uipath-cli
latest
false
UiPath CLI 用户指南
重要 :
请注意,此内容已使用机器翻译进行了本地化。
新发布内容的本地化可能需要 1-2 周的时间才能完成。
uip admin 外部应用程序
“uip adminexternal-apps”的语法和选项,用于管理 OAuth2 客户端注册及其联合凭据,以进行外部应用程序集成。
uip admin external-apps 管理 OAuth2 客户端注册,即使用自己的客户端 ID/密码(或工作负载联合身份验证)而不是用户自己的登录名对 UiPath 进行身份验证的外部应用程序和服务。每个应用程序都是机密(服务器端,有密码)或非机密(公开,例如 SPA 或移动应用程序,无密码)。嵌套式 federated-credentials 组管理工作负载-身份-联合绑定(例如GitHub Actions OIDC),让外部应用程序完全不需要静态密码进行身份验证。
大纲
uip admin external-apps list
uip admin external-apps get <client-id>
uip admin external-apps create <name> [--redirect-uri <uri>] [--user-scope <scopes>] [--app-scope <scopes>] [--non-confidential] [--no-secret]
uip admin external-apps update <client-id> [--name <name>] [--redirect-uri <uri>] [--user-scope <scopes>] [--app-scope <scopes>]
uip admin external-apps delete <client-id>
uip admin external-apps generate-secret <client-id> [--description <text>] [--expiration <date>]
uip admin external-apps delete-secret <secret-id>
uip admin external-apps federated-credentials list <client-id>
uip admin external-apps federated-credentials get <client-id> <credential-id>
uip admin external-apps federated-credentials create <client-id> --name <name> --issuer <url> --audience <audience> --subject <subject>
uip admin external-apps federated-credentials update <client-id> <credential-id> --name <name> --issuer <url> --audience <audience> --subject <subject>
uip admin external-apps federated-credentials delete <client-id> <credential-id>
uip admin external-apps list
uip admin external-apps get <client-id>
uip admin external-apps create <name> [--redirect-uri <uri>] [--user-scope <scopes>] [--app-scope <scopes>] [--non-confidential] [--no-secret]
uip admin external-apps update <client-id> [--name <name>] [--redirect-uri <uri>] [--user-scope <scopes>] [--app-scope <scopes>]
uip admin external-apps delete <client-id>
uip admin external-apps generate-secret <client-id> [--description <text>] [--expiration <date>]
uip admin external-apps delete-secret <secret-id>
uip admin external-apps federated-credentials list <client-id>
uip admin external-apps federated-credentials get <client-id> <credential-id>
uip admin external-apps federated-credentials create <client-id> --name <name> --issuer <url> --audience <audience> --subject <subject>
uip admin external-apps federated-credentials update <client-id> <credential-id> --name <name> --issuer <url> --audience <audience> --subject <subject>
uip admin external-apps federated-credentials delete <client-id> <credential-id>
动词
| 组 | 动词 | 用途 |
|---|---|---|
external-apps | list | 列出分区中的外部应用程序。 |
external-apps | get | 按客户端 ID 获取应用程序的详细信息。 |
external-apps | create | 注册新的 OAuth2 客户端。 |
external-apps | update | 更新应用程序的名称、重定向 URI 或作用域。 |
external-apps | delete | 按客户端 ID 删除应用程序。 |
external-apps | generate-secret | 生成新的客户端密码。 |
external-apps | delete-secret | 删除特定客户端密码。 |
federated-credentials | list | 列出应用程序的联合凭据。 |
federated-credentials | get | 按 ID 获取联合凭据。 |
federated-credentials | create | 绑定外部身份提供程序(例如GitHub Actions OIDC)。 |
federated-credentials | update | 更新联合凭据。 |
federated-credentials | delete | 删除联合凭据。 |
概念
- 机密信息与非机密信息。默认为机密(服务器端,获取客户端密码)。
--non-confidential创建一个没有密码的公共客户端 — 它仅支持--user-scope(委派)作用域,从不支持--app-scope;无法在客户端向非机密应用程序传递--app-scope。 - 作用域按授权类型拆分。
--user-scope(已委派、需要用户登录)和--app-scope(仅适用于应用程序,客户端凭据授予)是独立列表 — 选择其中一个或同时发送。需要至少在create上配置一个。有关可用作用域名称的完整目录,请参阅uip admin scopes list。 --scope是--app-scope已弃用别名。如果两者都给定,则--app-scope胜出;若任一值为空白值(空字符串或仅包含空格的字符串),系统会拒绝该值,而不是静默地将其视为“无作用域”。- 每当涉及用户作用域时,都需要使用重定向 URI (因为应用程序不是机密信息,或者因为传递了
--user-scope),因为两者都需要 OAuth2 授权代码流程。机密且仅适用于应用程序范围的应用程序则不需要 ID。 - 当您未传递任何作用域时,
update将从资源重新派生作用域— 如果您同时省略--user-scope和--app-scope,则该命令将不加更改地重新发送应用程序的现有作用域,而不是清除它们;与create相同的非机密/重定向 URI 验证仍适用于任何最终作用域设置和重定向 URI。 - 密码显示一次。无法再次检索
generate-secret的返回值 — 请立即存储。
uip admin 外部应用程序列表
列出分区中的外部应用程序。无筛选/分页选项。
示例
uip admin external-apps list
uip admin external-apps list
数据形状(--输出 json)
{ "Code": "ExternalClientList", "Data": [{ "id": "my-app", "name": "My Application", "isConfidential": true }] }
{ "Code": "ExternalClientList", "Data": [{ "id": "my-app", "name": "My Application", "isConfidential": true }] }
uip 管理员外部应用程序获取
按客户端 ID 获取外部应用程序详细信息。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<client-id> | 是 | 外部应用程序 ID。使用 external-apps list 查找。 |
示例
uip admin external-apps get my-app
uip admin external-apps get my-app
数据形状(--输出 json)
{ "Code": "ExternalClientDetails", "Data": { "id": "my-app", "name": "My Application", "isConfidential": true, "redirectUri": "https://example.com/callback" } }
{ "Code": "ExternalClientDetails", "Data": { "id": "my-app", "name": "My Application", "isConfidential": true, "redirectUri": "https://example.com/callback" } }
uip 管理员外部应用程序创建
创建外部应用程序(默认机密)。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<name> | 是 | 应用程序显示名称。 |
选项
| 长 | 值 | 描述 |
|---|---|---|
--redirect-uri <uri> | 逗号分隔 | OAuth2 流程的重定向 URI。当非机密信息或设置了 --user-scope 时为必需。 |
--user-scope <scopes> | 逗号或空格分隔 | 委派(用户)作用域。 |
--app-scope <scopes> | 逗号或空格分隔 | 应用程序(仅适用于应用程序)作用域。不允许在非机密应用程序中使用。 |
--scope <scopes> | 逗号或空格分隔 | 已弃用 --app-scope 的别名。 |
--non-confidential | 标记 | 创建公共客户端 (无密码)。 |
--no-secret | 标记 | 在创建时跳过生成客户端密码(仅限机密信息应用程序)。 |
其中至少需要 --user-scope/--app-scope 之一。
示例
# Confidential app with application scopes only
uip admin external-apps create "My App" --app-scope "OR.Folders,OR.Assets"
# Confidential app with application scopes only
uip admin external-apps create "My App" --app-scope "OR.Folders,OR.Assets"
# Confidential app with both user and app scopes
uip admin external-apps create "My App" --user-scope "OR.Folders" --app-scope "OR.Jobs" --redirect-uri "https://example.com/callback"
# Confidential app with both user and app scopes
uip admin external-apps create "My App" --user-scope "OR.Folders" --app-scope "OR.Jobs" --redirect-uri "https://example.com/callback"
# Public client (SPA) with user scopes
uip admin external-apps create "My SPA" --non-confidential --user-scope "OR.Folders" --redirect-uri "http://localhost:3000/callback"
# Public client (SPA) with user scopes
uip admin external-apps create "My SPA" --non-confidential --user-scope "OR.Folders" --redirect-uri "http://localhost:3000/callback"
数据形状(--输出 json)
{ "Code": "ExternalClientCreated", "Data": { "id": "my-app", "name": "My App", "isConfidential": true, "secret": "generated-secret-value" } }
{ "Code": "ExternalClientCreated", "Data": { "id": "my-app", "name": "My App", "isConfidential": true, "secret": "generated-secret-value" } }
secret 仅适用于创建的不带 --no-secret 的机密应用程序。
uip admin 外部应用程序更新
更新应用程序的名称、重定向 URI 或作用域。至少需要“--name/--redirect-uri/--user-scope/--app-scope”中的一个。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<client-id> | 是 | 外部应用程序 ID。 |
选项
| 长 | 短 | 值 | 描述 |
|---|---|---|---|
--name <name> | -n | 字符串 | 新显示名称。 |
--redirect-uri <uri> | 逗号分隔 | 新的重定向 URI。 | |
--user-scope <scopes> | 逗号或空格分隔 | 新的委派作用域。 | |
--app-scope <scopes> | 逗号或空格分隔 | 新的应用程序作用域。 | |
--scope <scopes> | 逗号或空格分隔 | 已弃用 --app-scope 的别名。 |
示例
uip admin external-apps update my-app-id --name "Updated App" --app-scope "OR.Folders"
uip admin external-apps update my-app-id --name "Updated App" --app-scope "OR.Folders"
数据形状(--输出 json)
{ "Code": "ExternalClientUpdated" }
{ "Code": "ExternalClientUpdated" }
uip 管理员外部应用程序删除
按客户端 ID 删除外部应用程序。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<client-id> | 是 | 外部应用程序 ID。 |
示例
uip admin external-apps delete my-app-id
uip admin external-apps delete my-app-id
数据形状(--输出 json)
{ "Code": "ExternalClientDeleted", "Data": { "Id": "my-app-id", "Status": "Deleted successfully" } }
{ "Code": "ExternalClientDeleted", "Data": { "Id": "my-app-id", "Status": "Deleted successfully" } }
uip 管理员外部应用程序生成密码
为外部应用程序生成新的密码。密码值仅显示一次。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<client-id> | 是 | 外部应用程序 ID。 |
选项
| 长 | 值 | 描述 |
|---|---|---|
--description <text> | 字符串 | 密码的说明。 |
--expiration <date> | ISO 8601 | 到期日期。 |
示例
uip admin external-apps generate-secret my-app
uip admin external-apps generate-secret my-app
数据形状(--输出 json)
{ "Code": "ExternalClientSecretGenerated", "Data": { "id": 1, "secret": "generated-secret-value" } }
{ "Code": "ExternalClientSecretGenerated", "Data": { "id": 1, "secret": "generated-secret-value" } }
UIP 管理员外部应用程序删除密码
从外部应用程序中删除特定密码 — 一个应用程序可以有多个活动密码;这仅删除一个。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<secret-id> | 是 | 密码 ID(数字)。通过 external-apps get 查找。 |
示例
uip admin external-apps delete-secret 12345
uip admin external-apps delete-secret 12345
数据形状(--输出 json)
{ "Code": "ExternalClientSecretDeleted", "Data": { "Id": "12345", "Status": "Deleted successfully" } }
{ "Code": "ExternalClientSecretDeleted", "Data": { "Id": "12345", "Status": "Deleted successfully" } }
uip 管理员外部应用程序联合凭据列表
列出外部应用程序的联合凭据。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<client-id> | 是 | 外部应用程序 ID。 |
示例
uip admin external-apps federated-credentials list my-app-id
uip admin external-apps federated-credentials list my-app-id
数据形状(--输出 json)
{ "Code": "FederatedCredentialList", "Data": [{ "id": "fc000000-0000-0000-0000-000000000001", "name": "GitHub Actions", "issuer": "https://token.actions.githubusercontent.com" }] }
{ "Code": "FederatedCredentialList", "Data": [{ "id": "fc000000-0000-0000-0000-000000000001", "name": "GitHub Actions", "issuer": "https://token.actions.githubusercontent.com" }] }
uip 管理员外部应用程序联合凭据获取
按 ID 获取联合凭据。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<client-id> | 是 | 外部应用程序 ID。 |
<credential-id> | 是 | 联合凭据 ID (UUID)。 |
示例
uip admin external-apps federated-credentials get my-app-id fc000000-0000-0000-0000-000000000001
uip admin external-apps federated-credentials get my-app-id fc000000-0000-0000-0000-000000000001
数据形状(--输出 json)
{
"Code": "FederatedCredentialDetails",
"Data": {
"id": "fc000000-0000-0000-0000-000000000001",
"name": "GitHub Actions",
"issuer": "https://token.actions.githubusercontent.com",
"audience": "api://AzureADTokenExchange",
"subject": "repo:org/repo:ref:refs/heads/main"
}
}
{
"Code": "FederatedCredentialDetails",
"Data": {
"id": "fc000000-0000-0000-0000-000000000001",
"name": "GitHub Actions",
"issuer": "https://token.actions.githubusercontent.com",
"audience": "api://AzureADTokenExchange",
"subject": "repo:org/repo:ref:refs/heads/main"
}
}
uip 管理员外部应用程序联合凭据创建
将外部身份提供程序绑定到应用程序 — 启用工作负载身份联合(例如,GitHub Actions 工作流在无需存储密码的情况下进行身份验证)。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<client-id> | 是 | 外部应用程序 ID。 |
选项
| 长 | 短 | 值 | 必填 | 描述 |
|---|---|---|---|---|
--name <name> | -n | 字符串 | 是 | 凭据名称。 |
--issuer <url> | url | 是 | 令牌颁发者 URL,例如https://token.actions.githubusercontent.com。 | |
--audience <audience> | 字符串 | 是 | 预期受众声明,例如api://AzureADTokenExchange。 | |
--subject <subject> | 字符串 | 是 | 预期的主题声明,例如repo:org/repo:ref:refs/heads/main。 | |
--description <text> | 字符串 | 否 | 说明。 |
示例
uip admin external-apps federated-credentials create my-app-id \
--name "GitHub Actions" \
--issuer "https://token.actions.githubusercontent.com" \
--audience "api://AzureADTokenExchange" \
--subject "repo:org/repo:ref:refs/heads/main"
uip admin external-apps federated-credentials create my-app-id \
--name "GitHub Actions" \
--issuer "https://token.actions.githubusercontent.com" \
--audience "api://AzureADTokenExchange" \
--subject "repo:org/repo:ref:refs/heads/main"
数据形状(--输出 json)
{ "Code": "FederatedCredentialCreated" }
{ "Code": "FederatedCredentialCreated" }
uip 管理员外部应用程序联合凭据更新
更新联合凭据 — 每次调用时,所有四个身份字段都需要填写(无部分更新)。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<client-id> | 是 | 外部应用程序 ID。 |
<credential-id> | 是 | 联合凭据 ID (UUID)。 |
选项
| 长 | 短 | 值 | 必填 | 描述 |
|---|---|---|---|---|
--name <name> | -n | 字符串 | 是 | 凭据名称。 |
--issuer <url> | url | 是 | 令牌颁发者 URL。 | |
--audience <audience> | 字符串 | 是 | 预期受众声明。 | |
--subject <subject> | 字符串 | 是 | 预期主题声明。 | |
--description <text> | 字符串 | 否 | 说明。 |
示例
uip admin external-apps federated-credentials update my-app-id fc000000-0000-0000-0000-000000000001 \
--name "GitHub Actions (prod)" \
--issuer "https://token.actions.githubusercontent.com" \
--audience "api://AzureADTokenExchange" \
--subject "repo:org/repo:environment:production"
uip admin external-apps federated-credentials update my-app-id fc000000-0000-0000-0000-000000000001 \
--name "GitHub Actions (prod)" \
--issuer "https://token.actions.githubusercontent.com" \
--audience "api://AzureADTokenExchange" \
--subject "repo:org/repo:environment:production"
数据形状(--输出 json)
{ "Code": "FederatedCredentialUpdated" }
{ "Code": "FederatedCredentialUpdated" }
uip 管理员外部应用程序联合凭据删除
删除外部应用程序中的联合凭据。
参数
| 名称 | 必填 | 用途 |
|---|---|---|
<client-id> | 是 | 外部应用程序 ID。 |
<credential-id> | 是 | 联合凭据 ID (UUID)。 |
示例
uip admin external-apps federated-credentials delete my-app-id fc000000-0000-0000-0000-000000000001
uip admin external-apps federated-credentials delete my-app-id fc000000-0000-0000-0000-000000000001
数据形状(--输出 json)
{ "Code": "FederatedCredentialDeleted", "Data": { "Id": "fc000000-0000-0000-0000-000000000001", "Status": "Deleted successfully" } }
{ "Code": "FederatedCredentialDeleted", "Data": { "Id": "fc000000-0000-0000-0000-000000000001", "Status": "Deleted successfully" } }
相关内容
uip admin robot-accounts/pat/scopes— 这些应用程序从中提取的共享 OAuth2 作用域目录。uip admin users— 目录用户和组。uip admin smtp— 组织电子邮件配置。
另请参阅
- 大纲
- 动词
- 概念
- uip admin 外部应用程序列表
- 示例
- 数据形状(--输出 json)
- uip 管理员外部应用程序获取
- 参数
- 示例
- 数据形状(--输出 json)
- uip 管理员外部应用程序创建
- 参数
- 选项
- 示例
- 数据形状(--输出 json)
- uip admin 外部应用程序更新
- 参数
- 选项
- 示例
- 数据形状(--输出 json)
- uip 管理员外部应用程序删除
- 参数
- 示例
- 数据形状(--输出 json)
- uip 管理员外部应用程序生成密码
- 参数
- 选项
- 示例
- 数据形状(--输出 json)
- UIP 管理员外部应用程序删除密码
- 参数
- 示例
- 数据形状(--输出 json)
- uip 管理员外部应用程序联合凭据列表
- 参数
- 示例
- 数据形状(--输出 json)
- uip 管理员外部应用程序联合凭据获取
- 参数
- 示例
- 数据形状(--输出 json)
- uip 管理员外部应用程序联合凭据创建
- 参数
- 选项
- 示例
- 数据形状(--输出 json)
- uip 管理员外部应用程序联合凭据更新
- 参数
- 选项
- 示例
- 数据形状(--输出 json)
- uip 管理员外部应用程序联合凭据删除
- 参数
- 示例
- 数据形状(--输出 json)
- 相关内容
- 另请参阅