onelogin v0.6.3 published on Friday, May 10, 2024 by Pulumi
onelogin.apps.getInstance
Explore with Pulumi AI
Using getInstance
Two invocation forms are available. The direct form accepts plain arguments and either blocks until the result value is available, or returns a Promise-wrapped result. The output form accepts Input-wrapped arguments and returns an Output-wrapped result.
function getInstance(args: GetInstanceArgs, opts?: InvokeOptions): Promise<GetInstanceResult>
function getInstanceOutput(args: GetInstanceOutputArgs, opts?: InvokeOptions): Output<GetInstanceResult>def get_instance(allow_assumed_signin: Optional[bool] = None,
                 auth_method: Optional[int] = None,
                 auth_method_description: Optional[str] = None,
                 brand_id: Optional[int] = None,
                 configuration: Optional[GetInstanceConfiguration] = None,
                 connector_id: Optional[int] = None,
                 created_at: Optional[str] = None,
                 description: Optional[str] = None,
                 enforcement_point: Optional[GetInstanceEnforcementPoint] = None,
                 icon_url: Optional[str] = None,
                 id: Optional[str] = None,
                 login_config: Optional[int] = None,
                 name: Optional[str] = None,
                 notes: Optional[str] = None,
                 parameters: Optional[GetInstanceParameters] = None,
                 policy_id: Optional[int] = None,
                 provisioning: Optional[GetInstanceProvisioning] = None,
                 role_ids: Optional[Sequence[int]] = None,
                 sso: Optional[GetInstanceSso] = None,
                 tab_id: Optional[int] = None,
                 updated_at: Optional[str] = None,
                 visible: Optional[bool] = None,
                 opts: Optional[InvokeOptions] = None) -> GetInstanceResult
def get_instance_output(allow_assumed_signin: Optional[pulumi.Input[bool]] = None,
                 auth_method: Optional[pulumi.Input[int]] = None,
                 auth_method_description: Optional[pulumi.Input[str]] = None,
                 brand_id: Optional[pulumi.Input[int]] = None,
                 configuration: Optional[pulumi.Input[GetInstanceConfigurationArgs]] = None,
                 connector_id: Optional[pulumi.Input[int]] = None,
                 created_at: Optional[pulumi.Input[str]] = None,
                 description: Optional[pulumi.Input[str]] = None,
                 enforcement_point: Optional[pulumi.Input[GetInstanceEnforcementPointArgs]] = None,
                 icon_url: Optional[pulumi.Input[str]] = None,
                 id: Optional[pulumi.Input[str]] = None,
                 login_config: Optional[pulumi.Input[int]] = None,
                 name: Optional[pulumi.Input[str]] = None,
                 notes: Optional[pulumi.Input[str]] = None,
                 parameters: Optional[pulumi.Input[GetInstanceParametersArgs]] = None,
                 policy_id: Optional[pulumi.Input[int]] = None,
                 provisioning: Optional[pulumi.Input[GetInstanceProvisioningArgs]] = None,
                 role_ids: Optional[pulumi.Input[Sequence[pulumi.Input[int]]]] = None,
                 sso: Optional[pulumi.Input[GetInstanceSsoArgs]] = None,
                 tab_id: Optional[pulumi.Input[int]] = None,
                 updated_at: Optional[pulumi.Input[str]] = None,
                 visible: Optional[pulumi.Input[bool]] = None,
                 opts: Optional[InvokeOptions] = None) -> Output[GetInstanceResult]func GetInstance(ctx *Context, args *GetInstanceArgs, opts ...InvokeOption) (*GetInstanceResult, error)
func GetInstanceOutput(ctx *Context, args *GetInstanceOutputArgs, opts ...InvokeOption) GetInstanceResultOutput> Note: This function is named GetInstance in the Go SDK.
public static class GetInstance 
{
    public static Task<GetInstanceResult> InvokeAsync(GetInstanceArgs args, InvokeOptions? opts = null)
    public static Output<GetInstanceResult> Invoke(GetInstanceInvokeArgs args, InvokeOptions? opts = null)
}public static CompletableFuture<GetInstanceResult> getInstance(GetInstanceArgs args, InvokeOptions options)
// Output-based functions aren't available in Java yet
fn::invoke:
  function: onelogin:apps/getInstance:getInstance
  arguments:
    # arguments dictionaryThe following arguments are supported:
- Id string
- AllowAssumed boolSignin 
- AuthMethod int
- AuthMethod stringDescription 
- BrandId int
- Configuration
GetInstance Configuration 
- ConnectorId int
- CreatedAt string
- Description string
- EnforcementPoint GetInstance Enforcement Point 
- IconUrl string
- LoginConfig int
- Name string
- Notes string
- Parameters
GetInstance Parameters 
- PolicyId int
- Provisioning
GetInstance Provisioning 
- RoleIds List<int>
- Sso
GetInstance Sso 
- TabId int
- UpdatedAt string
- Visible bool
- Id string
- AllowAssumed boolSignin 
- AuthMethod int
- AuthMethod stringDescription 
- BrandId int
- Configuration
GetInstance Configuration 
- ConnectorId int
- CreatedAt string
- Description string
- EnforcementPoint GetInstance Enforcement Point 
- IconUrl string
- LoginConfig int
- Name string
- Notes string
- Parameters
GetInstance Parameters 
- PolicyId int
- Provisioning
GetInstance Provisioning 
- RoleIds []int
- Sso
GetInstance Sso 
- TabId int
- UpdatedAt string
- Visible bool
- id String
- allowAssumed BooleanSignin 
- authMethod Integer
- authMethod StringDescription 
- brandId Integer
- configuration
GetInstance Configuration 
- connectorId Integer
- createdAt String
- description String
- enforcementPoint GetInstance Enforcement Point 
- iconUrl String
- loginConfig Integer
- name String
- notes String
- parameters
GetInstance Parameters 
- policyId Integer
- provisioning
GetInstance Provisioning 
- roleIds List<Integer>
- sso
GetInstance Sso 
- tabId Integer
- updatedAt String
- visible Boolean
- id string
- allowAssumed booleanSignin 
- authMethod number
- authMethod stringDescription 
- brandId number
- configuration
GetInstance Configuration 
- connectorId number
- createdAt string
- description string
- enforcementPoint GetInstance Enforcement Point 
- iconUrl string
- loginConfig number
- name string
- notes string
- parameters
GetInstance Parameters 
- policyId number
- provisioning
GetInstance Provisioning 
- roleIds number[]
- sso
GetInstance Sso 
- tabId number
- updatedAt string
- visible boolean
- id str
- allow_assumed_ boolsignin 
- auth_method int
- auth_method_ strdescription 
- brand_id int
- configuration
GetInstance Configuration 
- connector_id int
- created_at str
- description str
- enforcement_point GetInstance Enforcement Point 
- icon_url str
- login_config int
- name str
- notes str
- parameters
GetInstance Parameters 
- policy_id int
- provisioning
GetInstance Provisioning 
- role_ids Sequence[int]
- sso
GetInstance Sso 
- tab_id int
- updated_at str
- visible bool
- id String
- allowAssumed BooleanSignin 
- authMethod Number
- authMethod StringDescription 
- brandId Number
- configuration Property Map
- connectorId Number
- createdAt String
- description String
- enforcementPoint Property Map
- iconUrl String
- loginConfig Number
- name String
- notes String
- parameters Property Map
- policyId Number
- provisioning Property Map
- roleIds List<Number>
- sso Property Map
- tabId Number
- updatedAt String
- visible Boolean
getInstance Result
The following output properties are available:
- AllowAssumed boolSignin 
- AuthMethod int
- AuthMethod stringDescription 
- BrandId int
- Configuration
GetInstance Configuration 
- ConnectorId int
- CreatedAt string
- Description string
- EnforcementPoint GetInstance Enforcement Point 
- IconUrl string
- Id string
- LoginConfig int
- Name string
- Notes string
- Parameters
GetInstance Parameters 
- PolicyId int
- Provisioning
GetInstance Provisioning 
- RoleIds List<int>
- Sso
GetInstance Sso 
- TabId int
- UpdatedAt string
- Visible bool
- AllowAssumed boolSignin 
- AuthMethod int
- AuthMethod stringDescription 
- BrandId int
- Configuration
GetInstance Configuration 
- ConnectorId int
- CreatedAt string
- Description string
- EnforcementPoint GetInstance Enforcement Point 
- IconUrl string
- Id string
- LoginConfig int
- Name string
- Notes string
- Parameters
GetInstance Parameters 
- PolicyId int
- Provisioning
GetInstance Provisioning 
- RoleIds []int
- Sso
GetInstance Sso 
- TabId int
- UpdatedAt string
- Visible bool
- allowAssumed BooleanSignin 
- authMethod Integer
- authMethod StringDescription 
- brandId Integer
- configuration
GetInstance Configuration 
- connectorId Integer
- createdAt String
- description String
- enforcementPoint GetInstance Enforcement Point 
- iconUrl String
- id String
- loginConfig Integer
- name String
- notes String
- parameters
GetInstance Parameters 
- policyId Integer
- provisioning
GetInstance Provisioning 
- roleIds List<Integer>
- sso
GetInstance Sso 
- tabId Integer
- updatedAt String
- visible Boolean
- allowAssumed booleanSignin 
- authMethod number
- authMethod stringDescription 
- brandId number
- configuration
GetInstance Configuration 
- connectorId number
- createdAt string
- description string
- enforcementPoint GetInstance Enforcement Point 
- iconUrl string
- id string
- loginConfig number
- name string
- notes string
- parameters
GetInstance Parameters 
- policyId number
- provisioning
GetInstance Provisioning 
- roleIds number[]
- sso
GetInstance Sso 
- tabId number
- updatedAt string
- visible boolean
- allow_assumed_ boolsignin 
- auth_method int
- auth_method_ strdescription 
- brand_id int
- configuration
GetInstance Configuration 
- connector_id int
- created_at str
- description str
- enforcement_point GetInstance Enforcement Point 
- icon_url str
- id str
- login_config int
- name str
- notes str
- parameters
GetInstance Parameters 
- policy_id int
- provisioning
GetInstance Provisioning 
- role_ids Sequence[int]
- sso
GetInstance Sso 
- tab_id int
- updated_at str
- visible bool
- allowAssumed BooleanSignin 
- authMethod Number
- authMethod StringDescription 
- brandId Number
- configuration Property Map
- connectorId Number
- createdAt String
- description String
- enforcementPoint Property Map
- iconUrl String
- id String
- loginConfig Number
- name String
- notes String
- parameters Property Map
- policyId Number
- provisioning Property Map
- roleIds List<Number>
- sso Property Map
- tabId Number
- updatedAt String
- visible Boolean
Supporting Types
GetInstanceConfiguration  
- AccessToken intExpiration Minutes 
- OIDC Apps only Number of minutes the refresh token will be valid for.
- LoginUrl string
- OIDC Apps only The OpenId Connect Client Id. Note that client_secret is only returned after Creating an App.
- OidcApi stringVersion 
- OidcApplication intType 
- OIDC Apps Only- 0: Web
- 1: Native/Mobile
 
- OidcEncryption stringKey 
- OIDC Apps only
- PostLogout stringRedirect Uri 
- OIDC Apps only
- RedirectUri string
- OIDC Apps only Comma or newline separated list of valid redirect uris for the OpenId Connect Authorization Code flow.
- RefreshToken intExpiration Minutes 
- Number of minutes the refresh token will be valid for.
- TokenEndpoint intAuth Method 
- OIDC Apps only- 0: Basic
- 1: POST
- 2: None / PKCE
 
- AccessToken intExpiration Minutes 
- OIDC Apps only Number of minutes the refresh token will be valid for.
- LoginUrl string
- OIDC Apps only The OpenId Connect Client Id. Note that client_secret is only returned after Creating an App.
- OidcApi stringVersion 
- OidcApplication intType 
- OIDC Apps Only- 0: Web
- 1: Native/Mobile
 
- OidcEncryption stringKey 
- OIDC Apps only
- PostLogout stringRedirect Uri 
- OIDC Apps only
- RedirectUri string
- OIDC Apps only Comma or newline separated list of valid redirect uris for the OpenId Connect Authorization Code flow.
- RefreshToken intExpiration Minutes 
- Number of minutes the refresh token will be valid for.
- TokenEndpoint intAuth Method 
- OIDC Apps only- 0: Basic
- 1: POST
- 2: None / PKCE
 
- accessToken IntegerExpiration Minutes 
- OIDC Apps only Number of minutes the refresh token will be valid for.
- loginUrl String
- OIDC Apps only The OpenId Connect Client Id. Note that client_secret is only returned after Creating an App.
- oidcApi StringVersion 
- oidcApplication IntegerType 
- OIDC Apps Only- 0: Web
- 1: Native/Mobile
 
- oidcEncryption StringKey 
- OIDC Apps only
- postLogout StringRedirect Uri 
- OIDC Apps only
- redirectUri String
- OIDC Apps only Comma or newline separated list of valid redirect uris for the OpenId Connect Authorization Code flow.
- refreshToken IntegerExpiration Minutes 
- Number of minutes the refresh token will be valid for.
- tokenEndpoint IntegerAuth Method 
- OIDC Apps only- 0: Basic
- 1: POST
- 2: None / PKCE
 
- accessToken numberExpiration Minutes 
- OIDC Apps only Number of minutes the refresh token will be valid for.
- loginUrl string
- OIDC Apps only The OpenId Connect Client Id. Note that client_secret is only returned after Creating an App.
- oidcApi stringVersion 
- oidcApplication numberType 
- OIDC Apps Only- 0: Web
- 1: Native/Mobile
 
- oidcEncryption stringKey 
- OIDC Apps only
- postLogout stringRedirect Uri 
- OIDC Apps only
- redirectUri string
- OIDC Apps only Comma or newline separated list of valid redirect uris for the OpenId Connect Authorization Code flow.
- refreshToken numberExpiration Minutes 
- Number of minutes the refresh token will be valid for.
- tokenEndpoint numberAuth Method 
- OIDC Apps only- 0: Basic
- 1: POST
- 2: None / PKCE
 
- access_token_ intexpiration_ minutes 
- OIDC Apps only Number of minutes the refresh token will be valid for.
- login_url str
- OIDC Apps only The OpenId Connect Client Id. Note that client_secret is only returned after Creating an App.
- oidc_api_ strversion 
- oidc_application_ inttype 
- OIDC Apps Only- 0: Web
- 1: Native/Mobile
 
- oidc_encryption_ strkey 
- OIDC Apps only
- post_logout_ strredirect_ uri 
- OIDC Apps only
- redirect_uri str
- OIDC Apps only Comma or newline separated list of valid redirect uris for the OpenId Connect Authorization Code flow.
- refresh_token_ intexpiration_ minutes 
- Number of minutes the refresh token will be valid for.
- token_endpoint_ intauth_ method 
- OIDC Apps only- 0: Basic
- 1: POST
- 2: None / PKCE
 
- accessToken NumberExpiration Minutes 
- OIDC Apps only Number of minutes the refresh token will be valid for.
- loginUrl String
- OIDC Apps only The OpenId Connect Client Id. Note that client_secret is only returned after Creating an App.
- oidcApi StringVersion 
- oidcApplication NumberType 
- OIDC Apps Only- 0: Web
- 1: Native/Mobile
 
- oidcEncryption StringKey 
- OIDC Apps only
- postLogout StringRedirect Uri 
- OIDC Apps only
- redirectUri String
- OIDC Apps only Comma or newline separated list of valid redirect uris for the OpenId Connect Authorization Code flow.
- refreshToken NumberExpiration Minutes 
- Number of minutes the refresh token will be valid for.
- tokenEndpoint NumberAuth Method 
- OIDC Apps only- 0: Basic
- 1: POST
- 2: None / PKCE
 
GetInstanceEnforcementPoint   
- CaseSensitive bool
- The URL path evaluation is case insensitive by default. Resources hosted on web servers such as Apache, NGINX and Java EE are case sensitive paths. Web servers such as Microsoft IIS are not case-sensitive.
- Conditions string
- If access is conditional, the conditions that must evaluate to true to allow access to a resource. For example, to require the user must be authenticated and have either the role Admin or User
- ContextRoot string
- The root path to the application, often the name of the application. Can be any name, path or just a slash (“/”). The context root uniquely identifies the application within the enforcement point.
- LandingPage string
- The location within the context root to which the browser will be redirected for IdP-initiated single sign-on. For example, the landing page might be an index page in the context root such as index.html or default.aspx. The landing page cannot begin with a slash and must use valid URL characters.
- Permissions string
- Specify to always allow,denyaccess to resources, of if access isconditional.
- RequireSitewide boolAuthentication 
- Require user authentication to access any resource protected by this enforcement point.
- Resources
List<GetInstance Enforcement Point Resource> 
- Array of resource objects
- SessionExpiry GetFixed Instance Enforcement Point Session Expiry Fixed 
- unit: - 0 = Seconds - 1 = Minutes - 2 = Hours value: - When Unit = 0 or 1 value must be 0-60 - When Unit = 2 value must be 0-24
- SessionExpiry GetInactivity Instance Enforcement Point Session Expiry Inactivity 
- unit: - 0 = Seconds - 1 = Minutes - 2 = Hours value: - When Unit = 0 or 1 value must be 0-60 - When Unit = 2 value must be 0-24
- Target string
- A fully-qualified URL to the internal application including scheme, authority and path. The target host authority must be an IP address, not a hostname.
- Token string
- Can only be set on create. Access Gateway Token.
- UseTarget boolHost Header 
- Use the target host header as opposed to the original gateway or upstream host header.
- Vhost string
- A comma-delimited list of one or more virtual hosts that map to applications assigned to the enforcement point. A VHOST may be a host name or an IP address. VHOST distinguish between applications that are at the same context root.
- CaseSensitive bool
- The URL path evaluation is case insensitive by default. Resources hosted on web servers such as Apache, NGINX and Java EE are case sensitive paths. Web servers such as Microsoft IIS are not case-sensitive.
- Conditions string
- If access is conditional, the conditions that must evaluate to true to allow access to a resource. For example, to require the user must be authenticated and have either the role Admin or User
- ContextRoot string
- The root path to the application, often the name of the application. Can be any name, path or just a slash (“/”). The context root uniquely identifies the application within the enforcement point.
- LandingPage string
- The location within the context root to which the browser will be redirected for IdP-initiated single sign-on. For example, the landing page might be an index page in the context root such as index.html or default.aspx. The landing page cannot begin with a slash and must use valid URL characters.
- Permissions string
- Specify to always allow,denyaccess to resources, of if access isconditional.
- RequireSitewide boolAuthentication 
- Require user authentication to access any resource protected by this enforcement point.
- Resources
[]GetInstance Enforcement Point Resource 
- Array of resource objects
- SessionExpiry GetFixed Instance Enforcement Point Session Expiry Fixed 
- unit: - 0 = Seconds - 1 = Minutes - 2 = Hours value: - When Unit = 0 or 1 value must be 0-60 - When Unit = 2 value must be 0-24
- SessionExpiry GetInactivity Instance Enforcement Point Session Expiry Inactivity 
- unit: - 0 = Seconds - 1 = Minutes - 2 = Hours value: - When Unit = 0 or 1 value must be 0-60 - When Unit = 2 value must be 0-24
- Target string
- A fully-qualified URL to the internal application including scheme, authority and path. The target host authority must be an IP address, not a hostname.
- Token string
- Can only be set on create. Access Gateway Token.
- UseTarget boolHost Header 
- Use the target host header as opposed to the original gateway or upstream host header.
- Vhost string
- A comma-delimited list of one or more virtual hosts that map to applications assigned to the enforcement point. A VHOST may be a host name or an IP address. VHOST distinguish between applications that are at the same context root.
- caseSensitive Boolean
- The URL path evaluation is case insensitive by default. Resources hosted on web servers such as Apache, NGINX and Java EE are case sensitive paths. Web servers such as Microsoft IIS are not case-sensitive.
- conditions String
- If access is conditional, the conditions that must evaluate to true to allow access to a resource. For example, to require the user must be authenticated and have either the role Admin or User
- contextRoot String
- The root path to the application, often the name of the application. Can be any name, path or just a slash (“/”). The context root uniquely identifies the application within the enforcement point.
- landingPage String
- The location within the context root to which the browser will be redirected for IdP-initiated single sign-on. For example, the landing page might be an index page in the context root such as index.html or default.aspx. The landing page cannot begin with a slash and must use valid URL characters.
- permissions String
- Specify to always allow,denyaccess to resources, of if access isconditional.
- requireSitewide BooleanAuthentication 
- Require user authentication to access any resource protected by this enforcement point.
- resources
List<GetInstance Enforcement Point Resource> 
- Array of resource objects
- sessionExpiry GetFixed Instance Enforcement Point Session Expiry Fixed 
- unit: - 0 = Seconds - 1 = Minutes - 2 = Hours value: - When Unit = 0 or 1 value must be 0-60 - When Unit = 2 value must be 0-24
- sessionExpiry GetInactivity Instance Enforcement Point Session Expiry Inactivity 
- unit: - 0 = Seconds - 1 = Minutes - 2 = Hours value: - When Unit = 0 or 1 value must be 0-60 - When Unit = 2 value must be 0-24
- target String
- A fully-qualified URL to the internal application including scheme, authority and path. The target host authority must be an IP address, not a hostname.
- token String
- Can only be set on create. Access Gateway Token.
- useTarget BooleanHost Header 
- Use the target host header as opposed to the original gateway or upstream host header.
- vhost String
- A comma-delimited list of one or more virtual hosts that map to applications assigned to the enforcement point. A VHOST may be a host name or an IP address. VHOST distinguish between applications that are at the same context root.
- caseSensitive boolean
- The URL path evaluation is case insensitive by default. Resources hosted on web servers such as Apache, NGINX and Java EE are case sensitive paths. Web servers such as Microsoft IIS are not case-sensitive.
- conditions string
- If access is conditional, the conditions that must evaluate to true to allow access to a resource. For example, to require the user must be authenticated and have either the role Admin or User
- contextRoot string
- The root path to the application, often the name of the application. Can be any name, path or just a slash (“/”). The context root uniquely identifies the application within the enforcement point.
- landingPage string
- The location within the context root to which the browser will be redirected for IdP-initiated single sign-on. For example, the landing page might be an index page in the context root such as index.html or default.aspx. The landing page cannot begin with a slash and must use valid URL characters.
- permissions string
- Specify to always allow,denyaccess to resources, of if access isconditional.
- requireSitewide booleanAuthentication 
- Require user authentication to access any resource protected by this enforcement point.
- resources
GetInstance Enforcement Point Resource[] 
- Array of resource objects
- sessionExpiry GetFixed Instance Enforcement Point Session Expiry Fixed 
- unit: - 0 = Seconds - 1 = Minutes - 2 = Hours value: - When Unit = 0 or 1 value must be 0-60 - When Unit = 2 value must be 0-24
- sessionExpiry GetInactivity Instance Enforcement Point Session Expiry Inactivity 
- unit: - 0 = Seconds - 1 = Minutes - 2 = Hours value: - When Unit = 0 or 1 value must be 0-60 - When Unit = 2 value must be 0-24
- target string
- A fully-qualified URL to the internal application including scheme, authority and path. The target host authority must be an IP address, not a hostname.
- token string
- Can only be set on create. Access Gateway Token.
- useTarget booleanHost Header 
- Use the target host header as opposed to the original gateway or upstream host header.
- vhost string
- A comma-delimited list of one or more virtual hosts that map to applications assigned to the enforcement point. A VHOST may be a host name or an IP address. VHOST distinguish between applications that are at the same context root.
- case_sensitive bool
- The URL path evaluation is case insensitive by default. Resources hosted on web servers such as Apache, NGINX and Java EE are case sensitive paths. Web servers such as Microsoft IIS are not case-sensitive.
- conditions str
- If access is conditional, the conditions that must evaluate to true to allow access to a resource. For example, to require the user must be authenticated and have either the role Admin or User
- context_root str
- The root path to the application, often the name of the application. Can be any name, path or just a slash (“/”). The context root uniquely identifies the application within the enforcement point.
- landing_page str
- The location within the context root to which the browser will be redirected for IdP-initiated single sign-on. For example, the landing page might be an index page in the context root such as index.html or default.aspx. The landing page cannot begin with a slash and must use valid URL characters.
- permissions str
- Specify to always allow,denyaccess to resources, of if access isconditional.
- require_sitewide_ boolauthentication 
- Require user authentication to access any resource protected by this enforcement point.
- resources
Sequence[GetInstance Enforcement Point Resource] 
- Array of resource objects
- session_expiry_ Getfixed Instance Enforcement Point Session Expiry Fixed 
- unit: - 0 = Seconds - 1 = Minutes - 2 = Hours value: - When Unit = 0 or 1 value must be 0-60 - When Unit = 2 value must be 0-24
- session_expiry_ Getinactivity Instance Enforcement Point Session Expiry Inactivity 
- unit: - 0 = Seconds - 1 = Minutes - 2 = Hours value: - When Unit = 0 or 1 value must be 0-60 - When Unit = 2 value must be 0-24
- target str
- A fully-qualified URL to the internal application including scheme, authority and path. The target host authority must be an IP address, not a hostname.
- token str
- Can only be set on create. Access Gateway Token.
- use_target_ boolhost_ header 
- Use the target host header as opposed to the original gateway or upstream host header.
- vhost str
- A comma-delimited list of one or more virtual hosts that map to applications assigned to the enforcement point. A VHOST may be a host name or an IP address. VHOST distinguish between applications that are at the same context root.
- caseSensitive Boolean
- The URL path evaluation is case insensitive by default. Resources hosted on web servers such as Apache, NGINX and Java EE are case sensitive paths. Web servers such as Microsoft IIS are not case-sensitive.
- conditions String
- If access is conditional, the conditions that must evaluate to true to allow access to a resource. For example, to require the user must be authenticated and have either the role Admin or User
- contextRoot String
- The root path to the application, often the name of the application. Can be any name, path or just a slash (“/”). The context root uniquely identifies the application within the enforcement point.
- landingPage String
- The location within the context root to which the browser will be redirected for IdP-initiated single sign-on. For example, the landing page might be an index page in the context root such as index.html or default.aspx. The landing page cannot begin with a slash and must use valid URL characters.
- permissions String
- Specify to always allow,denyaccess to resources, of if access isconditional.
- requireSitewide BooleanAuthentication 
- Require user authentication to access any resource protected by this enforcement point.
- resources List<Property Map>
- Array of resource objects
- sessionExpiry Property MapFixed 
- unit: - 0 = Seconds - 1 = Minutes - 2 = Hours value: - When Unit = 0 or 1 value must be 0-60 - When Unit = 2 value must be 0-24
- sessionExpiry Property MapInactivity 
- unit: - 0 = Seconds - 1 = Minutes - 2 = Hours value: - When Unit = 0 or 1 value must be 0-60 - When Unit = 2 value must be 0-24
- target String
- A fully-qualified URL to the internal application including scheme, authority and path. The target host authority must be an IP address, not a hostname.
- token String
- Can only be set on create. Access Gateway Token.
- useTarget BooleanHost Header 
- Use the target host header as opposed to the original gateway or upstream host header.
- vhost String
- A comma-delimited list of one or more virtual hosts that map to applications assigned to the enforcement point. A VHOST may be a host name or an IP address. VHOST distinguish between applications that are at the same context root.
GetInstanceEnforcementPointResource    
- Conditions string
- required if permission == "conditions"
- IsPath boolRegex 
- Path string
- Permission string
- RequireAuth bool
- Conditions string
- required if permission == "conditions"
- IsPath boolRegex 
- Path string
- Permission string
- RequireAuth bool
- conditions String
- required if permission == "conditions"
- isPath BooleanRegex 
- path String
- permission String
- requireAuth Boolean
- conditions string
- required if permission == "conditions"
- isPath booleanRegex 
- path string
- permission string
- requireAuth boolean
- conditions str
- required if permission == "conditions"
- is_path_ boolregex 
- path str
- permission str
- require_auth bool
- conditions String
- required if permission == "conditions"
- isPath BooleanRegex 
- path String
- permission String
- requireAuth Boolean
GetInstanceEnforcementPointSessionExpiryFixed      
GetInstanceEnforcementPointSessionExpiryInactivity      
GetInstanceParameters  
GetInstanceParametersGroups   
- AttributesTransformations string
- DefaultValues string
- Id int
- Label string
- ProvisionedEntitlements bool
- SkipIf boolBlank 
- UserAttribute stringMacros 
- UserAttribute stringMappings 
- Values string
- AttributesTransformations string
- DefaultValues string
- Id int
- Label string
- ProvisionedEntitlements bool
- SkipIf boolBlank 
- UserAttribute stringMacros 
- UserAttribute stringMappings 
- Values string
- attributesTransformations String
- defaultValues String
- id Integer
- label String
- provisionedEntitlements Boolean
- skipIf BooleanBlank 
- userAttribute StringMacros 
- userAttribute StringMappings 
- values String
- attributesTransformations string
- defaultValues string
- id number
- label string
- provisionedEntitlements boolean
- skipIf booleanBlank 
- userAttribute stringMacros 
- userAttribute stringMappings 
- values string
- attributes_transformations str
- default_values str
- id int
- label str
- provisioned_entitlements bool
- skip_if_ boolblank 
- user_attribute_ strmacros 
- user_attribute_ strmappings 
- values str
- attributesTransformations String
- defaultValues String
- id Number
- label String
- provisionedEntitlements Boolean
- skipIf BooleanBlank 
- userAttribute StringMacros 
- userAttribute StringMappings 
- values String
GetInstanceProvisioning  
GetInstanceSso  
- AcsUrl string
- App Name. This is only returned after Creating a SAML App.
- Certificate
GetInstance Sso Certificate 
- The certificate used for signing. This is only returned after Creating a SAML App.
- ClientId string
- The OpenId Connect Client Id. Note that client_secret is only returned after Creating an OIDC App.
- ClientSecret string
- OpenId Connet Client Secret
- Issuer string
- Issuer of app. This is only returned after Creating a SAML App.
- MetadataUrl string
- ID of the apps underlying connector. This is only returned after Creating a SAML App.
- AcsUrl string
- App Name. This is only returned after Creating a SAML App.
- Certificate
GetInstance Sso Certificate 
- The certificate used for signing. This is only returned after Creating a SAML App.
- ClientId string
- The OpenId Connect Client Id. Note that client_secret is only returned after Creating an OIDC App.
- ClientSecret string
- OpenId Connet Client Secret
- Issuer string
- Issuer of app. This is only returned after Creating a SAML App.
- MetadataUrl string
- ID of the apps underlying connector. This is only returned after Creating a SAML App.
- acsUrl String
- App Name. This is only returned after Creating a SAML App.
- certificate
GetInstance Sso Certificate 
- The certificate used for signing. This is only returned after Creating a SAML App.
- clientId String
- The OpenId Connect Client Id. Note that client_secret is only returned after Creating an OIDC App.
- clientSecret String
- OpenId Connet Client Secret
- issuer String
- Issuer of app. This is only returned after Creating a SAML App.
- metadataUrl String
- ID of the apps underlying connector. This is only returned after Creating a SAML App.
- acsUrl string
- App Name. This is only returned after Creating a SAML App.
- certificate
GetInstance Sso Certificate 
- The certificate used for signing. This is only returned after Creating a SAML App.
- clientId string
- The OpenId Connect Client Id. Note that client_secret is only returned after Creating an OIDC App.
- clientSecret string
- OpenId Connet Client Secret
- issuer string
- Issuer of app. This is only returned after Creating a SAML App.
- metadataUrl string
- ID of the apps underlying connector. This is only returned after Creating a SAML App.
- acs_url str
- App Name. This is only returned after Creating a SAML App.
- certificate
GetInstance Sso Certificate 
- The certificate used for signing. This is only returned after Creating a SAML App.
- client_id str
- The OpenId Connect Client Id. Note that client_secret is only returned after Creating an OIDC App.
- client_secret str
- OpenId Connet Client Secret
- issuer str
- Issuer of app. This is only returned after Creating a SAML App.
- metadata_url str
- ID of the apps underlying connector. This is only returned after Creating a SAML App.
- acsUrl String
- App Name. This is only returned after Creating a SAML App.
- certificate Property Map
- The certificate used for signing. This is only returned after Creating a SAML App.
- clientId String
- The OpenId Connect Client Id. Note that client_secret is only returned after Creating an OIDC App.
- clientSecret String
- OpenId Connet Client Secret
- issuer String
- Issuer of app. This is only returned after Creating a SAML App.
- metadataUrl String
- ID of the apps underlying connector. This is only returned after Creating a SAML App.
GetInstanceSsoCertificate   
Package Details
- Repository
- onelogin pulumi/pulumi-onelogin
- License
- Apache-2.0
- Notes
- This Pulumi package is based on the oneloginTerraform Provider.