---
title: "List of Identity Providers"
method: GET
path: "/iam/v2/identity-providers"
tags: ["Identity Providers (iam/v2)"]
---

# List of Identity Providers

`GET /iam/v2/identity-providers`

[![General Availability](https://img.shields.io/badge/Lifecycle%20Stage-General%20Availability-%2345c6e8)](#section/Versioning/API-Lifecycle-Policy)

Retrieve a sorted, filtered, paginated list of all identity providers.

## Query parameters

- `page_size` integer
- `page_token` string

## Response `200`

Identity Provider.

- IamV2IdentityProviderList — `IdentityProvider` objects represent external OAuth-OIDC providers in Confluent Cloud. The API allows you to list, create, read, update, and delete your Identity Provider. Related guide: [OAuth for Confluent Cloud](https://docs.confluent.io/cloud/current/access-management/authenticate/oauth/overview.html). ## The Identity Providers Model <SchemaDefinition schemaRef="#/components/schemas/iam.v2.IdentityProvider" /> ## Quotas and Limits This resource is subject to the [following quotas](https://docs.confluent.io/cloud/current/quotas/overview.html): | Quota | Description | | --- | --- | | `identity_providers_per_org` | Number of OAuth identity providers per organization | | `public_keys_per_provider` | Number of public keys saved per identity provider |
  - `api_version` 'iam/v2', required — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'IdentityProviderList', required — Kind defines the object this REST resource represents.
  - `metadata` object, required — ListMeta describes metadata that resource collections may have
    - `first` string, uri, nullable — A link to the first page of results. If a response does not contain a first link, then direct navigation to the first page is not supported.
    - `last` string, uri, nullable — A link to the last page of results. If a response does not contain a last link, then direct navigation to the last page is not supported.
    - `prev` string, uri, nullable — A link to the previous page of results. If a response does not contain a prev link, then either there is no previous data or backwards traversal through the result set is not supported.
    - `next` string, uri, nullable — A link to the next page of results. If a response does not contain a next link, then there is no more data available.
    - `total_size` integer — Number of records in the full result set. This response may be paginated and have a smaller number of records.
  - `data` object[], required — A data property that contains an array of resource items. Each entry in the array is a separate resource.
    - `api_version` 'iam/v2' — APIVersion defines the schema version of this representation of a resource.
    - `kind` 'IdentityProvider' — Kind defines the object this REST resource represents.
    - `id` string, required — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
    - `metadata` object, required — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
      - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
      - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
      - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
      - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
      - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
    - `display_name` string, required — The human-readable name of the OAuth identity provider.
    - `description` string, required — A description of the identity provider.
    - `identity_claim` string — The JSON Web Token (JWT) claim to extract the authenticating identity to Confluent resources from [Registered Claim Names](https://datatracker.ietf.org/doc/html/rfc7519#section-4.1). This appears in audit log records. Note: if the client specifies mapping to one identity pool ID, the identity claim configured with that pool will be used instead. Note - The attribute is in an [Early Access lifecycle stage] (https://docs.confluent.io/cloud/current/api.html#section/Versioning/API-Lifecycle-Policy)
    - `state` string, required — The current state of the identity provider.
    - `issuer` string, uri, required — A publicly accessible URL uniquely identifying the OAuth identity provider authorized to issue access tokens.
    - `jwks_uri` string, uri, required — A publicly accessible JSON Web Key Set (JWKS) URI for the OAuth identity provider. JWKS provides a set of crypotgraphic keys used to verify the authenticity and integrity of JSON Web Tokens (JWTs) issued by the OAuth identity provider.
    - `keys` IamV2JwksObject[] — The JWKS issued by the OAuth identity provider. Only `kid` (key ID) and `alg` (algorithm) properties for each key set are included.
      - `kty` string, required — Specifies the cryptographic algorithm family used with the key
      - `kid` string, required — Specifies the key-id issued by the OpenIDProvider for the particular tenant
      - `alg` string, required — Specifies the algorithm to be used to generate the public key
      - `use` string — Specifies the intended usage of the key
      - `n` string — Specifies the modulus of the RSA public key. Represented as a Base64urlUInt-encoded value
      - `e` string — Specifies the exponent of the RSA public key.

## Other responses

- `400` — Bad Request
- `401` — The request lacks valid authentication credentials for this resource.
- `403` — The access credentials were considered insufficient to grant access
- `429` — Rate Limit Exceeded
- `500` — Oops, something went wrong!

---

[API](https://skmtc.dev/confluent/apis/confluent-cloud-apis.md) · [All operations](https://skmtc.dev/confluent/apis/confluent-cloud-apis/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/confluent/confluent-cloud-apis/revisions/a6a73f98a698/schema)
