ListGroups - Identity Store
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).


Lists all groups in the identity store. Returns a paginated list of complete Group objects. Filtering for a Group by the DisplayName attribute is deprecated. Instead, use the GetGroupId API action.


If you have access to a member account, you can use this API operation from the member account. For more information, see Limiting access to the identity store from member accounts in the Amazon IAM Identity Center User Guide.

Request Syntax

{ "Filters": [ { "AttributePath": "string", "AttributeValue": "string" } ], "IdentityStoreId": "string", "MaxResults": number, "NextToken": "string" }

Request Parameters

For information about the parameters that are common to all actions, see Common Parameters.

The request accepts the following data in JSON format.


This parameter has been deprecated.

A list of Filter objects, which is used in the ListUsers and ListGroups requests.

Type: Array of Filter objects

Array Members: Minimum number of 0 items. Maximum number of 1 item.

Required: No


The globally unique identifier for the identity store, such as d-1234567890. In this example, d- is a fixed prefix, and 1234567890 is a randomly generated string that contains numbers and lower case letters. This value is generated at the time that a new identity store is created.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 36.

Pattern: d-[0-9a-f]{10}$|^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}

Required: Yes


The maximum number of results to be returned per request. This parameter is used in the ListUsers and ListGroups requests to specify how many results to return in one page. The length limit is 50 characters.

Type: Integer

Valid Range: Minimum value of 1. Maximum value of 100.

Required: No


The pagination token used for the ListUsers and ListGroups API operations. This value is generated by the identity store service. It is returned in the API response if the total results are more than the size of one page. This token is also returned when it is used in the API request to search for the next page.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 65535.

Pattern: [-a-zA-Z0-9+=/:_]*

Required: No

Response Syntax

{ "Groups": [ { "Description": "string", "DisplayName": "string", "ExternalIds": [ { "Id": "string", "Issuer": "string" } ], "GroupId": "string", "IdentityStoreId": "string" } ], "NextToken": "string" }

Response Elements

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.


A list of Group objects in the identity store.

Type: Array of Group objects


The pagination token used for the ListUsers and ListGroups API operations. This value is generated by the identity store service. It is returned in the API response if the total results are more than the size of one page. This token is also returned when it1 is used in the API request to search for the next page.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 65535.

Pattern: [-a-zA-Z0-9+=/:_]*


For information about the errors that are common to all actions, see Common Errors.


You do not have sufficient access to perform this action.

HTTP Status Code: 400


The request processing has failed because of an unknown error, exception or failure with an internal server.

HTTP Status Code: 500


Indicates that a requested resource is not found.

HTTP Status Code: 400


Indicates that the principal has crossed the throttling limits of the API operations.

HTTP Status Code: 400


The request failed because it contains a syntax error.

HTTP Status Code: 400

See Also

For more information about using this API in one of the language-specific Amazon SDKs, see the following: