- Support
- Integrations
- Identity
Identity
Oracle Cloud integration · 90 node(s).
00Overview
Manage your entire Oracle Cloud Identity and Access Management layer from a flow — create and update users, groups and memberships, write policy statements, and organise resources into compartments. Issue and revoke every kind of user credential, from API signing keys and auth tokens to SMTP, database, OAuth and S3-compatible secret keys, and manage dynamic groups, network sources, tag namespaces and SAML federation alongside them. Read-only actions cover the tenancy, its regions and availability domains, so a flow can discover its own environment before it acts.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting Identity
- In the Oracle Cloud Console, open the Profile menu (top-right) → User settings for the IAM user the flow will act as, then under Resources choose API Keys → Add API Key.
- Let the console Generate API Key Pair (or paste your own public key), download the private key, then copy the Configuration File Preview it shows — it lists the Tenancy OCID, User OCID, Key Fingerprint and Region for the key you just added.
- Back in the node, set Authentication: Connect Oracle Cloud (the default) lets you pick a saved account in the Oracle Cloud connection field and fills the signing details for you, while API signing key (advanced) instead exposes the Tenancy OCID, User OCID, Region, Key Fingerprint and Private Key (PEM) fields to paste in by hand.
- Set Region to your tenancy's home region (e.g.
uk-london-1) — Identity is a global, home-region service, so IAM writes sent to any other region are rejected. - In Flomation, store the downloaded key as an environment secret (e.g.
identity_secret) and select it in the node's Private Key (PEM) field; supply the Private Key Passphrase only if the key is encrypted.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Connect Oracle Cloud, API signing key (advanced) | |
| Oracle Cloud connection | credential | Pick a connected Oracle Cloud account | |
| Region | string | the tenancy home region, e.g. uk-london-1 | |
| Private Key (PEM) | secret | The API signing private key — full PEM, incl. BEGIN/END lines | |
| Private Key Passphrase | secret | Only if the key is encrypted (optional) | |
| Tenancy OCID | string | ocid1.tenancy.oc1..aaaa… | |
| User OCID | string | ocid1.user.oc1..aaaa… (the caller's user, for signing) | |
| Key Fingerprint | string | aa:bb:cc:… fingerprint of the uploaded API key |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Api
OCI Identity: Delete API Key
oracle/identity/api_key_delete · Action
Remove an API signing key from an Oracle Cloud IAM user, identified by the target user's OCID and the key's fingerprint. This is permanent — the key can no longer sign requests.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID (key owner) | string | Required | ocid1.user.oc1..aaaa… of the user the key belongs to |
| API Key Fingerprint (to delete) | string | Required | aa:bb:cc:… fingerprint of the target user's API key to remove (NOT your signing key) |
Returns: tool_result, id, success, error
OCI Identity: List API Keys
oracle/identity/api_key_list · Action
List the API signing keys uploaded for an Oracle Cloud IAM user — each key's fingerprint, OCID and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID (to read) | string | Required | ocid1.user.oc1..aaaa… whose API keys to list |
Returns: tool_result, api_keys, count, truncated, success, error
OCI Identity: Upload API Key
oracle/identity/api_key_upload · Action
Upload an API signing key (the PEM RSA public key) for an Oracle Cloud IAM user — the private half stays with the caller. Returns the key's fingerprint. Each user may hold at most three API keys.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the key belongs to |
| Public Key (PEM) | text | Required | -----BEGIN PUBLIC KEY----- … the RSA public key in PEM format |
Returns: tool_result, api_key, fingerprint, id, success, error
03Auth
OCI Identity: Create Auth Token
oracle/identity/auth_token_create · Action
Create an auth token for an Oracle Cloud IAM user — a bearer credential for services that use token auth. The token value is returned ONCE here and never shown again, so capture it now.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the token belongs to |
| Description | string | Required | What this token is for |
Returns: tool_result, auth_token, token, id, success, error
OCI Identity: Delete Auth Token
oracle/identity/auth_token_delete · Action
Delete an auth token from an Oracle Cloud IAM user — permanently revokes that bearer credential. Give the user's OCID and the auth token's OCID.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the token belongs to |
| Auth Token OCID | string | Required | ocid1.credential.oc1..aaaa… of the token to delete |
Returns: tool_result, id, success, error
OCI Identity: List Auth Tokens
oracle/identity/auth_token_list · Action
List the auth tokens belonging to an Oracle Cloud IAM user — their OCID, description, lifecycle state and expiry. The token secret itself is never returned by a list (only on create).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… whose auth tokens to list |
Returns: tool_result, auth_tokens, count, truncated, success, error
OCI Identity: Update Auth Token
oracle/identity/auth_token_update · Action
Change the description of an existing Oracle Cloud IAM auth token. The token secret is never re-shown — only the description is editable.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the token belongs to |
| Auth Token OCID | string | Required | ocid1.credential.oc1..aaaa… of the auth token to update |
| Description | string | Required | The new description for this auth token |
Returns: tool_result, auth_token, id, success, error
04Authentication
OCI Identity: Get Authentication Policy
oracle/identity/authentication_policy_get · Action
Fetch the Oracle Cloud IAM authentication policy for a compartment (defaulting to the tenancy) — its password complexity rules and the network sources allowed to sign in.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (the authentication policy is read from this compartment) |
Returns: tool_result, authentication_policy, compartment_id, success, error
OCI Identity: Update Authentication Policy
oracle/identity/authentication_policy_update · Action
Update the Oracle Cloud IAM authentication (password) policy for a compartment — minimum length and the character-class requirements. Reads the current policy first and overlays only the fields you set, leaving the rest (including the network policy) untouched.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (the policy applies at the tenancy root) | |
| Minimum Password Length | integer | e.g. 12 (leave unset to keep unchanged) | |
| Require Uppercase Character | boolean | At least one A–Z required (leave unset to keep unchanged) | |
| Require Lowercase Character | boolean | At least one a–z required (leave unset to keep unchanged) | |
| Require Numeric Character | boolean | At least one 0–9 required (leave unset to keep unchanged) | |
| Require Special Character | boolean | At least one special character required (leave unset to keep unchanged) | |
| Allow Username In Password | boolean | Permit the user name to appear in the password (leave unset to keep unchanged) |
Returns: tool_result, policy, compartment_id, success, error
05Availability
OCI Identity: List Availability Domains
oracle/identity/availability_domain_list · Action
List the availability domains visible to a compartment (the tenancy) — each one's name and OCID. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (availability domains are tenancy-scoped) |
Returns: tool_result, availability_domains, count, truncated, success, error
06Compartment
OCI Identity: Create Compartment
oracle/identity/compartment_create · Action
Create an Oracle Cloud compartment under a parent (or the tenancy root) — the container that groups and isolates resources for access control and billing.
| Field | Type | Details | |
|---|---|---|---|
| Parent Compartment OCID | string | Leave blank for the tenancy root — the parent to create under | |
| Compartment Name | string | Required | Unique name within the parent, e.g. Prod |
| Description | string | Required | What this compartment holds |
| Freeform Tags (JSON) | string | {"env":"prod"} (optional) |
Returns: tool_result, compartment, id, success, error
OCI Identity: Delete Compartment
oracle/identity/compartment_delete · Action
Delete an Oracle Cloud compartment by OCID. The compartment must be empty first. Asynchronous — returns a work-request id; the compartment moves to DELETING then DELETED.
| Field | Type | Details | |
|---|---|---|---|
| Parent Compartment OCID | string | Leave blank for the tenancy (scopes the compartment picker) | |
| Compartment OCID (to delete) | string | Required | ocid1.compartment.oc1..aaaa… of the compartment to delete |
Returns: tool_result, id, work_request_id, success, error
OCI Identity: Get Compartment
oracle/identity/compartment_get · Action
Fetch a single Oracle Cloud IAM compartment by OCID — its name, description, parent, accessibility and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the compartment picker) | |
| Compartment OCID (to read) | string | Required | ocid1.compartment.oc1..aaaa… of the compartment to fetch |
Returns: tool_result, compartment, id, success, error
OCI Identity: List Compartments
oracle/identity/compartment_list · Action
List the Oracle Cloud compartments under a parent compartment (leave blank for the tenancy root). Optionally traverse the full subtree. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Parent Compartment OCID | string | Leave blank for the tenancy (lists the root's children) | |
| Include Subtree | boolean | List every descendant compartment, not just direct children (tenancy root only) |
Returns: tool_result, compartments, count, truncated, success, error
OCI Identity: Move Compartment
oracle/identity/compartment_move · Action
Move an Oracle Cloud compartment (and its contents) into a different parent compartment. Asynchronous — returns a work-request id to track the move.
| Field | Type | Details | |
|---|---|---|---|
| Parent Compartment OCID | string | Leave blank for the tenancy (scopes the compartment picker) | |
| Compartment OCID (to move) | string | Required | ocid1.compartment.oc1..aaaa… of the compartment to move |
| Destination Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… of the new parent (or the tenancy) |
Returns: tool_result, id, work_request_id, success, error
OCI Identity: Recover Compartment
oracle/identity/compartment_recover · Action
Recover (un-delete) a previously deleted Oracle Cloud IAM compartment by OCID, returning it to the active state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the compartment picker) | |
| Compartment OCID (to recover) | string | Required | ocid1.compartment.oc1..aaaa… of the deleted compartment |
Returns: tool_result, compartment, id, success, error
OCI Identity: Update Compartment
oracle/identity/compartment_update · Action
Update an Oracle Cloud compartment's name, description and/or freeform tags — only the fields you supply are changed.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the compartment picker) | |
| Compartment OCID (to update) | string | Required | ocid1.compartment.oc1..aaaa… of the compartment to update |
| Name | string | New name — must be unique within the parent (leave blank to keep) | |
| Description | string | New description (leave blank to keep the current one) | |
| Freeform Tags (JSON) | string | {"env":"prod"} — replaces all freeform tags (leave blank to keep) |
Returns: tool_result, compartment, id, success, error
07Customer
OCI Identity: Create Customer Secret Key
oracle/identity/customer_secret_key_create · Action
Create a customer secret key for an Oracle Cloud IAM user — an access-key/secret-key pair for Object Storage's Amazon S3-compatible API. The secret key value is returned ONCE here and never shown again, so capture it now.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the secret key belongs to |
| Display Name | string | Required | A name for this secret key (need not be unique) |
Returns: tool_result, customer_secret_key, key, id, success, error
OCI Identity: Delete Customer Secret Key
oracle/identity/customer_secret_key_delete · Action
Permanently delete a customer secret key (an S3-compatible Access Key / Secret Key pair) from an Oracle Cloud IAM user. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the secret key belongs to |
| Customer Secret Key OCID | string | Required | ocid1.credential.oc1..aaaa… of the secret key to delete |
Returns: tool_result, id, success, error
OCI Identity: List Customer Secret Keys
oracle/identity/customer_secret_key_list · Action
List the customer secret keys belonging to an Oracle Cloud IAM user (used with Object Storage's S3-compatible API) — their OCID, display name, lifecycle state and creation time. The secret key itself is never returned by a list (only on create).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… whose customer secret keys to list |
Returns: tool_result, customer_secret_keys, count, truncated, success, error
08Db
OCI Identity: Create DB Credential
oracle/identity/db_credential_create · Action
Create a database credential for an Oracle Cloud IAM user — used to authenticate a cloud database to Identity. You supply the password here (it is not generated), so store it yourself; OCI never returns it again.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the DB credential belongs to |
| Description | string | Required | What this DB credential is for |
| DB Password | secret | Required | The password to set on the DB credential — store it yourself, OCI never returns it |
Returns: tool_result, db_credential, id, success, error
OCI Identity: Delete DB Credential
oracle/identity/db_credential_delete · Action
Permanently delete a database (DB) credential from an Oracle Cloud IAM user. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the DB credential belongs to |
| DB Credential OCID | string | Required | ocid1.dbcredential.oc1..aaaa… of the DB credential to delete |
Returns: tool_result, id, success, error
OCI Identity: List DB Credentials
oracle/identity/db_credential_list · Action
List the DB credentials belonging to an Oracle Cloud IAM user — their OCID, description, lifecycle state, creation and expiry times. The credential secret itself is never returned by a list (only on create).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… whose DB credentials to list |
Returns: tool_result, db_credentials, count, truncated, success, error
09Dynamic
OCI Identity: Create Dynamic Group
oracle/identity/dynamic_group_create · Action
Create an Oracle Cloud dynamic group — members are resources (compute instances, functions…) matched by a rule, so policies can grant permissions to workloads without static credentials.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (dynamic groups live in the root) | |
| Dynamic Group Name | string | Required | Unique name, e.g. prod-instances |
| Description | string | Required | What this dynamic group is for |
| Matching Rule | text | Required | e.g. ALL {instance.compartment.id = 'ocid1.compartment.oc1..aaaa…'} |
| Freeform Tags (JSON) | string | {"env":"prod"} (optional) |
Returns: tool_result, dynamic_group, id, success, error
OCI Identity: Delete Dynamic Group
oracle/identity/dynamic_group_delete · Action
Permanently delete an Oracle Cloud IAM dynamic group by OCID. Any policies that grant it access stop matching once it is gone. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the dynamic group picker) | |
| Dynamic Group OCID (to delete) | string | Required | ocid1.dynamicgroup.oc1..aaaa… of the dynamic group to delete |
Returns: tool_result, id, success, error
OCI Identity: Get Dynamic Group
oracle/identity/dynamic_group_get · Action
Fetch a single Oracle Cloud IAM dynamic group by OCID — its name, description, matching rule and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the dynamic group picker) | |
| Dynamic Group OCID | string | Required | ocid1.dynamicgroup.oc1..aaaa… of the dynamic group to fetch |
Returns: tool_result, dynamic_group, id, success, error
OCI Identity: List Dynamic Groups
oracle/identity/dynamic_group_list · Action
List the Oracle Cloud IAM dynamic groups in a compartment (the tenancy), optionally filtered by exact name. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (IAM dynamic groups live in the root) | |
| Name Filter | string | Only the dynamic group with this exact name (optional) |
Returns: tool_result, dynamic_groups, count, truncated, success, error
OCI Identity: Update Dynamic Group
oracle/identity/dynamic_group_update · Action
Update an Oracle Cloud dynamic group's description, matching rule and/or freeform tags — only the fields you supply are changed.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (dynamic groups live in the root) | |
| Dynamic Group OCID | string | Required | ocid1.dynamicgroup.oc1..aaaa… of the dynamic group to update |
| Description | string | New description (leave blank to keep the current one) | |
| Matching Rule | text | New rule, e.g. ALL {instance.compartment.id = 'ocid1.compartment.oc1..aaaa…'} (leave blank to keep) | |
| Freeform Tags (JSON) | string | {"env":"prod"} — replaces all freeform tags (leave blank to keep) |
Returns: tool_result, dynamic_group, id, success, error
10Group
OCI Identity: Create Group
oracle/identity/group_create · Action
Create an Oracle Cloud IAM group in the tenancy — a named set of users that policies grant permissions to. Add users with Add User to Group.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (IAM groups live in the root) | |
| Group Name | string | Required | Unique name, e.g. Administrators |
| Description | string | Required | What this group is for |
| Freeform Tags (JSON) | string | {"team":"ops"} (optional) |
Returns: tool_result, group, id, success, error
OCI Identity: Delete Group
oracle/identity/group_delete · Action
Permanently delete an Oracle Cloud IAM group by OCID. Remove its members first if OCI reports it is not empty. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the group picker) | |
| Group OCID (to delete) | string | Required | ocid1.group.oc1..aaaa… of the group to delete |
Returns: tool_result, id, success, error
OCI Identity: Get Group
oracle/identity/group_get · Action
Fetch a single Oracle Cloud IAM group by OCID — its name, description, compartment and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the group picker) | |
| Group OCID | string | Required | ocid1.group.oc1..aaaa… of the group to fetch |
Returns: tool_result, group, id, success, error
OCI Identity: List Groups
oracle/identity/group_list · Action
List the Oracle Cloud IAM groups in a compartment (the tenancy), optionally filtered by exact name. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (IAM groups live in the root) | |
| Name Filter | string | Only the group with this exact name (optional) |
Returns: tool_result, groups, count, truncated, success, error
OCI Identity: Update Group
oracle/identity/group_update · Action
Update an Oracle Cloud IAM group's description and/or freeform tags. Only the fields you supply are changed; the group name is immutable.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (IAM groups live in the root) | |
| Group OCID | string | Required | ocid1.group.oc1..aaaa… of the group to update |
| Description | string | New description (leave blank to keep the current one) | |
| Freeform Tags (JSON) | string | {"team":"ops"} — replaces all freeform tags (leave blank to keep current) |
Returns: tool_result, group, id, success, error
11Identity
OCI Identity: Create Identity Provider
oracle/identity/identity_provider_create · Action
Create a SAML2 federation identity provider in an Oracle Cloud tenancy — trust an external IdP (IDCS or ADFS) by supplying its SAML metadata XML so its users can federate in.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (identity providers live in the root) | |
| Name | string | Required | Unique IdP name, cannot be changed later, e.g. corp-adfs |
| Description | string | Required | What this identity provider is for |
| Product Type | string | Required | IDCS or ADFS |
| SAML Metadata XML | text | Required | Paste the IdP's SAML 2.0 metadata XML (the full <EntityDescriptor>…</EntityDescriptor>) |
| Metadata URL | string | URL the IdP metadata was retrieved from (optional) | |
| Freeform Attributes (JSON) | string | {"clientId":"app_sf3kdjf3"} (optional) | |
| Freeform Tags (JSON) | string | {"team":"ops"} (optional) |
Returns: tool_result, identity_provider, id, success, error
OCI Identity: Delete Identity Provider
oracle/identity/identity_provider_delete · Action
Permanently delete an Oracle Cloud IAM identity provider by OCID. Remove its group mappings first if OCI reports they still exist. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the identity-provider picker) | |
| Identity Provider OCID (to delete) | string | Required | ocid1.saml2idp.oc1..aaaa… of the identity provider to delete |
Returns: tool_result, id, success, error
OCI Identity: Get Identity Provider
oracle/identity/identity_provider_get · Action
Fetch a single Oracle Cloud IAM identity provider by OCID — its name, product type, protocol and (for SAML2) metadata/redirect URLs and signing certificate.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (identity providers live in the tenancy) | |
| Identity Provider OCID | string | Required | ocid1.saml2idp.oc1..aaaa… of the identity provider to fetch |
Returns: tool_result, identity_provider, id, success, error
OCI Identity: List Identity Providers
oracle/identity/identity_provider_list · Action
List the federated identity providers configured on an Oracle Cloud tenancy for a given federation protocol (e.g. SAML2). Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (identity providers live in the root) | |
| Protocol | string | Federation protocol — SAML2 (default) |
Returns: tool_result, identity_providers, count, truncated, success, error
12Idp
OCI Identity: Create IdP Group Mapping
oracle/identity/idp_group_mapping_create · Action
Map an Oracle Cloud identity provider (IdP) group to an IAM Service group, so federated users in that IdP group inherit the IAM group's access.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the group picker) | |
| Identity Provider OCID | string | Required | ocid1.saml2idp.oc1..aaaa… the IdP to map from |
| IdP Group Name | string | Required | The name of the group as defined in the identity provider |
| IAM Group OCID | string | Required | ocid1.group.oc1..aaaa… the IAM Service group to map to |
Returns: tool_result, idp_group_mapping, id, success, error
OCI Identity: Delete IdP Group Mapping
oracle/identity/idp_group_mapping_delete · Action
Delete a single group mapping (the link between an identity-provider group and an Oracle Cloud IAM group) by its OCID. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the identity-provider picker) | |
| Identity Provider OCID | string | Required | ocid1.saml2idp.oc1..aaaa… the mapping belongs to |
| Group Mapping OCID (to delete) | string | Required | ocid1.idpgroupmapping.oc1..aaaa… of the mapping to delete |
Returns: tool_result, id, success, error
OCI Identity: List IdP Group Mappings
oracle/identity/idp_group_mapping_list · Action
List the group mappings for an Oracle Cloud identity provider — each links one federated IdP group to one IAM group. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (not used by this action) | |
| Identity Provider OCID | string | Required | ocid1.saml2idp.oc1..aaaa… of the IdP whose mappings to list |
Returns: tool_result, mappings, count, truncated, success, error
13Membership
OCI Identity: Get Group Membership
oracle/identity/membership_get · Action
Fetch a single Oracle Cloud IAM user-group membership by OCID — the user, group and compartment it ties together, plus its lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the pickers) | |
| Membership OCID | string | Required | ocid1.usergroupmembership.oc1..aaaa… of the membership to fetch |
Returns: tool_result, membership, id, success, error
OCI Identity: List Group Memberships
oracle/identity/membership_list · Action
List the Oracle Cloud IAM user-group memberships in a compartment (the tenancy), optionally filtered by a user OCID and/or a group OCID. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (IAM memberships live in the root) | |
| User OCID Filter | string | ocid1.user.oc1..aaaa… — only this user's memberships (optional) | |
| Group OCID Filter | string | ocid1.group.oc1..aaaa… — only this group's memberships (optional) |
Returns: tool_result, memberships, count, truncated, success, error
14Mfa
OCI Identity: Activate MFA TOTP Device
oracle/identity/mfa_totp_activate · Action
Activate a user's MFA TOTP device by submitting the 6-digit code from their authenticator app — the device must be activated before it can be used for sign-in.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID (device owner) | string | Required | ocid1.user.oc1..aaaa… of the user the device belongs to |
| MFA TOTP Device OCID | string | Required | ocid1.mfatotpdevice.oc1..aaaa… |
| TOTP Code | string | Required | the 6-digit code from the authenticator app |
Returns: tool_result, device, id, success, error
OCI Identity: Create MFA TOTP Device
oracle/identity/mfa_totp_create · Action
Register a multi-factor-authentication TOTP device for an Oracle Cloud IAM user. This starts enrolment: the device comes back in the CREATING state — you must then generate its seed and activate it (with a TOTP code) to finish, and MFA registration ultimately requires the Console.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the MFA device belongs to |
Returns: tool_result, mfa_totp_device, id, success, error
OCI Identity: Delete MFA TOTP Device
oracle/identity/mfa_totp_delete · Action
Delete an MFA TOTP device from an Oracle Cloud IAM user — removes that authenticator so the user must re-enrol to use MFA again. Give the user's OCID and the MFA TOTP device's OCID.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the device belongs to |
| MFA TOTP Device OCID | string | Required | ocid1.mfatotpdevice.oc1..aaaa… of the device to delete |
Returns: tool_result, id, success, error
OCI Identity: Get MFA TOTP Device
oracle/identity/mfa_totp_get · Action
Fetch a single Oracle Cloud IAM MFA TOTP device by OCID — its lifecycle state, whether it is activated, and its creation/expiry times.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID (device owner) | string | Required | ocid1.user.oc1..aaaa… of the user the MFA device belongs to |
| MFA TOTP Device OCID | string | Required | ocid1.mfatotpdevice.oc1..aaaa… of the device to fetch |
Returns: tool_result, mfa_totp_device, id, success, error
OCI Identity: List MFA TOTP Devices
oracle/identity/mfa_totp_list · Action
List the MFA TOTP (authenticator-app) devices registered for an Oracle Cloud IAM user — each device's OCID, activation flag and lifecycle state. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID (to read) | string | Required | ocid1.user.oc1..aaaa… whose MFA TOTP devices to list |
Returns: tool_result, mfa_totp_devices, count, truncated, success, error
15Network
OCI Identity: Create Network Source
oracle/identity/network_source_create · Action
Create an Oracle Cloud IAM network source — a named list of allowed public IPs/CIDR ranges you can reference in policy statements to restrict access by source IP.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (network sources live in the root compartment) | |
| Name | string | Required | Unique network-source name (cannot be changed later) |
| Description | string | Required | What this network source is for |
| Public Source List | string | Comma-separated public IPs / CIDR ranges, e.g. 129.213.39.0/24, 203.0.113.5 | |
| Services | string | Comma-separated services, e.g. all (reserved by Oracle — usually left blank) |
Returns: tool_result, network_source, id, success, error
OCI Identity: Delete Network Source
oracle/identity/network_source_delete · Action
Permanently delete an Oracle Cloud IAM network source by OCID. Detach it from any policies that reference it first if OCI reports it is in use. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the network source picker) | |
| Network Source OCID (to delete) | string | Required | ocid1.networksource.oc1..aaaa… of the network source to delete |
Returns: tool_result, id, success, error
OCI Identity: Get Network Source
oracle/identity/network_source_get · Action
Fetch a single Oracle Cloud IAM network source by OCID — its name, description, allowed public IP/CIDR list, VCN source list and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the network-source picker) | |
| Network Source OCID | string | Required | ocid1.networksource.oc1..aaaa… of the network source to fetch |
Returns: tool_result, network_source, id, success, error
OCI Identity: List Network Sources
oracle/identity/network_source_list · Action
List the Oracle Cloud IAM network sources in a compartment (the tenancy), optionally filtered by exact name — with their allowed public IP/CIDR and VCN source lists. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (network sources live in the root) | |
| Name Filter | string | Only the network source with this exact name (optional) |
Returns: tool_result, network_sources, count, truncated, success, error
OCI Identity: Update Network Source
oracle/identity/network_source_update · Action
Update an Oracle Cloud IAM network source — its description, allowed public IP/CIDR list or services. The IP list and services REPLACE wholesale, so leave one blank to keep the current values (they are re-sent unchanged for you, along with the untouched VCN/virtual source list).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the network source picker) | |
| Network Source OCID | string | Required | ocid1.networksource.oc1..aaaa… of the network source to update |
| Description | string | New description (leave blank to keep the current one) | |
| Public IP/CIDR List (comma-separated) | string | 203.0.113.0/24, 198.51.100.5 — REPLACES the list (leave blank to keep it) | |
| Services (comma-separated) | string | Reserved by Oracle — usually blank; REPLACES the list (leave blank to keep it) |
Returns: tool_result, network_source, id, success, error
16Oauth
OCI Identity: Create OAuth Client Credential
oracle/identity/oauth_credential_create · Action
Create an OAuth 2.0 client credential for an Oracle Cloud IAM user — a client-id/secret pair for the OAuth client-credentials grant. The secret (password) is returned ONCE here and never shown again, so capture it now.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the OAuth credential belongs to |
| Name | string | Required | A label to tell this credential apart |
| Description | string | Required | What this OAuth credential is for |
| Scopes | text | Required | One scope per line, as `audience, scope` — e.g. urn:oracle:db::id::ocid1.autonomousdatabase…, urn:opc:resource:consumer::all |
Returns: tool_result, oauth_credential, password, id, success, error
OCI Identity: Delete OAuth Client Credential
oracle/identity/oauth_credential_delete · Action
Permanently delete an OAuth 2.0 client credential belonging to an Oracle Cloud IAM user, revoking its ability to obtain access tokens. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the OAuth credential belongs to |
| OAuth Credential OCID | string | Required | ocid1.credential.oc1..aaaa… of the OAuth client credential to delete |
Returns: tool_result, id, success, error
OCI Identity: List OAuth Client Credentials
oracle/identity/oauth_credential_list · Action
List the OAuth 2.0 client credentials belonging to an Oracle Cloud IAM user — their OCID, name, description, scopes, expiry and lifecycle state. The client-secret value is never returned by a list (only once on create).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… whose OAuth client credentials to list |
Returns: tool_result, oauth_credentials, count, truncated, success, error
17Policy
OCI Identity: Create Policy
oracle/identity/policy_create · Action
Create an Oracle Cloud IAM policy in a compartment — one statement per line, e.g. "Allow group Admins to manage all-resources in tenancy". Statements are what actually grant access.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy — the compartment the policy governs | |
| Policy Name | string | Required | Unique name, e.g. ops-team-access |
| Description | string | Required | What this policy grants |
| Statements (one per line) | text | Required | Allow group Admins to manage all-resources in tenancy Allow group Ops to read instances in compartment Prod |
| Freeform Tags (JSON) | string | {"team":"ops"} (optional) |
Returns: tool_result, policy, id, success, error
OCI Identity: Delete Policy
oracle/identity/policy_delete · Action
Permanently delete an Oracle Cloud IAM policy by OCID — its statements stop granting access immediately. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the policy picker) | |
| Policy OCID (to delete) | string | Required | ocid1.policy.oc1..aaaa… of the policy to delete |
Returns: tool_result, id, success, error
OCI Identity: Get Policy
oracle/identity/policy_get · Action
Fetch a single Oracle Cloud IAM policy by OCID — its name, description, compartment, statements and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the policy picker) | |
| Policy OCID | string | Required | ocid1.policy.oc1..aaaa… of the policy to fetch |
Returns: tool_result, policy, id, success, error
OCI Identity: List Policies
oracle/identity/policy_list · Action
List the Oracle Cloud IAM policies in a compartment (the tenancy), optionally filtered by exact name. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (IAM policies live in the root) | |
| Name Filter | string | Only the policy with this exact name (optional) |
Returns: tool_result, policies, count, truncated, success, error
OCI Identity: Update Policy
oracle/identity/policy_update · Action
Update an Oracle Cloud IAM policy — its description, statements or freeform tags. Statements REPLACE the policy wholesale, so leave them blank to keep the current ones (they are re-sent unchanged for you).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the policy picker) | |
| Policy OCID | string | Required | ocid1.policy.oc1..aaaa… of the policy to update |
| Description | string | New description (leave blank to keep the current one) | |
| Statements (one per line) | text | Leave blank to keep the current statements. Anything you enter REPLACES them all. Allow group Ops to read instances in compartment Prod | |
| Freeform Tags (JSON) | string | {"team":"ops"} — replaces the freeform tags (leave blank to keep them) |
Returns: tool_result, policy, id, success, error
18Region
OCI Identity: List Regions
oracle/identity/region_list · Action
List every Oracle Cloud region in the catalogue — each region's 3-letter key (e.g. LHR) and name (e.g. uk-london-1).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (not used — the region catalogue is global) |
Returns: tool_result, regions, count, success, error
OCI Identity: List Region Subscriptions
oracle/identity/region_subscription_list · Action
List the Oracle Cloud regions this tenancy is subscribed to — each region's key, name, subscription status and whether it is the home region.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (region subscriptions are tenancy-scoped) |
Returns: tool_result, regions, count, success, error
19Smtp
OCI Identity: Create SMTP Credential
oracle/identity/smtp_credential_create · Action
Create an SMTP credential for an Oracle Cloud IAM user — an Oracle-generated username/password pair for sending mail through Email Delivery. The password is returned ONCE here and never shown again, so capture it now.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the SMTP credential belongs to |
| Description | string | Required | What this SMTP credential is for |
Returns: tool_result, smtp_credential, username, password, id, success, error
OCI Identity: Delete SMTP Credential
oracle/identity/smtp_credential_delete · Action
Permanently delete an SMTP credential belonging to an Oracle Cloud IAM user, revoking its ability to send mail through the Email Delivery service. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the SMTP credential belongs to |
| SMTP Credential OCID | string | Required | ocid1.credential.oc1..aaaa… of the SMTP credential to delete |
Returns: tool_result, id, success, error
OCI Identity: List SMTP Credentials
oracle/identity/smtp_credential_list · Action
List the SMTP credentials belonging to an Oracle Cloud IAM user — their OCID, SMTP username, description and lifecycle state. The credential password is never returned by a list (only once on create).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… whose SMTP credentials to list |
Returns: tool_result, smtp_credentials, count, truncated, success, error
20Swift
OCI Identity: Create Swift Password
oracle/identity/swift_password_create · Action
Create a Swift password for an Oracle Cloud IAM user — an Oracle-generated credential for Swift-client access to Object Storage. The password value is returned ONCE here and never shown again, so capture it now. (Swift passwords are deprecated in favour of auth tokens.)
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the Swift password belongs to |
| Description | string | Required | What this Swift password is for |
Returns: tool_result, swift_password, password, id, success, error
OCI Identity: Delete Swift Password
oracle/identity/swift_password_delete · Action
Delete a Swift password from an Oracle Cloud IAM user — permanently revokes that Object Storage Swift/RADOS credential. Give the user's OCID and the Swift password's OCID.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… the Swift password belongs to |
| Swift Password OCID | string | Required | ocid1.credential.oc1..aaaa… of the Swift password to delete |
Returns: tool_result, id, success, error
OCI Identity: List Swift Passwords
oracle/identity/swift_password_list · Action
List the Swift passwords belonging to an Oracle Cloud IAM user — their OCID, description, lifecycle state, creation and expiry times. The password secret itself is never returned by a list (only on create). Swift passwords are deprecated in favour of auth tokens.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… whose Swift passwords to list |
Returns: tool_result, swift_passwords, count, truncated, success, error
21Tag
OCI Identity: Create Tag Key
oracle/identity/tag_create · Action
Create a defined tag key inside an Oracle Cloud tag namespace. The name is unique within the namespace and cannot be changed later; enable cost tracking to have it appear on cost reports.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the picker) | |
| Tag Namespace OCID | string | Required | ocid1.tagnamespace.oc1..aaaa… the tag key belongs to |
| Tag Key Name | string | Required | Unique in the namespace, e.g. CostCenter (cannot be changed later) |
| Description | string | Required | What this tag key is for |
| Cost Tracking | boolean | Enable this tag for cost tracking (default off) |
Returns: tool_result, tag, id, success, error
OCI Identity: Delete Tag Key
oracle/identity/tag_delete · Action
Delete a tag key definition from an Oracle Cloud tag namespace, identified by the namespace OCID and the tag name. Asynchronous — returns a work-request id; the tag moves to DELETING then DELETED.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the picker) | |
| Tag Namespace OCID | string | Required | ocid1.tagnamespace.oc1..aaaa… containing the tag |
| Tag Name | string | Required | the tag key to delete, e.g. CostCentre |
Returns: tool_result, id, work_request_id, success, error
OCI Identity: Get Tag Key
oracle/identity/tag_get · Action
Fetch a single Oracle Cloud tag key definition by its namespace OCID and tag name — its description, retired flag, cost-tracking flag and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the picker) | |
| Tag Namespace OCID | string | Required | ocid1.tagnamespace.oc1..aaaa… that contains the tag |
| Tag Name | string | Required | The tag key name, e.g. CostCenter |
Returns: tool_result, tag, id, success, error
OCI Identity: List Tag Keys
oracle/identity/tag_list · Action
List the tag key definitions in an Oracle Cloud tag namespace, optionally filtered by exact name. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (tag namespaces are addressed by OCID) | |
| Tag Namespace OCID | string | Required | ocid1.tagnamespace.oc1..aaaa… — the namespace whose tag keys to list |
| Name Filter | string | Only the tag key with this exact name (optional) |
Returns: tool_result, tags, count, truncated, success, error
OCI Identity: Create Tag Namespace
oracle/identity/tag_namespace_create · Action
Create an Oracle Cloud tag namespace — the container that holds defined tag keys. The name is unique in the tenancy and cannot be changed later.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (tag namespaces live in the root) | |
| Namespace Name | string | Required | Unique in the tenancy, e.g. Operations (cannot be changed later) |
| Description | string | Required | What this tag namespace is for |
| Freeform Tags (JSON) | string | {"team":"ops"} (optional) |
Returns: tool_result, tag_namespace, id, success, error
OCI Identity: Delete Tag Namespace
oracle/identity/tag_namespace_delete · Action
Delete an Oracle Cloud tag namespace by OCID. It must be retired and empty (no tag definitions) first. Cascade delete is asynchronous — when the service returns a work-request id it is surfaced; otherwise the delete completes synchronously.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the picker) | |
| Tag Namespace OCID | string | Required | ocid1.tagnamespace.oc1..aaaa… of the namespace to delete |
Returns: tool_result, id, work_request_id, success, error
OCI Identity: Get Tag Namespace
oracle/identity/tag_namespace_get · Action
Fetch a single Oracle Cloud tag namespace by OCID — its name, description, compartment, retired flag and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the picker) | |
| Tag Namespace OCID | string | Required | ocid1.tagnamespace.oc1..aaaa… of the namespace to fetch |
Returns: tool_result, tag_namespace, id, success, error
OCI Identity: List Tag Namespaces
oracle/identity/tag_namespace_list · Action
List the Oracle Cloud tag namespaces in a compartment (the tenancy), optionally including those in subcompartments. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (tag namespaces live in the root) | |
| Include Subcompartments | boolean | Also list tag namespaces in subcompartments (optional) |
Returns: tool_result, tag_namespaces, count, truncated, success, error
OCI Identity: Update Tag Namespace
oracle/identity/tag_namespace_update · Action
Update an Oracle Cloud tag namespace's description and/or retired state — only the fields you supply are changed.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the picker) | |
| Tag Namespace OCID | string | Required | ocid1.tagnamespace.oc1..aaaa… of the namespace to update |
| Description | string | New description (leave blank to keep the current one) | |
| Retired | boolean | On to retire the namespace, off to reactivate (leave blank to keep) |
Returns: tool_result, tag_namespace, id, success, error
OCI Identity: Update Tag Key
oracle/identity/tag_update · Action
Update an Oracle Cloud tag key definition (its description, retired flag or cost-tracking flag) within a tag namespace. Only the fields you supply are changed; the tag name is immutable.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the picker) | |
| Tag Namespace OCID | string | Required | ocid1.tagnamespace.oc1..aaaa… of the namespace holding the tag |
| Tag Name | string | Required | The tag key name to update (e.g. CostCenter) |
| Description | string | New description (leave blank to keep the current one) | |
| Retired | boolean | Retire (true) or reactivate (false) the tag key (leave unset to keep unchanged) | |
| Cost Tracking | boolean | Enable (true) or disable (false) cost tracking (leave unset to keep unchanged) |
Returns: tool_result, tag, id, success, error
22Tenancy
OCI Identity: Get Tenancy
oracle/identity/tenancy_get · Action
Fetch the Oracle Cloud tenancy (the root compartment) — its name, description and home-region key.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (unused here — the tenancy OCID is read directly) |
Returns: tool_result, tenancy, id, success, error
23User
OCI Identity: Add User to Group
oracle/identity/user_add_to_group · Action
Add an Oracle Cloud IAM user to a group — creating the membership that grants the user every policy the group is named in. Returns the membership OCID (use it to remove the user later).
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user/group pickers) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… of the user to add |
| Group OCID | string | Required | ocid1.group.oc1..aaaa… of the group to add them to |
Returns: tool_result, membership, id, success, error
OCI Identity: Create User
oracle/identity/user_create · Action
Create an Oracle Cloud IAM user in the tenancy — the login/principal that policies grant access to. Add it to groups to give it permissions.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (IAM users live in the root) | |
| User Name | string | Required | Unique name/login, e.g. jane.doe or an email |
| Description | string | Required | What this user is for |
string | The user's email (optional) | ||
| Freeform Tags (JSON) | string | {"team":"ops"} (optional) |
Returns: tool_result, user, id, success, error
OCI Identity: Create or Reset UI Password
oracle/identity/user_create_or_reset_ui_password · Action
Create or reset an Oracle Cloud IAM user's Console (UI) sign-in password. A new one-time password is generated and returned ONCE here — it is never shown again, so capture it now. If the user already has a password, this resets it.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID | string | Required | ocid1.user.oc1..aaaa… whose UI password to create/reset |
Returns: tool_result, password, user_id, success, error
OCI Identity: Delete User
oracle/identity/user_delete · Action
Permanently delete an Oracle Cloud IAM user by OCID. Remove the user from its groups first if OCI reports it is still a member. Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID (to delete) | string | Required | ocid1.user.oc1..aaaa… of the user to delete |
Returns: tool_result, id, success, error
OCI Identity: Get User
oracle/identity/user_get · Action
Fetch a single Oracle Cloud IAM user by OCID — its name, description, email, MFA status and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID (to read) | string | Required | ocid1.user.oc1..aaaa… of the user to fetch |
Returns: tool_result, user, id, success, error
OCI Identity: Get UI Password Info
oracle/identity/user_get_ui_password_info · Action
Fetch metadata about an Oracle Cloud IAM user's Console (UI) password — its lifecycle state and creation time. This never returns the password itself, only whether one exists and its state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID (to inspect) | string | Required | ocid1.user.oc1..aaaa… of the user whose UI password to inspect |
Returns: tool_result, ui_password_info, id, success, error
OCI Identity: List Users
oracle/identity/user_list · Action
List the Oracle Cloud IAM users in a compartment (the tenancy), optionally filtered by exact name. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (IAM users live in the root) | |
| Name Filter | string | Only the user with this exact name (optional) |
Returns: tool_result, users, count, truncated, success, error
OCI Identity: Remove User from Group
oracle/identity/user_remove_from_group · Action
Remove an Oracle Cloud IAM user from a group by deleting the membership — pass the membership OCID from Add User to Group or List Memberships (not the user and group OCIDs). Synchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the picker) | |
| Membership OCID | string | Required | ocid1.usergroupmembership.oc1..aaaa… (from Add User to Group / List Memberships) |
Returns: tool_result, id, success, error
OCI Identity: Update User
oracle/identity/user_update · Action
Update an Oracle Cloud IAM user's description, email and/or freeform tags — only the fields you supply are changed.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID (to update) | string | Required | ocid1.user.oc1..aaaa… of the user to update |
| Description | string | New description (leave blank to keep the current one) | |
string | New email — must be unique across the tenancy (leave blank to keep) | ||
| Freeform Tags (JSON) | string | {"Department":"Finance"} — replaces all freeform tags (leave blank to keep) |
Returns: tool_result, user, id, success, error
OCI Identity: Update User Capabilities
oracle/identity/user_update_capabilities · Action
Enable or disable an Oracle Cloud IAM user's credential capabilities (console password, API keys, auth tokens, SMTP/DB/customer-secret/OAuth2 credentials). Only the switches you set are changed; the rest are left as-is.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID (to update) | string | Required | ocid1.user.oc1..aaaa… of the user whose capabilities to change |
| Can Use Console Password | boolean | Allow console login (leave unset to keep unchanged) | |
| Can Use API Keys | boolean | Allow API signing keys (leave unset to keep unchanged) | |
| Can Use Auth Tokens | boolean | Allow auth/SWIFT tokens (leave unset to keep unchanged) | |
| Can Use SMTP Credentials | boolean | Allow SMTP passwords (leave unset to keep unchanged) | |
| Can Use DB Credentials | boolean | Allow database passwords (leave unset to keep unchanged) | |
| Can Use Customer Secret Keys | boolean | Allow SigV4 symmetric keys (leave unset to keep unchanged) | |
| Can Use OAuth2 Client Credentials | boolean | Allow OAuth2 credentials/tokens (leave unset to keep unchanged) |
Returns: tool_result, user, id, success, error
OCI Identity: Unblock User
oracle/identity/user_update_state · Action
Unblock an Oracle Cloud IAM user that was auto-blocked after repeated failed sign-ins. OCI's state API only supports unblocking — to disable a user, remove their capabilities or delete them.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Leave blank for the tenancy (scopes the user picker) | |
| User OCID (to unblock) | string | Required | ocid1.user.oc1..aaaa… of the user to unblock |
Returns: tool_result, user, id, success, error
24Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- Identity is a home-region service, so every create, update and delete must target your tenancy's home region — pointing the Region field at any other region returns a clean rejection rather than silently succeeding.
- Users, groups, policies and dynamic groups live in the tenancy root, so leaving Compartment OCID blank correctly targets the tenancy — supply a compartment OCID only when working with compartment-scoped resources.
- Newly created secrets — auth tokens, SMTP, customer-secret, OAuth and Swift passwords, and one-time Console passwords — are shown only once at creation and are never returned again by any list action, so capture them within the same run.
- Remove User from Group takes the membership OCID returned by Add User to Group or List Memberships, not the user OCID and group OCID together.
- Update Policy and Update Network Source replace their statement and IP lists wholesale, so leave those fields blank to keep the existing entries unchanged.
- Unblock User only lifts an automatic sign-in block; there is no disable switch, so to stop a user you remove their credential capabilities or delete them.