

# DescribeIdentityStore
<a name="API_DescribeIdentityStore"></a>

Retrieves details about the specified identity store, including its Amazon Resource Name (ARN) and network configuration.

## Request Syntax
<a name="API_DescribeIdentityStore_RequestSyntax"></a>

```
{
   "IdentityStoreId": "{{string}}"
}
```

## Request Parameters
<a name="API_DescribeIdentityStore_RequestParameters"></a>

For information about the parameters that are common to all actions, see [Common Parameters](CommonParameters.md).

The request accepts the following data in JSON format.

 ** [IdentityStoreId](#API_DescribeIdentityStore_RequestSyntax) **   <a name="singlesignon-DescribeIdentityStore-request-IdentityStoreId"></a>
The globally unique identifier for the identity store.  
You can specify the identity store by ID or by Amazon Resource Name (ARN). For example, identity store ID `d-1234567890` or identity store ARN `arn:aws:identitystore::111122223333:identitystore/d-1234567890`.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 93.  
Pattern: `(arn:aws[a-z-]*:identitystore::\d{12}:identitystore/)?(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})`   
Required: Yes

## Response Syntax
<a name="API_DescribeIdentityStore_ResponseSyntax"></a>

```
{
   "IdentityStoreArn": "string",
   "IdentityStoreId": "string",
   "NetworkConfiguration": { 
      "ApiAllowSourceIps": [ "string" ],
      "ApiRestrictSourceVpcs": [ "string" ],
      "ScimAllowSourceIps": [ "string" ],
      "VpceAccessRequired": boolean
   }
}
```

## Response Elements
<a name="API_DescribeIdentityStore_ResponseElements"></a>

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.

 ** [IdentityStoreArn](#API_DescribeIdentityStore_ResponseSyntax) **   <a name="singlesignon-DescribeIdentityStore-response-IdentityStoreArn"></a>
The Amazon Resource Name (ARN) of the identity store. For example, `arn:aws:identitystore::111122223333:identitystore/d-1234567890`.  
Type: String  
Length Constraints: Minimum length of 62. Maximum length of 93.  
Pattern: `arn:aws[a-z-]*:identitystore::\d{12}:identitystore/(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})` 

 ** [IdentityStoreId](#API_DescribeIdentityStore_ResponseSyntax) **   <a name="singlesignon-DescribeIdentityStore-response-IdentityStoreId"></a>
The globally unique identifier for the identity store.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 93.  
Pattern: `(arn:aws[a-z-]*:identitystore::\d{12}:identitystore/)?(d-[0-9a-f]{10}|[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})` 

 ** [NetworkConfiguration](#API_DescribeIdentityStore_ResponseSyntax) **   <a name="singlesignon-DescribeIdentityStore-response-NetworkConfiguration"></a>
The network configuration of the identity store. This configuration controls whether access through a virtual private cloud (VPC) endpoint is required, and which source VPCs and IP addresses are allowed.  
Type: [NetworkConfigurationDetails](API_NetworkConfigurationDetails.md) object

## Errors
<a name="API_DescribeIdentityStore_Errors"></a>

For information about the errors that are common to all actions, see [Common Error Types](CommonErrors.md).

 ** AccessDeniedException **   
You do not have sufficient access to perform this action.    
 ** Reason **   
Indicates the reason for an access denial when returned by KMS while accessing a Customer Managed KMS key. For non-KMS access-denied errors, this field is not included.  
 ** RequestId **   
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
HTTP Status Code: 400

 ** InternalServerException **   
The request processing has failed because of an unknown error, exception or failure with an internal server.    
 ** RequestId **   
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.  
 ** RetryAfterSeconds **   
The number of seconds to wait before retrying the next request.
HTTP Status Code: 500

 ** ResourceNotFoundException **   
Indicates that a requested resource is not found.    
 ** Reason **   
Indicates the reason for a resource not found error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.  
 ** RequestId **   
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.  
 ** ResourceId **   
The identifier for a resource in the identity store that can be used as `UserId` or `GroupId`. The format for `ResourceId` is either `UUID` or `1234567890-UUID`, where `UUID` is a randomly generated value for each resource when it is created and `1234567890` represents the ` IdentityStoreId` string value. In the case that the identity store is migrated from a legacy SSO identity store, the `ResourceId` for that identity store will be in the format of `UUID`. Otherwise, it will be in the `1234567890-UUID` format.  
 ** ResourceType **   
An enum object indicating the type of resource in the identity store service. Valid values include USER, GROUP, GROUP\_MEMBERSHIP, RESOURCE\_POLICY, and IDENTITY\_STORE.
HTTP Status Code: 400

 ** ThrottlingException **   
Indicates that the principal has crossed the throttling limits of the API operations.    
 ** Reason **   
Indicates the reason for the throttling error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.  
 ** RequestId **   
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.  
 ** RetryAfterSeconds **   
The number of seconds to wait before retrying the next request.
HTTP Status Code: 400

 ** ValidationException **   
The request failed because it contains a syntax error.    
 ** Reason **   
Indicates the reason for the validation error when the service is unable to access a Customer Managed KMS key. For non-KMS permission errors, this field is not included.  
 ** RequestId **   
The identifier for each request. This value is a globally unique ID that is generated by the identity store service for each sent request, and is then returned inside the exception if the request fails.
HTTP Status Code: 400

## Examples
<a name="API_DescribeIdentityStore_Examples"></a>

### Example 1
<a name="API_DescribeIdentityStore_Example_1"></a>

This example describes an identity store specified by its ID.

#### Sample Request
<a name="API_DescribeIdentityStore_Example_1_Request"></a>

```
{
    "IdentityStoreId": "d-1234567890"
}
```

#### Sample Response
<a name="API_DescribeIdentityStore_Example_1_Response"></a>

```
{
    "IdentityStoreId": "d-1234567890",
    "IdentityStoreArn": "arn:aws:identitystore::111122223333:identitystore/d-1234567890",
    "NetworkConfiguration": {
        "VpceAccessRequired": true,
        "ApiRestrictSourceVpcs": ["vpc-0a1b2c3d4e5f67890"],
        "ApiAllowSourceIps": ["203.0.113.0/24"],
        "ScimAllowSourceIps": ["203.0.113.0/24"]
    }
}
```

### Example 2
<a name="API_DescribeIdentityStore_Example_2"></a>

This example describes the same identity store specified by its Amazon Resource Name (ARN) instead of its ID.

#### Sample Request
<a name="API_DescribeIdentityStore_Example_2_Request"></a>

```
{
    "IdentityStoreId": "arn:aws:identitystore::111122223333:identitystore/d-1234567890"
}
```

#### Sample Response
<a name="API_DescribeIdentityStore_Example_2_Response"></a>

```
{
    "IdentityStoreId": "d-1234567890",
    "IdentityStoreArn": "arn:aws:identitystore::111122223333:identitystore/d-1234567890",
    "NetworkConfiguration": {
        "VpceAccessRequired": true,
        "ApiRestrictSourceVpcs": ["vpc-0a1b2c3d4e5f67890"],
        "ApiAllowSourceIps": ["203.0.113.0/24"],
        "ScimAllowSourceIps": ["203.0.113.0/24"]
    }
}
```

## See Also
<a name="API_DescribeIdentityStore_SeeAlso"></a>

For more information about using this API in one of the language-specific AWS SDKs, see the following:
+  [AWS Command Line Interface V2](https://docs.aws.amazon.com/goto/cli2/identitystore-2020-06-15/DescribeIdentityStore) 
+  [AWS SDK for .NET V4](https://docs.aws.amazon.com/goto/DotNetSDKV4/identitystore-2020-06-15/DescribeIdentityStore) 
+  [AWS SDK for C\+\+](https://docs.aws.amazon.com/goto/SdkForCpp/identitystore-2020-06-15/DescribeIdentityStore) 
+  [AWS SDK for Go v2](https://docs.aws.amazon.com/goto/SdkForGoV2/identitystore-2020-06-15/DescribeIdentityStore) 
+  [AWS SDK for Java V2](https://docs.aws.amazon.com/goto/SdkForJavaV2/identitystore-2020-06-15/DescribeIdentityStore) 
+  [AWS SDK for JavaScript V3](https://docs.aws.amazon.com/goto/SdkForJavaScriptV3/identitystore-2020-06-15/DescribeIdentityStore) 
+  [AWS SDK for Kotlin](https://docs.aws.amazon.com/goto/SdkForKotlin/identitystore-2020-06-15/DescribeIdentityStore) 
+  [AWS SDK for PHP V3](https://docs.aws.amazon.com/goto/SdkForPHPV3/identitystore-2020-06-15/DescribeIdentityStore) 
+  [AWS SDK for Python (Boto3)](https://docs.aws.amazon.com/goto/boto3/identitystore-2020-06-15/DescribeIdentityStore) 
+  [AWS SDK for Ruby V3](https://docs.aws.amazon.com/goto/SdkForRubyV3/identitystore-2020-06-15/DescribeIdentityStore) 