Cloud tag namespace, optionally filtered by exact name. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (tag namespaces are addressed by OCID)
Tag Namespace OCIDstringRequiredocid1.tagnamespace.oc1..aaaa… — the namespace whose tag keys to list
Name FilterstringOnly the tag key with this exact name (optional)

Returns: tool_result, tags, count, truncated, success, error

OCI Identity: Create Tag Namespace

oracle/identity/tag_namespace_create · Action

Create an Oracle Cloud tag namespace — the container that holds defined tag keys. The name is unique in the tenancy and cannot be changed later.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (tag namespaces live in the root)
Namespace NamestringRequiredUnique in the tenancy, e.g. Operations (cannot be changed later)
DescriptionstringRequiredWhat this tag namespace is for
Freeform Tags (JSON)string{"team":"ops"} (optional)

Returns: tool_result, tag_namespace, id, success, error

OCI Identity: Delete Tag Namespace

oracle/identity/tag_namespace_delete · Action

Delete an Oracle Cloud tag namespace by OCID. It must be retired and empty (no tag definitions) first. Cascade delete is asynchronous — when the service returns a work-request id it is surfaced; otherwise the delete completes synchronously.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the picker)
Tag Namespace OCIDstringRequiredocid1.tagnamespace.oc1..aaaa… of the namespace to delete

Returns: tool_result, id, work_request_id, success, error

OCI Identity: Get Tag Namespace

oracle/identity/tag_namespace_get · Action

Fetch a single Oracle Cloud tag namespace by OCID — its name, description, compartment, retired flag and lifecycle state.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the picker)
Tag Namespace OCIDstringRequiredocid1.tagnamespace.oc1..aaaa… of the namespace to fetch

Returns: tool_result, tag_namespace, id, success, error

OCI Identity: List Tag Namespaces

oracle/identity/tag_namespace_list · Action

List the Oracle Cloud tag namespaces in a compartment (the tenancy), optionally including those in subcompartments. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (tag namespaces live in the root)
Include SubcompartmentsbooleanAlso list tag namespaces in subcompartments (optional)

Returns: tool_result, tag_namespaces, count, truncated, success, error

OCI Identity: Update Tag Namespace

oracle/identity/tag_namespace_update · Action

Update an Oracle Cloud tag namespace's description and/or retired state — only the fields you supply are changed.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the picker)
Tag Namespace OCIDstringRequiredocid1.tagnamespace.oc1..aaaa… of the namespace to update
DescriptionstringNew description (leave blank to keep the current one)
RetiredbooleanOn to retire the namespace, off to reactivate (leave blank to keep)

Returns: tool_result, tag_namespace, id, success, error

OCI Identity: Update Tag Key

oracle/identity/tag_update · Action

Update an Oracle Cloud tag key definition (its description, retired flag or cost-tracking flag) within a tag namespace. Only the fields you supply are changed; the tag name is immutable.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the picker)
Tag Namespace OCIDstringRequiredocid1.tagnamespace.oc1..aaaa… of the namespace holding the tag
Tag NamestringRequiredThe tag key name to update (e.g. CostCenter)
DescriptionstringNew description (leave blank to keep the current one)
RetiredbooleanRetire (true) or reactivate (false) the tag key (leave unset to keep unchanged)
Cost TrackingbooleanEnable (true) or disable (false) cost tracking (leave unset to keep unchanged)

Returns: tool_result, tag, id, success, error

22Tenancy

OCI Identity: Get Tenancy

oracle/identity/tenancy_get · Action

Fetch the Oracle Cloud tenancy (the root compartment) — its name, description and home-region key.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (unused here — the tenancy OCID is read directly)

Returns: tool_result, tenancy, id, success, error

23User

OCI Identity: Add User to Group

oracle/identity/user_add_to_group · Action

Add an Oracle Cloud IAM user to a group — creating the membership that grants the user every policy the group is named in. Returns the membership OCID (use it to remove the user later).

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user/group pickers)
User OCIDstringRequiredocid1.user.oc1..aaaa… of the user to add
Group OCIDstringRequiredocid1.group.oc1..aaaa… of the group to add them to

Returns: tool_result, membership, id, success, error

OCI Identity: Create User

oracle/identity/user_create · Action

Create an Oracle Cloud IAM user in the tenancy — the login/principal that policies grant access to. Add it to groups to give it permissions.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (IAM users live in the root)
User NamestringRequiredUnique name/login, e.g. jane.doe or an email
DescriptionstringRequiredWhat this user is for
EmailstringThe user's email (optional)
Freeform Tags (JSON)string{"team":"ops"} (optional)

Returns: tool_result, user, id, success, error

OCI Identity: Create or Reset UI Password

oracle/identity/user_create_or_reset_ui_password · Action

Create or reset an Oracle Cloud IAM user's Console (UI) sign-in password. A new one-time password is generated and returned ONCE here — it is never shown again, so capture it now. If the user already has a password, this resets it.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCIDstringRequiredocid1.user.oc1..aaaa… whose UI password to create/reset

Returns: tool_result, password, user_id, success, error

OCI Identity: Delete User

oracle/identity/user_delete · Action

Permanently delete an Oracle Cloud IAM user by OCID. Remove the user from its groups first if OCI reports it is still a member. Synchronous.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCID (to delete)stringRequiredocid1.user.oc1..aaaa… of the user to delete

Returns: tool_result, id, success, error

OCI Identity: Get User

oracle/identity/user_get · Action

Fetch a single Oracle Cloud IAM user by OCID — its name, description, email, MFA status and lifecycle state.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCID (to read)stringRequiredocid1.user.oc1..aaaa… of the user to fetch

Returns: tool_result, user, id, success, error

OCI Identity: Get UI Password Info

oracle/identity/user_get_ui_password_info · Action

Fetch metadata about an Oracle Cloud IAM user's Console (UI) password — its lifecycle state and creation time. This never returns the password itself, only whether one exists and its state.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCID (to inspect)stringRequiredocid1.user.oc1..aaaa… of the user whose UI password to inspect

Returns: tool_result, ui_password_info, id, success, error

OCI Identity: List Users

oracle/identity/user_list · Action

List the Oracle Cloud IAM users in a compartment (the tenancy), optionally filtered by exact name. Walks pagination up to a safe cap.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (IAM users live in the root)
Name FilterstringOnly the user with this exact name (optional)

Returns: tool_result, users, count, truncated, success, error

OCI Identity: Remove User from Group

oracle/identity/user_remove_from_group · Action

Remove an Oracle Cloud IAM user from a group by deleting the membership — pass the membership OCID from Add User to Group or List Memberships (not the user and group OCIDs). Synchronous.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the picker)
Membership OCIDstringRequiredocid1.usergroupmembership.oc1..aaaa… (from Add User to Group / List Memberships)

Returns: tool_result, id, success, error

OCI Identity: Update User

oracle/identity/user_update · Action

Update an Oracle Cloud IAM user's description, email and/or freeform tags — only the fields you supply are changed.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCID (to update)stringRequiredocid1.user.oc1..aaaa… of the user to update
DescriptionstringNew description (leave blank to keep the current one)
EmailstringNew email — must be unique across the tenancy (leave blank to keep)
Freeform Tags (JSON)string{"Department":"Finance"} — replaces all freeform tags (leave blank to keep)

Returns: tool_result, user, id, success, error

OCI Identity: Update User Capabilities

oracle/identity/user_update_capabilities · Action

Enable or disable an Oracle Cloud IAM user's credential capabilities (console password, API keys, auth tokens, SMTP/DB/customer-secret/OAuth2 credentials). Only the switches you set are changed; the rest are left as-is.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCID (to update)stringRequiredocid1.user.oc1..aaaa… of the user whose capabilities to change
Can Use Console PasswordbooleanAllow console login (leave unset to keep unchanged)
Can Use API KeysbooleanAllow API signing keys (leave unset to keep unchanged)
Can Use Auth TokensbooleanAllow auth/SWIFT tokens (leave unset to keep unchanged)
Can Use SMTP CredentialsbooleanAllow SMTP passwords (leave unset to keep unchanged)
Can Use DB CredentialsbooleanAllow database passwords (leave unset to keep unchanged)
Can Use Customer Secret KeysbooleanAllow SigV4 symmetric keys (leave unset to keep unchanged)
Can Use OAuth2 Client CredentialsbooleanAllow OAuth2 credentials/tokens (leave unset to keep unchanged)

Returns: tool_result, user, id, success, error

OCI Identity: Unblock User

oracle/identity/user_update_state · Action

Unblock an Oracle Cloud IAM user that was auto-blocked after repeated failed sign-ins. OCI's state API only supports unblocking — to disable a user, remove their capabilities or delete them.

FieldTypeDetails
Compartment OCIDstringLeave blank for the tenancy (scopes the user picker)
User OCID (to unblock)stringRequiredocid1.user.oc1..aaaa… of the user to unblock

Returns: tool_result, user, id, success, error

24Notes & Limitations

Behaviours and constraints worth knowing before you build with these nodes.

  • Identity is a home-region service, so every create, update and delete must target your tenancy's home region — pointing the Region field at any other region returns a clean rejection rather than silently succeeding.
  • Users, groups, policies and dynamic groups live in the tenancy root, so leaving Compartment OCID blank correctly targets the tenancy — supply a compartment OCID only when working with compartment-scoped resources.
  • Newly created secrets — auth tokens, SMTP, customer-secret, OAuth and Swift passwords, and one-time Console passwords — are shown only once at creation and are never returned again by any list action, so capture them within the same run.
  • Remove User from Group takes the membership OCID returned by Add User to Group or List Memberships, not the user OCID and group OCID together.
  • Update Policy and Update Network Source replace their statement and IP lists wholesale, so leave those fields blank to keep the existing entries unchanged.
  • Unblock User only lifts an automatic sign-in block; there is no disable switch, so to stop a user you remove their credential capabilities or delete them.