Security Token Service API | Identity and Access Management (IAM) | Google Cloud Documentation
https://docs.cloud.google.com/iam/docs/reference/sts/rest • 374 KB fetched Open original page
Security Token Service API | Identity and Access Management (IAM) | Google Cloud Documentation
Skip to main content
Documentation
close
* Get Started
*
Get Started with Google Cloud
*
Product List
*
Cloud Customer Care
* Featured Products
*
Agent Platform
*
Apigee API Management
*
BigQuery
*
Compute Engine
*
Cloud CDN
*
Cloud Run
*
Cloud Storage
*
Cloud SQL
*
Gemini Enterprise
*
Google Kubernetes Engine
*
Looker
* Cross-product Tools
*
Access and resources management
*
Costs and usage management
*
Infrastructure as code
*
SDK, languages, frameworks, and tools
* Technology Areas
*
AI and ML
*
Application development
*
Application hosting
*
Compute
*
Data analytics and pipelines
*
Databases
*
Distributed, hybrid, and multicloud
*
Industry solutions
*
Migration
*
Networking
*
Observability and monitoring
*
Security
*
Storage
/
Console
*
English
*
Deutsch
*
Español – América Latina
*
Français
*
Português – Brasil
*
中文 – 简体
*
日本語
*
한국어
Sign in
*
IAM
Start free
Overview
Guides
Reference
Samples
Resources
*
Documentation
*
More
*
Overview
*
Guides
*
Reference
*
Samples
*
Resources
*
Console
*
Identity and Access Management
* All APIs and reference
* Authenticate to IAM
* Retry failed requests
* Client libraries
* gcloud iam commands
*
REST API reference
*
IAM REST API
* Overview
*
v3
*
REST Resources
*
folders.locations.operations
* Overview
* get
*
folders.locations.policyBindings
* Overview
* create
* delete
* get
* list
* patch
* searchTargetPolicyBindings
*
organizations.locations.operations
* Overview
* get
*
organizations.locations.policyBindings
* Overview
* create
* delete
* get
* list
* patch
* searchTargetPolicyBindings
*
organizations.locations.principalAccessBoundaryPolicies
* Overview
* create
* delete
* get
* list
* patch
* searchPolicyBindings
*
projects.locations.operations
* Overview
* get
*
projects.locations.policyBindings
* Overview
* create
* delete
* get
* list
* patch
* searchTargetPolicyBindings
*
Types
* ListPolicyBindingsResponse
* SearchTargetPolicyBindingsResponse
*
v3beta
*
REST Resources
*
folders.locations.accessPolicies
* Overview
* create
* delete
* get
* list
* patch
* searchPolicyBindings
*
folders.locations.operations
* Overview
* get
*
folders.locations.policyBindings
* Overview
* create
* delete
* get
* list
* patch
* searchTargetPolicyBindings
*
organizations.locations.accessPolicies
* Overview
* create
* delete
* get
* list
* patch
* searchPolicyBindings
*
organizations.locations.operations
* Overview
* get
*
organizations.locations.policyBindings
* Overview
* create
* delete
* get
* list
* patch
* searchTargetPolicyBindings
*
organizations.locations.principalAccessBoundaryPolicies
* Overview
* create
* delete
* get
* list
* patch
* searchPolicyBindings
*
projects.locations.accessPolicies
* Overview
* create
* delete
* get
* list
* patch
* searchPolicyBindings
*
projects.locations.operations
* Overview
* get
*
projects.locations.policyBindings
* Overview
* create
* delete
* get
* list
* patch
* searchTargetPolicyBindings
*
Types
* ListAccessPoliciesResponse
* ListPolicyBindingsResponse
* SearchAccessPolicyBindingsResponse
* SearchTargetPolicyBindingsResponse
*
v2
*
REST Resources
*
policies
* Overview
* createPolicy
* delete
* get
* listPolicies
* update
*
policies.operations
* Overview
* get
*
v1
*
REST Resources
*
iamPolicies
* Overview
* lintPolicy
* queryAuditableServices
*
locations.workforcePools
* Overview
* create
* delete
* get
* getIamPolicy
* list
* patch
* setIamPolicy
* testIamPermissions
* undelete
*
locations.workforcePools.operations
* Overview
* get
*
locations.workforcePools.providers
* Overview
* create
* delete
* get
* list
* patch
* undelete
*
locations.workforcePools.providers.keys
* Overview
* create
* delete
* get
* list
* undelete
*
locations.workforcePools.providers.operations
* Overview
* get
*
locations.workforcePools.providers.scimTenants
* Overview
* create
* delete
* get
* list
* patch
* undelete
*
locations.workforcePools.providers.scimTenants.tokens
* Overview
* create
* delete
* get
* list
* patch
* undelete
*
locations.workforcePools.subjects
* Overview
* delete
* undelete
*
organizations.roles
* Overview
* create
* delete
* get
* list
* patch
* undelete
*
permissions
* Overview
* queryTestablePermissions
*
projects.locations.oauthClients
* Overview
* create
* delete
* get
* list
* patch
* undelete
*
projects.locations.oauthClients.credentials
* Overview
* create
* delete
* get
* list
* patch
*
projects.locations.workloadIdentityPools
* Overview
* create
* delete
* get
* getIamPolicy
* list
* patch
* setIamPolicy
* testIamPermissions
* undelete
*
projects.locations.workloadIdentityPools.namespaces
* Overview
* create
* delete
* get
* list
* patch
* undelete
*
projects.locations.workloadIdentityPools.namespaces.managedIdentities
* Overview
* addAttestationRule
* create
* delete
* get
* list
* listAttestationRules
* patch
* removeAttestationRule
* setAttestationRules
* undelete
*
projects.locations.workloadIdentityPools.operations
* Overview
* get
*
projects.locations.workloadIdentityPools.providers
* Overview
* create
* delete
* get
* list
* patch
* undelete
*
projects.locations.workloadIdentityPools.providers.keys
* Overview
* create
* delete
* get
* list
* undelete
*
projects.locations.workloadIdentityPools.providers.operations
* Overview
* get
*
projects.roles
* Overview
* create
* delete
* get
* list
* patch
* undelete
*
projects.serviceAccounts
* Overview
* create
* delete
* disable
* enable
* get
* getIamPolicy
* list
* patch
* setIamPolicy
* signBlob
* signJwt
* testIamPermissions
* undelete
* update
*
projects.serviceAccounts.keys
* Overview
* create
* delete
* disable
* enable
* get
* list
* upload
*
roles
* Overview
* get
* list
* queryGrantableRoles
*
Types
* AttestationRule
* GetPolicyOptions
* KeyData
* ListRolesResponse
* Policy
* RoleView
* TestIamPermissionsResponse
* TrustStore
*
v2beta
*
REST Resources
*
policies
* Overview
* createPolicy
* delete
* get
* listPolicies
* update
*
policies.operations
* Overview
* get
*
v1beta
*
REST Resources
*
projects.locations.workloadIdentityPools
* Overview
* create
* delete
* get
* list
* patch
* undelete
*
projects.locations.workloadIdentityPools.operations
* Overview
* get
*
projects.locations.workloadIdentityPools.providers
* Overview
* create
* delete
* get
* list
* patch
* undelete
*
projects.locations.workloadIdentityPools.providers.operations
* Overview
* get
*
Shared types
*
Types
* Expr
* GetOperationRequest
* Operation
*
PAM REST API
* Overview
*
v1
*
REST Resources
*
folders.locations
* Overview
* checkOnboardingStatus
* get
* list
*
folders.locations.entitlements
* Overview
* create
* delete
* get
* list
* patch
* search
*
folders.locations.entitlements.grants
* Overview
* approve
* create
* deny
* get
* list
* revoke
* search
*
folders.locations.operations
* Overview
* delete
* get
* list
*
organizations.locations
* Overview
* checkOnboardingStatus
* get
* list
*
organizations.locations.entitlements
* Overview
* create
* delete
* get
* list
* patch
* search
*
organizations.locations.entitlements.grants
* Overview
* approve
* create
* deny
* get
* list
* revoke
* search
*
organizations.locations.operations
* Overview
* delete
* get
* list
*
projects.locations
* Overview
* checkOnboardingStatus
* get
* list
*
projects.locations.entitlements
* Overview
* create
* delete
* get
* list
* patch
* search
*
projects.locations.entitlements.grants
* Overview
* approve
* create
* deny
* get
* list
* revoke
* search
*
projects.locations.operations
* Overview
* delete
* get
* list
*
Types
* CallerAccessType
* CallerRelationshipType
* CheckOnboardingStatusResponse
* ListEntitlementsResponse
* ListGrantsResponse
* PrivilegedAccess
* SearchEntitlementsResponse
* SearchGrantsResponse
*
v1beta
*
REST Resources
*
folders.locations
* Overview
* checkOnboardingStatus
* fetchEffectiveSettings
* get
* getSettings
* list
* updateSettings
*
folders.locations.entitlements
* Overview
* create
* delete
* get
* list
* patch
* search
*
folders.locations.entitlements.grants
* Overview
* approve
* create
* deny
* get
* list
* revoke
* search
* withdraw
*
folders.locations.operations
* Overview
* delete
* get
* list
*
organizations.locations
* Overview
* checkOnboardingStatus
* fetchEffectiveSettings
* get
* getSettings
* list
* updateSettings
*
organizations.locations.entitlements
* Overview
* create
* delete
* get
* list
* patch
* search
*
organizations.locations.entitlements.grants
* Overview
* approve
* create
* deny
* get
* list
* revoke
* search
* withdraw
*
organizations.locations.operations
* Overview
* delete
* get
* list
*
projects.locations
* Overview
* checkOnboardingStatus
* fetchEffectiveSettings
* get
* getSettings
* list
* updateSettings
*
projects.locations.entitlements
* Overview
* create
* delete
* get
* list
* patch
* search
*
projects.locations.entitlements.grants
* Overview
* approve
* create
* deny
* get
* list
* revoke
* search
* withdraw
*
projects.locations.operations
* Overview
* delete
* get
* list
*
Types
* CallerAccessType
* CallerRelationshipType
* CheckOnboardingStatusResponse
* FetchEffectiveSettingsResponse
* ListEntitlementsResponse
* ListGrantsResponse
* PrivilegedAccess
* SearchEntitlementsResponse
* SearchGrantsResponse
* Settings
*
Shared types
*
Types
* DeleteOperationRequest
* GetLocationRequest
* GetOperationRequest
* ListLocationsRequest
* ListLocationsResponse
* ListOperationsRequest
* ListOperationsResponse
*
Security Token Service REST API
* Overview
*
v1
*
TopLevel
* token
*
Types
* AccessBoundary
* Binding
* Options
*
v1beta
*
TopLevel
* token
*
Types
* AccessBoundary
* Options
*
Types
* Expr
*
Service Account Credentials REST API
* Overview
*
v1
*
REST Resources
*
locations.workforcePools
* Overview
* getAllowedLocations
*
projects.locations.workloadIdentityPools
* Overview
* getAllowedLocations
*
projects.serviceAccounts
* Overview
* generateAccessToken
* generateIdToken
* getAllowedLocations
* signBlob
* signJwt
*
Workload Identity REST API
* Overview
*
v1
*
REST Resources
*
folders.locations
* Overview
* get
* list
*
folders.locations.operations
* Overview
* cancel
* delete
* get
* list
*
folders.locations.serviceProducers
* Overview
* generateServiceAgents
*
organizations.locations
* Overview
* get
* list
*
organizations.locations.operations
* Overview
* cancel
* delete
* get
* list
*
organizations.locations.serviceProducers
* Overview
* generateServiceAgents
*
projects.locations
* Overview
* get
* list
*
projects.locations.operations
* Overview
* cancel
* delete
* get
* list
*
projects.locations.serviceProducers
* Overview
* generateServiceAgents
*
Types
* ListLocationsResponse
* ListOperationsResponse
*
Agent Identity Credentials REST API
* Overview
*
v1
*
REST Resources
*
projects.locations.authProviders.credentials
* Overview
* finalize
* retrieve
*
Agent Identity REST API
* Overview
*
v1
*
REST Resources
*
projects.locations
* Overview
* get
* list
*
projects.locations.accessSummaries
* Overview
* get
* list
*
projects.locations.authProviders
* Overview
* create
* delete
* disable
* enable
* get
* getIamPolicy
* list
* patch
* query
* queryWorkloads
* revokeAuthorization
* setIamPolicy
* testIamPermissions
* undelete
*
projects.locations.authProviders.authorizations
* Overview
* delete
* get
* list
*
v1beta
*
REST Resources
*
projects.locations
* Overview
* get
* list
*
projects.locations.accessSummaries
* Overview
* get
* list
*
projects.locations.authProviders
* Overview
* create
* delete
* disable
* enable
* get
* getIamPolicy
* list
* patch
* query
* queryWorkloads
* revokeAuthorization
* setIamPolicy
* testIamPermissions
* undelete
*
projects.locations.authProviders.authorizations
* Overview
* delete
* get
* list
*
Shared types
*
Types
* AuditConfig
* Binding
* GetIamPolicyRequest
* GetLocationRequest
* ListLocationsRequest
* ListLocationsResponse
* LogType
* Policy
* SetIamPolicyRequest
* TestIamPermissionsRequest
* TestIamPermissionsResponse
*
RPC API reference
*
IAM RPC API
* Overview
* cloud.control2.shared.operations
* google.cloud.common
* google.iam.admin.v1
*
google.iam.v1
* Overview
* logging
* google.iam.v1beta
* google.iam.v2
* google.iam.v2beta
* google.iam.v3
* google.iam.v3beta
* google.longrunning
* google.rpc
* google.type
*
PAM RPC API
* Overview
* google.cloud.common
* google.cloud.location
* google.cloud.privilegedaccessmanager.v1
* google.cloud.privilegedaccessmanager.v1alpha
* google.cloud.privilegedaccessmanager.v1beta
* google.longrunning
* google.rpc
*
IAM MCP reference
* Overview
*
Tools
* list_deny_policies
* get_deny_policy
* create_deny_policy
* update_deny_policy
* delete_deny_policy
* get_deny_policy_status
* list_roles
* get_role
* create_role
* update_role
* delete_role
* undelete_role
* Use the IAM remote MCP server
*
IAM Conditions reference
* Conditions attribute reference
* Conditions resource attribute value reference
* Services that allow conditional role bindings
*
Roles and permissions reference
* Roles and permissions index
* Roles for job functions
*
A-C
* Access Approval
* Access Context Manager
* Access Transparency
* Actions
* Advisory Notifications
* Agent Gateway
* Agent Identity API
* Agent Registry
* AI Commerce Search API
* AI Edge Portal
* AI Platform
* AI Platform Data Labeling Service
* AlloyDB for PostgreSQL
* Android Management
* Anthos
* Anthos Audit API
* Anthos Support
* API Gateway
* API Hub
* API Keys
* API Management
* Apigee
* Apigee Connect
* Apigee Registry
* App Development Experience
* App Engine
* App Engine flexible environment
* App Hub
* App Optimize API
* App Topology
* Appliance Activation Service
* Application Design Center
* Artifact Analysis
* Artifact Registry
* Assured Open Source Software
* Assured Workloads
* Audit Manager
* AutoML
* Backup and Disaster Recovery
* Backup for GKE
* Bare Metal Solution
* Batch
* BigLake
* BigQuery
* BigQuery Connection API
* BigQuery Continuous Query
* BigQuery Data Policy
* BigQuery Data Transfer Service
* BigQuery Engine for Apache Flink
* BigQuery Migration API
* BigQuery Omni
* BigQuery sharing
* Bigtable
* Binary Authorization
* Blockchain Node Engine
* Blockchain Validator Manager
* Browser
* Business AI Code
* Capacity Planner
* Care Studio
* Certificate Authority Service
* Certificate Manager
* Chrome Enterprise Premium
* Client Auth Config
* Cloud API Registry
* Cloud Asset Inventory
* Cloud Autoscaling
* Cloud Billing
* Cloud Build
* Cloud Commerce Consumer Procurement
* Cloud Controls Partner API
* Cloud Data Fusion
* Cloud Debugger
* Cloud Deploy
* Cloud Deployment Manager
* Cloud DNS
* Cloud Domains
* Cloud Endpoints
* Cloud Endpoints Portal
* Cloud FTP
* Cloud Healthcare API
* Cloud Hub
* Cloud Infrastructure Entitlement Management (CIEM)
* Cloud Integrations
* Cloud Intrusion Detection System
* Cloud IoT
* Cloud Key Management Service
* Cloud License Manager
* Cloud Life Sciences
* Cloud Location Finder
* Cloud Logging
* Cloud Monitoring
* Cloud Notifications
* Cloud Number Registry
* Cloud Optimization
* Cloud OS Config
* Cloud Profiler
* Cloud Quotas
* Cloud Run
* Cloud Run functions
* Cloud Runtime Configuration API
* Cloud Scheduler
* Cloud Security Compliance
* Cloud Service Mesh
* Cloud Service Mesh control plane
* Cloud Source Repositories
* Cloud SQL
* Cloud Storage
* Cloud Tasks
* Cloud Tool Results
* Cloud TPU
* Cloud Trace
* Cloud Workstations
* Cluster Director
* Commerce Agreement Publishing
* Commerce Business Enablement
* Commerce Offer Catalog
* Commerce Org Governance
* Commerce Price Management
* Commerce Producer
* Compliance Scanning
* Compute Engine
* Confidential Computing
* Config Delivery
* Config Management
* Connectors
* Container Registry
* Container Scanning
* Container Security
* Container Threat Detection
* Content Warehouse
* Customer Experience Insights
* Customer Usage Data Processing
* Cyber Insurance Hub
*
D-F
* Data Catalog
* Data Connectors
* Data Lineage API
* Data Pipelines
* Data Security Posture Management
* Data Studio
* Database Center
* Database Insights
* Database Migration Service
* Dataflow
* Dataform
* Dataprep by Trifacta
* Dataproc Metastore
* Datastream
* Dell EMC Cloud OneFS
* Developer Connect
* Device Run
* Device Streaming API
* Dialogflow
* Discovery Engine
* Distributed Cloud Edge Container
* Distributed Cloud Edge Network
* Document AI
* Enterprise Knowledge Graph
* Enterprise Purchasing API
* Error Reporting
* Essential Contacts
* Eventarc
* External Exposure
* Fault Injection Testing
* Filestore
* Financial Services
* Firebase
* Firebase A/B Testing
* Firebase AI Logic
* Firebase App Check
* Firebase App Distribution
* Firebase App Hosting
* Firebase Authentication
* Firebase Cloud Messaging
* Firebase Cloud Messaging Data
* Firebase Crashlytics
* Firebase Data Connect
* Firebase Dynamic Links
* Firebase Extensions
* Firebase E
Links found on this page
- Skip to main content [direct]
- Documentation [direct]
- Get Started with Google Cloud [direct]
- Product List [direct]
- Cloud Customer Care [direct]
- Agent Platform [direct]
- Apigee API Management [direct]
- BigQuery [direct]
- Compute Engine [direct]
- Cloud CDN [direct]
- Cloud Run [direct]
- Cloud Storage [direct]
- Cloud SQL [direct]
- Gemini Enterprise [direct]
- Google Kubernetes Engine [direct]
- Looker [direct]
- Access and resources management [direct]
- Costs and usage management [direct]
- Infrastructure as code [direct]
- SDK, languages, frameworks, and tools [direct]
- AI and ML [direct]
- Application development [direct]
- Application hosting [direct]
- Compute [direct]
- Data analytics and pipelines [direct]
- Databases [direct]
- Distributed, hybrid, and multicloud [direct]
- Industry solutions [direct]
- Migration [direct]
- Networking [direct]
- Observability and monitoring [direct]
- Security [direct]
- Storage [direct]
- Console [direct]
- IAM [direct]
- Start free [direct]
- Guides [direct]
- Reference [direct]
- Samples [direct]
- Resources [direct]
- Authenticate to IAM [direct]
- Retry failed requests [direct]
- Client libraries [direct]
- gcloud iam commands [direct]
- Overview [direct]
- Overview [direct]
- get [direct]
- Overview [direct]
- create [direct]
- delete [direct]
- get [direct]
- list [direct]
- patch [direct]
- searchTargetPolicyBindings [direct]
- Overview [direct]
- get [direct]
- Overview [direct]
- create [direct]
- delete [direct]
- get [direct]
- list [direct]
- patch [direct]
- searchTargetPolicyBindings [direct]
- Overview [direct]
- create [direct]
- delete [direct]
- get [direct]
- list [direct]
- patch [direct]
- searchPolicyBindings [direct]
- Overview [direct]
- get [direct]
- Overview [direct]
- create [direct]
- delete [direct]
- get [direct]
- list [direct]
- patch [direct]
- searchTargetPolicyBindings [direct]
- ListPolicyBindingsResponse [direct]
|
|