检测到您已登录华为云国际站账号,为了您更好的体验,建议您访问国际站服务网站 https://www.huaweicloud.com/intl/zh-cn
不再显示此消息
Does FRS Support Fine-grained Policies of IAM? FRS supports fine-grained policies of IAM, allowing for varying FRS operation permissions between IAM accounts and master accounts. You can create IAM users for employees or applications. For details, see "Creating an IAM User."
For example, to obtain an IAM token in the CN-Hong Kong region, obtain the endpoint of IAM (iam.ap-southeast-1.myhuaweicloud.com) for this region and the resource-path (/v3/auth/tokens) in the URI of the API used to obtain a user token.
Check the permissions granted by the master account and confirm if the IAM user who subscribed to the service is the same as the one calling the API. Parent topic: Permissions
Related Services IAM FRS uses Identity and Access Management (IAM) for authentication and authorization. OBS FRS allows users to read facial images from Object Storage Service (OBS).
Does FRS Support Fine-grained Policies of IAM? Calling APIs Failed Due to Permission Issues
Arrears Reasons Arrears typically occur in the following scenarios: The master account did not subscribe to FRS, but an IAM user under the master account had the permission to subscribe and did so independently, resulting in charges incurred by calling FRS APIs.
{Endpoint} indicates the endpoint of IAM, which can be obtained from Regions and Endpoints. Select Headers, add KEY as X-Auth-Token, and set VALUE to the obtained token. For details about API authentication, see Authentication. The following is an example response.
User A user is created on in IAM using an account to use cloud services. Each user has its own identity credentials (password and access keys). You can check the account ID and user ID on the My Credentials page of the console.
When using a token for authentication, cache it to prevent frequently calling the IAM API used to obtain a user token. A token specifies temporary permissions in a computer system.