v1

latestOpenAPI 3.0.0Apache 2.0 License2026-07-171,1822,9897.4 MB

A trust provider is a third-party entity that creates, maintains, and manages identity information for users and devices. When an application request is made, the identity information sent by the trust provider will be evaluated by Amazon Web Services Verified Access, before allowing or denying the application request.

get/#Action=CreateVerifiedAccessTrustProvider

Query parameters

TrustProviderType'user' | 'device' required

The type of trust provider can be either user or device-based.

UserTrustProviderType'iam-identity-center' | 'oidc'

The type of user-based trust provider.

DeviceTrustProviderType'jamf' | 'crowdstrike'

The type of device-based trust provider.

Issuerstring

The OIDC issuer.

AuthorizationEndpointstring

The OIDC authorization endpoint.

TokenEndpointstring

The OIDC token endpoint.

UserInfoEndpointstring

The OIDC user info endpoint.

ClientIdstring

The client identifier.

ClientSecretstring

The client secret.

Scopestring

OpenID Connect (OIDC) scopes are used by an application during authentication to authorize access to a user's details. Each scope returns a specific set of user attributes.

The OpenID Connect details for an <code>oidc</code>-type, user-identity based trust provider.

TenantIdstring

The ID of the tenant application with the device-identity provider.

The options for device identity based trust providers.

PolicyReferenceNamestring required

The identifier to be used when working with policy rules.

Descriptionstring

A description for the Amazon Web Services Verified Access trust provider.

ResourceType'capacity-reservation' | 'client-vpn-endpoint' | 'customer-gateway' | 'carrier-gateway' | 'coip-pool' | 'dedicated-host' | 'dhcp-options' | 'egress-only-internet-gateway' | 'elastic-ip' | 'elastic-gpu' | 'export-image-task' | 'export-instance-task' | 'fleet' | 'fpga-image' | 'host-reservation' | 'image' | 'import-image-task' | 'import-snapshot-task' | 'instance' | 'instance-event-window' | 'internet-gateway' | 'ipam' | 'ipam-pool' | 'ipam-scope' | 'ipv4pool-ec2' | 'ipv6pool-ec2' | 'key-pair' | 'launch-template' | 'local-gateway' | 'local-gateway-route-table' | 'local-gateway-virtual-interface' | 'local-gateway-virtual-interface-group' | 'local-gateway-route-table-vpc-association' | 'local-gateway-route-table-virtual-interface-group-association' | 'natgateway' | 'network-acl' | 'network-interface' | 'network-insights-analysis' | 'network-insights-path' | 'network-insights-access-scope' | 'network-insights-access-scope-analysis' | 'placement-group' | 'prefix-list' | 'replace-root-volume-task' | 'reserved-instances' | 'route-table' | 'security-group' | 'security-group-rule' | 'snapshot' | 'spot-fleet-request' | 'spot-instances-request' | 'subnet' | 'subnet-cidr-reservation' | 'traffic-mirror-filter' | 'traffic-mirror-session' | 'traffic-mirror-target' | 'transit-gateway' | 'transit-gateway-attachment' | 'transit-gateway-connect-peer' | 'transit-gateway-multicast-domain' | 'transit-gateway-policy-table' | 'transit-gateway-route-table' | 'transit-gateway-route-table-announcement' | 'volume' | 'vpc' | 'vpc-endpoint' | 'vpc-endpoint-connection' | 'vpc-endpoint-service' | 'vpc-endpoint-service-permission' | 'vpc-peering-connection' | 'vpn-connection' | 'vpn-gateway' | 'vpc-flow-log' | 'capacity-reservation-fleet' | 'traffic-mirror-filter-rule' | 'vpc-endpoint-connection-device-type' | 'verified-access-instance' | 'verified-access-group' | 'verified-access-endpoint' | 'verified-access-policy' | 'verified-access-trust-provider' | 'vpn-connection-device-type' | 'vpc-block-public-access-exclusion' | 'ipam-resource-discovery' | 'ipam-resource-discovery-association'

The type of resource to tag on creation.

The tags to assign to the Amazon Web Services Verified Access trust provider.

ClientTokenstring

A unique, case-sensitive token that you provide to ensure idempotency of your modification request. For more information, see <a href="https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Run_Instance_Idempotency.html">Ensuring Idempotency</a>.

DryRunboolean

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is <code>DryRunOperation</code>. Otherwise, it is <code>UnauthorizedOperation</code>.

Action'CreateVerifiedAccessTrustProvider' required
Version'2016-11-15' required

Response

Success