- 概要
- はじめに
- 概念
- UiPath CLI を使用する
- 使用ガイド
- CI/CD レシピ
- コマンド リファレンス
- 概要
- 終了コード
- グローバル オプション
- uip codedagent
- UIP コーダー
- UIP のコンテキスト グラウンディング
- uip docsai
- uip 関数
- UIP ガードレール
- uip llm - 構成
- uip llm-gateway
- uip model-hub
- add-test-data-entity
- テスト データのキューを追加
- 追加-テスト-データ-バリエーション
- 分析
- 開発
- プロジェクトを作成
- 差分
- アクティビティを検索
- GET-ANALYZER-RULES
- get-default-activity-xaml
- エラーを取得
- 手動テスト用のテスト ケースを取得
- 手動テストステップを取得
- get-library-object-repository
- オブジェクト リポジトリを取得
- get-versions
- Get-workflow-example
- indicate-application
- 要素を示す
- inspect-package
- install-data-fabric-entities
- パッケージのインストールまたは更新
- list-data-fabric-entities
- リスト - インスタンス
- list-workflow-examples
- パッケージ化
- パブリッシュ
- リモート
- 元に戻す
- 実行、デバッグ、実行
- ファイル名を実行
- 検索テンプレート
- スタートスタジオ
- 実行を停止
- TM
- UIA
- UIP タスク
- uip traces
- UIP トレースのフィードバック
- 移行
- 参照とサポート
UIP はコネクタ ビルダーの認証です
Integration Service コネクタ ビルダーでコネクタの認証スキームを設定および検査するための構文とオプションです。Integration Service コネクタ ビルダーで設定および検査する場合の構文とオプションです。Auth set、auth get、および auth system create/list。
このページでは、コネクタ独自の認証スキームを定義するコマンド グループである uip is connectors builder auth(コネクタ自体がベンダーの API と通信する方法) について説明します。これは設計時の問題であり、テナント接続とは異なります。テナント 接続は、そのスキームの実行時インスタンス (このページで設定するスキームに対する特定のユーザーの資格情報) です。コネクタ ディレクトリの解決、デザインとパブリッシュの違い、および全体的な作成フローについては、親ページの 「概念 」をご覧ください。
概要
uip is connectors builder auth set --auth-type <type> [scheme-specific options] [--connector-dir <path>]
uip is connectors builder auth get [--connector-dir <path>]
uip is connectors builder auth system create --type <type> [--vendor-path <path>] [--method <method>] [--next-resource <selector>] [--path <path>] [--connector-dir <path>]
uip is connectors builder auth system list [--connector-dir <path>]
uip is connectors builder auth set --auth-type <type> [scheme-specific options] [--connector-dir <path>]
uip is connectors builder auth get [--connector-dir <path>]
uip is connectors builder auth system create --type <type> [--vendor-path <path>] [--method <method>] [--next-resource <selector>] [--path <path>] [--connector-dir <path>]
uip is connectors builder auth system list [--connector-dir <path>]
これらのオプションはいずれもテナントを対象範囲としていません。このグループには --tenant フラグがありません。ここでのすべては、ローカルのコネクタ ディレクトリのみを編集または読み取ります。
UIP はコネクタ ビルダーの認証セットです
コネクタで認証を構成する1 つの --auth-type が必要です。残りのどのオプションが適用されるかは、その種類によって異なります。--forceが合格しない限り、すでに設定済みのコネクタに対して再実行は失敗します。これにより、エラーが発生するのではなく、既存の構成エントリに差分が適用されます — これは、最初の試行が拒否される可能性があり (たとえば、既存の構成と競合するスコープ オプションの変更)、リトライする必要があるためです。
これを使用して、以下のいずれかの認証の種類に対して既存のコネクタで認証を配線するか、または既存のコネクタの認証の種類 (--force) を入れ替えます。ここでも --scope-options/--required-scopes/--preselected-scopes を使用して OAuth/JWT スコープを定義します。個別の auth scope コマンドはありません。コネクタを最初から作成する場合に使用しないでください。最初に builder init を使用してください。認証以外の設定エントリには使用しないでください。 builder init preset apply または builder state patch を使用します ( 「トリガーとステート」を参照)。
オプション
| 長押し | 値 (Value) | 適用対象 | 説明 |
|---|---|---|---|
--auth-type <type> | 以下のいずれかの種類 | すべて | 必須。設定する認証フローです。 |
--connector-dir <path> | パス | すべて | コネクタ ディレクトリ。概念と同じ解決順序です。 |
--force | フラグ | すべて | コネクタがすでに設定されている場合は、エラーを発生させるのではなく、既存の構成エントリに差分を適用します。 |
--authorization-url <url> | url | OAuth | ログイン/同意 URL。 |
--token-url <url> | url | OAuth、JWT | トークン エンドポイント。 |
--token-refresh-url <url> | url | OAuth | 既定値は --token-url です。 |
--token-revoke-url <url> | url | OAuth | トークン取り消しエンドポイント。 |
--scope <scope> | string | OAuth、JWT、 firstPartyService | スペースで区切られたスコープ文字列。firstPartyServiceの場合、鋳造されたトークンが持つプラットフォーム スコープ。 |
--jwt-claim <spec> | name[=value][;label=...][;hint=...]、 繰り返し可能 | jwtOauth, jwtOauth2 | JWT アサーションのクレーム。裸の名前 ( =valueなし) は必須で空で作成されるため、接続ユーザーは接続時に入力します。 label/hint 接続フォームの表示名とヒント テキストを設定します。 |
--jwt-header <spec> | --jwt-claimと同じ構文で、繰り返し可能 | jwtOauth, jwtOauth2 | JWT アサーション ヘッダー。 |
--aws-service-name <name> | string | awsv4 | SigV4 サービス名定数 (例: polly、 connect)。[非表示] aws.service.name を既定値に設定します。 |
--scope-options <json> | の JSON 配列 {description, value} | OAuth、JWT | コネクション ユーザーに提供される複数選択スコープの選択肢。 |
--scope-options-file <path> | パス | OAuth、JWT | JSON --scope-options インラインではなくファイルから読み取ります。 |
--required-scopes <csv> | コンマ区切り | OAuth、JWT | スコープ: ユーザーが選択解除できません。 |
--preselected-scopes <csv> | コンマ区切り | OAuth、JWT | スコープは既定で事前にオンになっています。 |
--scope-delimiter <char> | string | OAuth、JWT | スコープの区切り文字。既定値はスペースです。 |
--scope-hint-text <text> | string | OAuth、JWT | スコープ セレクターの下に表示されるヒント テキストです。 |
--scope-screen-type <type> | string | OAuth、JWT | configScreenType を [スコープ] エントリに入力します。既定値は preです。 |
--api-key-param-name <name> | string | customApiKey | 必須のベンダー ヘッダーまたはクエリ パラメーター名。 |
--api-key-location <where> | header | query | customApiKey | キーの送信先です。既定値は headerです。 |
--api-key-prefix <prefix> | string | customApiKey | キー値の先頭に付加されるリテラル プレフィックス。 |
--key-config-name <key> | string | customApiKey | 内部構成キー。既定値は custom.api.keyです。 |
--key-config-display-name <name> | string | customApiKey | UI ラベル。既定値は API Keyです。 |
--validation-vendor-path <path> | パス | すべて (任意) | このベンダー パスで provisionAuthValidation テスト コールを追加します。 |
--validation-method <method> | HTTP メソッド | すべて (任意) | auth-validation 呼び出しのメソッド。既定の推奨値: GET — プローブは読み取り専用である必要があり、ベンダー データを変更してはなりません。 |
--auth-header <kv> | ConfigName=VendorHeader、 繰り返し可能 | マルチヘッダースキーム | 追加の静的認証ヘッダー。コネクションのユーザーが入力するプレーン テキスト構成として作成されます。複数の資格情報ヘッダーを必要とするスキームの場合 (例: iContact の API-AppId/API-Username)。 |
--secret-auth-header <kv> | ConfigName=VendorHeader、 繰り返し可能 | マルチヘッダースキーム | --auth-headerと似ていますが、構成は暗号化されたパスワード フィールドとして作成されます。API-Passwordなどの資格情報ヘッダーの場合。 |
--auth-type のいずれかを受け入れます: oauth2、 oauth2Pkce、 oauth2ClientCredentials、 oauth2Password、 oauth2PrivateKeyJwt、 oauth1、 basic、 jwtOauth、 jwtOauth2、 custom、 customApiKey、 personalAccessToken、 awsv4、 googleServiceAccount、 rsaCertificate、 none、 firstPartyService、 fpsUserDelegatedAccess、 fpsRobotAccessです。
firstPartyService は、UiPath プラットフォームから挿入された ID です。プラットフォームによってトークンが鋳造および更新され、接続時の設定フィールドではなくプラットフォームのヘッダーに {host}/{account}/{tenant} がバインドされます (下記の例に示すように、この 3 つのフィールドは、この種類に切り替えると、実際には構成セットから 削除されます )。
認証の種類ごとに異なる構成バンドルが書き込まれます。以下の各例は、1 つの一般的な形状ではなく、実際の型固有の結果を示しています。
例
# OAuth2 authorization-code flow
uip is connectors builder auth set --auth-type oauth2 \
--authorization-url https://acme.com/oauth/authorize \
--token-url https://acme.com/oauth/token \
--scope 'read write'
# OAuth2 authorization-code flow
uip is connectors builder auth set --auth-type oauth2 \
--authorization-url https://acme.com/oauth/authorize \
--token-url https://acme.com/oauth/token \
--scope 'read write'
{
"Code": "AuthConfigured",
"Data": {
"AuthType": "oauth2",
"AuthenticationTypes": ["oauth2"],
"TypeOauth": true,
"OauthRefreshResourceCreated": true,
"ConfigChanges": {
"added": ["oauth.api.key", "oauth.api.secret", "oauth.token.url"],
"updated": [],
"unchanged": []
}
}
}
{
"Code": "AuthConfigured",
"Data": {
"AuthType": "oauth2",
"AuthenticationTypes": ["oauth2"],
"TypeOauth": true,
"OauthRefreshResourceCreated": true,
"ConfigChanges": {
"added": ["oauth.api.key", "oauth.api.secret", "oauth.token.url"],
"updated": [],
"unchanged": []
}
}
}
# customApiKey, sent as a header
uip is connectors builder auth set --auth-type customApiKey --api-key-param-name X-API-Key
# customApiKey, sent as a header
uip is connectors builder auth set --auth-type customApiKey --api-key-param-name X-API-Key
{
"Code": "AuthConfigured",
"Data": {
"AuthType": "customApiKey",
"AuthenticationTypes": ["customApiKey"],
"TypeOauth": false,
"ApiKeyConfigAdded": true,
"ApiKeyParamAdded": true,
"KeyConfigName": "custom.api.key",
"ConfigChanges": { "added": ["custom.api.key"], "updated": [], "unchanged": [] }
}
}
{
"Code": "AuthConfigured",
"Data": {
"AuthType": "customApiKey",
"AuthenticationTypes": ["customApiKey"],
"TypeOauth": false,
"ApiKeyConfigAdded": true,
"ApiKeyParamAdded": true,
"KeyConfigName": "custom.api.key",
"ConfigChanges": { "added": ["custom.api.key"], "updated": [], "unchanged": [] }
}
}
# Re-apply a config diff that was rejected on first try
uip is connectors builder auth set --auth-type customApiKey --api-key-param-name X-API-Key --force
# Re-apply a config diff that was rejected on first try
uip is connectors builder auth set --auth-type customApiKey --api-key-param-name X-API-Key --force
{
"Code": "AuthConfigured",
"Data": {
"AuthType": "customApiKey",
"ConfigChanges": {
"added": [],
"updated": [{ "key": "custom.api.key", "diff": { "displayOrder": [3, 1] } }],
"unchanged": []
}
}
}
{
"Code": "AuthConfigured",
"Data": {
"AuthType": "customApiKey",
"ConfigChanges": {
"added": [],
"updated": [{ "key": "custom.api.key", "diff": { "displayOrder": [3, 1] } }],
"unchanged": []
}
}
}
# OAuth 2.0 JWT Bearer (Salesforce-style): claims with a value are pre-filled,
# bare claims are filled in by the connection user
uip is connectors builder auth set --auth-type jwtOauth \
--token-url https://login.salesforce.com/services/oauth2/token \
--jwt-claim aud=https://login.salesforce.com \
--jwt-claim iss \
--jwt-claim sub
# OAuth 2.0 JWT Bearer (Salesforce-style): claims with a value are pre-filled,
# bare claims are filled in by the connection user
uip is connectors builder auth set --auth-type jwtOauth \
--token-url https://login.salesforce.com/services/oauth2/token \
--jwt-claim aud=https://login.salesforce.com \
--jwt-claim iss \
--jwt-claim sub
{
"Code": "AuthConfigured",
"Data": {
"AuthType": "jwtOauth",
"AuthenticationTypes": ["jwtOauth"],
"TypeOauth": true,
"ConfigChanges": {
"added": [
"oauth.api.key", "oauth.api.secret", "oauth.callback.url", "oauth.token.url",
"jwt.base64.encoded.key", "jwt.claim.aud", "jwt.claim.iss", "jwt.claim.sub"
],
"updated": [],
"unchanged": []
}
}
}
{
"Code": "AuthConfigured",
"Data": {
"AuthType": "jwtOauth",
"AuthenticationTypes": ["jwtOauth"],
"TypeOauth": true,
"ConfigChanges": {
"added": [
"oauth.api.key", "oauth.api.secret", "oauth.callback.url", "oauth.token.url",
"jwt.base64.encoded.key", "jwt.claim.aud", "jwt.claim.iss", "jwt.claim.sub"
],
"updated": [],
"unchanged": []
}
}
}
# UiPath first-party service auth (platform-injected identity)
uip is connectors builder auth set --auth-type firstPartyService --scope OrchestratorApiUserAccess
# UiPath first-party service auth (platform-injected identity)
uip is connectors builder auth set --auth-type firstPartyService --scope OrchestratorApiUserAccess
{
"Code": "AuthConfigured",
"Data": {
"AuthType": "firstPartyService",
"AuthenticationTypes": ["firstPartyService"],
"TypeOauth": false,
"ConfigChanges": {
"added": [
"oauth.scope", "oauth.basic.header", "oauth.user.token",
"oauth.user.refresh_time", "oauth.user.refresh_interval"
],
"updated": [],
"unchanged": [],
"removed": ["host", "account", "tenant"]
}
}
}
{
"Code": "AuthConfigured",
"Data": {
"AuthType": "firstPartyService",
"AuthenticationTypes": ["firstPartyService"],
"TypeOauth": false,
"ConfigChanges": {
"added": [
"oauth.scope", "oauth.basic.header", "oauth.user.token",
"oauth.user.refresh_time", "oauth.user.refresh_interval"
],
"updated": [],
"unchanged": [],
"removed": ["host", "account", "tenant"]
}
}
}
# No authentication
uip is connectors builder auth set --auth-type none
# No authentication
uip is connectors builder auth set --auth-type none
{
"Code": "AuthConfigured",
"Data": {
"AuthType": "none",
"AuthenticationTypes": ["none"],
"TypeOauth": false,
"ConfigChanges": { "added": [], "updated": [], "unchanged": [] }
}
}
{
"Code": "AuthConfigured",
"Data": {
"AuthType": "none",
"AuthenticationTypes": ["none"],
"TypeOauth": false,
"ConfigChanges": { "added": [], "updated": [], "unchanged": [] }
}
}
UIP はコネクタ ビルダーの認証の取得です。
コネクタの完全な認証設定 (種類、構成エントリ (シークレットの墨消し)、ライフサイクル リソース、FPS ヘッダーのバインド) を確認します。
これを使用して、コネクタの現在の認証ブロックを調べます。変更するには、 を使用します auth set。
オプション
| 長押し | 値 (Value) | 説明 |
|---|---|---|
--connector-dir <path> | パス | コネクタ ディレクトリ。概念と同じ解決順序です。 |
例
uip is connectors builder auth get
uip is connectors builder auth get
データシェイプ(--output json)
{
"Code": "AuthInfo",
"Data": {
"ConnectorRoot": "/work/my-acme-connector",
"Authentication": {
"Type": "jwtOauth",
"AuthenticationTypes": ["jwtOauth"],
"TypeOauth": true
},
"Configs": [
{
"key": "oauth.token.url",
"configScreenType": null,
"required": true,
"hidden": true,
"defaultValue": "https://login.acme.com/oauth2/token"
},
{
"key": "jwt.claim.iss",
"configScreenType": "pre",
"required": true,
"defaultValue": null
}
],
"ConnectionFormFields": [],
"Resources": {
"oauthOnTokenRefresh": false,
"provisionAuthValidation": true
},
"FpsBindings": null,
"TemplateBindings": null
}
}
{
"Code": "AuthInfo",
"Data": {
"ConnectorRoot": "/work/my-acme-connector",
"Authentication": {
"Type": "jwtOauth",
"AuthenticationTypes": ["jwtOauth"],
"TypeOauth": true
},
"Configs": [
{
"key": "oauth.token.url",
"configScreenType": null,
"required": true,
"hidden": true,
"defaultValue": "https://login.acme.com/oauth2/token"
},
{
"key": "jwt.claim.iss",
"configScreenType": "pre",
"required": true,
"defaultValue": null
}
],
"ConnectionFormFields": [],
"Resources": {
"oauthOnTokenRefresh": false,
"provisionAuthValidation": true
},
"FpsBindings": null,
"TemplateBindings": null
}
}
Secret で入力された構成値 (パスワード、API キー) は一切含まれません。構成のメタデータ (キー、必須か非表示か、既定値ではないか) のみが含まれます。
UIP はコネクタ ビルダーの認証システムです
コネクタのライフサイクル (「システム」) リソースの管理 — provisionAuthValidation、 onProvision、 oauthOnTokenRefreshなどの認証時フック。これらは認証ライフサイクル フックであるため、 auth の下に存在します: activity create によって作成される通常の API エンドポイント (または activity create --skip-sr を介したアドホック SR レス エンドポイント — アクティビティ とフックを参照) とは異なり、個別の SR (セマンティック リソース) ファイルを持たないelement.jsonエントリです。
uip is コネクタ ビルダー 認証システムの作成
これを使用して、ライフサイクル フック エンドポイント (auth-validation、onProvision、またはトークン更新呼び出し) を接続します。通常の API エンドポイントを追加する場合には使用しないでください。代わりに builder activity create を使用してください。
オプション
| 長押し | 値 (Value) | 説明 |
|---|---|---|
--type <type> | string | 必須。システム リソースの種類 (例: provisionAuthValidation、 onProvision、 oauthOnTokenRefresh)。 |
--vendor-path <path> | パス | このフックのベンダー API パス。 |
--method <method> | HTTP メソッド | 型にメソッドが必要な場合は、既定で POST されます。 |
--next-resource <selector> | METHOD:/path | 次のリソース (例: GET:/organization) にチェーンします。 |
--path <path> | パス | 明示的なリソース パス — 型がオーバーライド パスを宣言する場合、その型のオーバーライド パスと一致する必要があります。 |
--connector-dir <path> | パス | コネクタ ディレクトリ。概念と同じ解決順序です。 |
例
uip is connectors builder auth system create --type provisionAuthValidation --vendor-path /me
uip is connectors builder auth system create --type provisionAuthValidation --vendor-path /me
データシェイプ(--output json)
{
"Code": "SystemResourceCreated",
"Data": {
"ResourceName": "provisionAuthValidation",
"ConnectorRoot": "/work/my-acme-connector",
"ResourceType": "provisionAuthValidation",
"ElementEntriesAdded": ["provisionAuthValidation"],
"ElementEntriesSkipped": [],
"SkipSr": true
}
}
{
"Code": "SystemResourceCreated",
"Data": {
"ResourceName": "provisionAuthValidation",
"ConnectorRoot": "/work/my-acme-connector",
"ResourceType": "provisionAuthValidation",
"ElementEntriesAdded": ["provisionAuthValidation"],
"ElementEntriesSkipped": [],
"SkipSr": true
}
}
UIP はコネクタ ビルダーの認証システム リストです。
種類がシステム リソースであるコネクタのelement.jsonエントリをリストにします。
オプション
| 長押し | 値 (Value) | 説明 |
|---|---|---|
--connector-dir <path> | パス | コネクタ ディレクトリ。概念と同じ解決順序です。 |
例
uip is connectors builder auth system list
uip is connectors builder auth system list
データシェイプ(--output json)
{
"Code": "SystemResourceList",
"Data": {
"Resources": [
{ "name": "provisionAuthValidation", "type": "provisionAuthValidation" }
]
}
}
{
"Code": "SystemResourceList",
"Data": {
"Resources": [
{ "name": "provisionAuthValidation", "type": "provisionAuthValidation" }
]
}
}
関連
- 概要とテナントのライフサイクル — すべてのビルダー ページ、および
download/import/publish/publish-statusで共有される概念。 - Init & connector — 認証を設定する前に、コネクタをスキャフォールディングします。
- アクティビティとフック — 設定後に、この認証を使用するエンドポイントを定義します。
- トリガーとステート — イベント トリガーと低レベルの要素ファイルの編集を行います。
uip is connections— ここで設定したスキームのテナント側のランタイム インスタンスです。