List instancesList the IAM Identity Center instances in the connection's region, with each one's identity store ID and status.
Describe instanceRead an Identity Center instance's status, encryption and whether multi-account permissions are on.
List usersList one page of the users in the identity store.
Get userRead one user's profile.
Find user IDFind a user's ID from their user name, email or external ID. Returns found = false rather than failing when nobody matches.
Create userAdd a user to the Identity Center directory. Works only when the identity source is the Identity Center directory, not an external identity provider or Active Directory.
Update userChange a user's attributes. Only the fields you fill in are changed; everything else is left as it is.
Delete userPermanently delete a user and their group memberships. This cannot be undone.
List groupsList one page of the groups in the identity store.
Get groupRead one group's name and description.
Find group IDFind a group's ID from its name or external ID. Returns found = false rather than failing when nothing matches.
Create groupCreate a group in the Identity Center directory. Group names must be unique.
Update groupRename a group, or change or remove its description.
Delete groupPermanently delete a group. Its members keep their accounts. This cannot be undone.
Add user to groupAdd a user to a group. If they are already a member, the existing membership is returned instead of an error.
Remove user from groupRemove a user from a group, by membership ID or by group and user. Removing someone who is not a member changes nothing and returns removed = false.
List group membersList one page of a group's memberships.
List user's groupsList one page of the groups a user belongs to.
Get group membershipCheck whether a user is in a group and get the membership ID. Returns is_member = false rather than failing when they are not.
Check user in groupsCheck which of up to 100 groups a user belongs to.