[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-03 (世界標準時間)。"],[[["\u003cp\u003eWorkforce Identity Federation allows users to access Apigee services using an external identity provider (IdP) that supports OpenID Connect (OIDC) or SAML 2.0.\u003c/p\u003e\n"],["\u003cp\u003eUsing Workforce Identity Federation simplifies identity management by removing the need to synchronize user identities between an existing IdP and Google Cloud identities, reducing Apigee onboarding time.\u003c/p\u003e\n"],["\u003cp\u003eWorkforce Identity Federation can be used across Apigee Subscription, Pay-as-you-go, and hybrid-enabled organizations, including the creation and management of Apigee evaluation organizations.\u003c/p\u003e\n"],["\u003cp\u003eWorkforce Identity Federation users can access Apigee in Cloud console or via the Apigee APIs, but they cannot use the Classic Apigee UI or features that are only available there, such as Integrated portals.\u003c/p\u003e\n"],["\u003cp\u003eTo use the Apigee APIs or the Google Cloud CLI as a Workforce Identity Federation user, you must first obtain a short-lived token from the Security Token Service (STS).\u003c/p\u003e\n"]]],[],null,["# Access Apigee using Workforce Identity Federation\n\n*View [Apigee Edge](https://docs.apigee.com/api-platform/get-started/what-apigee-edge) documentation.*\n\nThis page describes how to use a third-party identity provider to access Apigee with [Workforce Identity Federation](/iam/docs/workforce-identity-federation).\nWorkforce Identity Federation lets you use an external identity provider (IdP) to authenticate and authorize\na workforce --- a group of users, such as employees, partners, and contractors --- using [Identity and Access Management (IAM)](/iam/docs)\nto access Apigee services.\n\nYou can use Workforce Identity Federation with any IdP that supports [OpenID\nConnect (OIDC)](https://openid.net/connect/) or [SAML 2.0](https://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-tech-overview-2.0.html),\nsuch as Azure Active Directory (Azure AD), Active Directory Federation Services\n(AD FS), Okta, and others.\n\nBenefits of using Workforce Identity Federation\n-----------------------------------------------\n\nWe understand that many Apigee customers already use some form of single sign-on (SSO), allowing their employees\nto sign-in using existing corporate credentials. Many of our customers also maintain an identity management system.\nSynchronizing user identities from your existing IdP to Google Cloud identities can be challenging and time-consuming.\n\nUsing Workforce Identity Federation can decrease Apigee onboarding time and streamline your identity and security processes\nby removing the need to synchronize user identities from your existing IdP to Google Cloud identities. Workforce Identity Federation can be used across\nGoogle Cloud and provides a single point of control for managing access to Apigee.\n\nSupported Apigee organization types\n-----------------------------------\n\nYou can use Workforce Identity Federation to access and manage resources in any Apigee [Subscription](/apigee/docs/api-platform/reference/subscription-entitlements)\nor [Pay-as-you-go](/apigee/docs/api-platform/reference/pay-as-you-go-updated-overview) organization, including [Apigee hybrid](/apigee/docs/hybrid/v1.12/what-is-hybrid)-enabled organizations. Workforce Identity Federation users can\nalso create and manage Apigee [evaluation organizations](/apigee/docs/api-platform/get-started/compare-paid-eval).\n\nLimitations and considerations\n------------------------------\n\nBefore using Workforce Identity Federation with Apigee, consider the limitations described below.\nApigee support for Workforce Identity Federation is also described in the [Identity federation: products and limitations](/iam/docs/federated-identity-supported-services#apigee) documentation.\n\n### Accessing Apigee in the Google Cloud console\n\nYou can use Workforce Identity Federation to access Apigee services using\n[Apigee in Cloud console](https://console.cloud.google.com/apigee), or via the Apigee APIs.\n\nNote that Apigee Workforce Identity Federation users cannot access Apigee services using the\n[Classic Apigee UI](https://apigee.google.com). Workforce Identity Federation users cannot log into the\nClassic Apigee UI directly and will not be able to access the Classic Apigee UI from Apigee in Cloud console.\n\n### Accessing features only available in the Classic Apigee UI\n\nSome Apigee features are *only* available in the Classic Apigee UI and can't be accessed using Workforce Identity Federation.\nSee [Accessing Apigee in the Google Cloud console](#class-console) for more details. These features include:\n\n- [Integrated portals](/apigee/docs/api-platform/publish/portal/build-integrated-portal)\n- [Developer Engagement](/apigee/docs/api-platform/analytics/partner-engagement-dashboard)\n- [End user analysis \\\u003e Devices](/apigee/docs/api-platform/analytics/devices-dashboard)\n- [End user analysis \\\u003e Geomap](/apigee/docs/api-platform/analytics/geomap-dashboard)\n\nAlthough these features are not available in the Apigee in Cloud console using Workforce Identity Federation,\nyou can use the [Apigee APIs](/apigee/docs/reference/apis/apigee/rest) to access these features.\n\n### Preview features\n\nSome Apigee features in [Preview](https://cloud.google.com/products#product-launch-stages)\nmay not be available to Workforce Identity Federation users. All Generally Available (GA) features accessible in the Apigee in Cloud console will be available to Workforce Identity Federation users.\n\n### Unsupported features\n\nThe following Apigee features are not supported for Workforce Identity Federation users:\n\n- Workforce Identity Federation users cannot use Cloud Code and the [Visual Studio Code (VS Code) IDE](https://code.visualstudio.com/) for [local development](/apigee/docs/api-platform/local-development/overview) of Apigee APIs and API proxies.\n- The Apigee Connect API (`apigeeconnect.googleapis.com`) is not supported for Workforce Identity Federation users with Apigee hybrid organizations.\n\nUse Apigee in Cloud console as a Workforce Identity Federation user\n-------------------------------------------------------------------\n\nWorkforce Identity Federation users can sign in to Apigee using one of three methods:\n\n- [Using an SSO link](/iam/docs/workforce-console-sso#inform-users)\n- [Using the console (federated)](/iam/docs/workforce-console-sso#initiate-console)\n- [Using IdP-initiated sign-in](/iam/docs/workforce-console-sso#initiate-console)\n\nAsk your Apigee administrator to determine which method you should use.\n\nDetailed information about each sign-in method is available in the [Set up\nuser access to the console (federated)](/iam/docs/workforce-console-sso) documentation.\n\nUse the Apigee APIs as a Workforce Identity Federation user\n-----------------------------------------------------------\n\nBefore you can access the Apigee APIs as a Workforce Identity Federation user, you must obtain\na short-lived token from the Security Token Service (STS). Once you have a token, you can access the\nApigee APIs with no additional steps.\n\nFor more information, see [Obtain short-lived tokens for Workforce Identity Federation](/iam/docs/workforce-obtaining-short-lived-credentials#use_the_rest_api).\n\nUse the Google Cloud CLI as a Workforce Identity Federation user\n----------------------------------------------------------------\n\nBefore you can use the Google Cloud CLI (gcloud CLI) as a Workforce Identity Federation user, you must obtain\na short-lived token from the Security Token Service (STS). Once you have a token, you can use the\ngcloud CLI libraries with no additional steps.\n\nFor more information, see [Obtain short-lived tokens for Workforce Identity Federation](/iam/docs/workforce-obtaining-short-lived-credentials#use_the_client_libraries)."]]