SOLFIND
Web Lens
Portal home

Security Token Service API | Identity and Access Management (IAM) | Google Cloud Documentation

https://docs.cloud.google.com/iam/docs/reference/sts/rest • 374 KB fetched
Open original page


Security Token Service API | Identity and Access Management (IAM) | Google Cloud Documentation

Skip to main content

Documentation

close

* Get Started

*

Get Started with Google Cloud

*

Product List

*

Cloud Customer Care

* Featured Products

*

Agent Platform

*

Apigee API Management

*

BigQuery

*

Compute Engine

*

Cloud CDN

*

Cloud Run

*

Cloud Storage

*

Cloud SQL

*

Gemini Enterprise

*

Google Kubernetes Engine

*

Looker

* Cross-product Tools

*

Access and resources management

*

Costs and usage management

*

Infrastructure as code

*

SDK, languages, frameworks, and tools

* Technology Areas

*

AI and ML

*

Application development

*

Application hosting

*

Compute

*

Data analytics and pipelines

*

Databases

*

Distributed, hybrid, and multicloud

*

Industry solutions

*

Migration

*

Networking

*

Observability and monitoring

*

Security

*

Storage

/

Console

*
English

*
Deutsch

*
Español – América Latina

*
Français

*
Português – Brasil

*
中文 – 简体

*
日本語

*
한국어

Sign in

*

IAM

Start free

Overview

Guides

Reference

Samples

Resources

*

Documentation

*

More

*

Overview

*

Guides

*

Reference

*

Samples

*

Resources

*

Console

*
Identity and Access Management

* All APIs and reference

* Authenticate to IAM

* Retry failed requests

* Client libraries

* gcloud iam commands

*

REST API reference

*

IAM REST API

* Overview

*

v3

*
REST Resources

*

folders.locations.operations

* Overview

* get

*

folders.locations.policyBindings

* Overview

* create

* delete

* get

* list

* patch

* searchTargetPolicyBindings

*

organizations.locations.operations

* Overview

* get

*

organizations.locations.policyBindings

* Overview

* create

* delete

* get

* list

* patch

* searchTargetPolicyBindings

*

organizations.locations.principalAccessBoundaryPolicies

* Overview

* create

* delete

* get

* list

* patch

* searchPolicyBindings

*

projects.locations.operations

* Overview

* get

*

projects.locations.policyBindings

* Overview

* create

* delete

* get

* list

* patch

* searchTargetPolicyBindings

*
Types

* ListPolicyBindingsResponse

* SearchTargetPolicyBindingsResponse

*

v3beta

*
REST Resources

*

folders.locations.accessPolicies

* Overview

* create

* delete

* get

* list

* patch

* searchPolicyBindings

*

folders.locations.operations

* Overview

* get

*

folders.locations.policyBindings

* Overview

* create

* delete

* get

* list

* patch

* searchTargetPolicyBindings

*

organizations.locations.accessPolicies

* Overview

* create

* delete

* get

* list

* patch

* searchPolicyBindings

*

organizations.locations.operations

* Overview

* get

*

organizations.locations.policyBindings

* Overview

* create

* delete

* get

* list

* patch

* searchTargetPolicyBindings

*

organizations.locations.principalAccessBoundaryPolicies

* Overview

* create

* delete

* get

* list

* patch

* searchPolicyBindings

*

projects.locations.accessPolicies

* Overview

* create

* delete

* get

* list

* patch

* searchPolicyBindings

*

projects.locations.operations

* Overview

* get

*

projects.locations.policyBindings

* Overview

* create

* delete

* get

* list

* patch

* searchTargetPolicyBindings

*
Types

* ListAccessPoliciesResponse

* ListPolicyBindingsResponse

* SearchAccessPolicyBindingsResponse

* SearchTargetPolicyBindingsResponse

*

v2

*
REST Resources

*

policies

* Overview

* createPolicy

* delete

* get

* listPolicies

* update

*

policies.operations

* Overview

* get

*

v1

*
REST Resources

*

iamPolicies

* Overview

* lintPolicy

* queryAuditableServices

*

locations.workforcePools

* Overview

* create

* delete

* get

* getIamPolicy

* list

* patch

* setIamPolicy

* testIamPermissions

* undelete

*

locations.workforcePools.operations

* Overview

* get

*

locations.workforcePools.providers

* Overview

* create

* delete

* get

* list

* patch

* undelete

*

locations.workforcePools.providers.keys

* Overview

* create

* delete

* get

* list

* undelete

*

locations.workforcePools.providers.operations

* Overview

* get

*

locations.workforcePools.providers.scimTenants

* Overview

* create

* delete

* get

* list

* patch

* undelete

*

locations.workforcePools.providers.scimTenants.tokens

* Overview

* create

* delete

* get

* list

* patch

* undelete

*

locations.workforcePools.subjects

* Overview

* delete

* undelete

*

organizations.roles

* Overview

* create

* delete

* get

* list

* patch

* undelete

*

permissions

* Overview

* queryTestablePermissions

*

projects.locations.oauthClients

* Overview

* create

* delete

* get

* list

* patch

* undelete

*

projects.locations.oauthClients.credentials

* Overview

* create

* delete

* get

* list

* patch

*

projects.locations.workloadIdentityPools

* Overview

* create

* delete

* get

* getIamPolicy

* list

* patch

* setIamPolicy

* testIamPermissions

* undelete

*

projects.locations.workloadIdentityPools.namespaces

* Overview

* create

* delete

* get

* list

* patch

* undelete

*

projects.locations.workloadIdentityPools.namespaces.managedIdentities

* Overview

* addAttestationRule

* create

* delete

* get

* list

* listAttestationRules

* patch

* removeAttestationRule

* setAttestationRules

* undelete

*

projects.locations.workloadIdentityPools.operations

* Overview

* get

*

projects.locations.workloadIdentityPools.providers

* Overview

* create

* delete

* get

* list

* patch

* undelete

*

projects.locations.workloadIdentityPools.providers.keys

* Overview

* create

* delete

* get

* list

* undelete

*

projects.locations.workloadIdentityPools.providers.operations

* Overview

* get

*

projects.roles

* Overview

* create

* delete

* get

* list

* patch

* undelete

*

projects.serviceAccounts

* Overview

* create

* delete

* disable

* enable

* get

* getIamPolicy

* list

* patch

* setIamPolicy

* signBlob

* signJwt

* testIamPermissions

* undelete

* update

*

projects.serviceAccounts.keys

* Overview

* create

* delete

* disable

* enable

* get

* list

* upload

*

roles

* Overview

* get

* list

* queryGrantableRoles

*
Types

* AttestationRule

* GetPolicyOptions

* KeyData

* ListRolesResponse

* Policy

* RoleView

* TestIamPermissionsResponse

* TrustStore

*

v2beta

*
REST Resources

*

policies

* Overview

* createPolicy

* delete

* get

* listPolicies

* update

*

policies.operations

* Overview

* get

*

v1beta

*
REST Resources

*

projects.locations.workloadIdentityPools

* Overview

* create

* delete

* get

* list

* patch

* undelete

*

projects.locations.workloadIdentityPools.operations

* Overview

* get

*

projects.locations.workloadIdentityPools.providers

* Overview

* create

* delete

* get

* list

* patch

* undelete

*

projects.locations.workloadIdentityPools.providers.operations

* Overview

* get

*

Shared types

*
Types

* Expr

* GetOperationRequest

* Operation

*

PAM REST API

* Overview

*

v1

*
REST Resources

*

folders.locations

* Overview

* checkOnboardingStatus

* get

* list

*

folders.locations.entitlements

* Overview

* create

* delete

* get

* list

* patch

* search

*

folders.locations.entitlements.grants

* Overview

* approve

* create

* deny

* get

* list

* revoke

* search

*

folders.locations.operations

* Overview

* delete

* get

* list

*

organizations.locations

* Overview

* checkOnboardingStatus

* get

* list

*

organizations.locations.entitlements

* Overview

* create

* delete

* get

* list

* patch

* search

*

organizations.locations.entitlements.grants

* Overview

* approve

* create

* deny

* get

* list

* revoke

* search

*

organizations.locations.operations

* Overview

* delete

* get

* list

*

projects.locations

* Overview

* checkOnboardingStatus

* get

* list

*

projects.locations.entitlements

* Overview

* create

* delete

* get

* list

* patch

* search

*

projects.locations.entitlements.grants

* Overview

* approve

* create

* deny

* get

* list

* revoke

* search

*

projects.locations.operations

* Overview

* delete

* get

* list

*
Types

* CallerAccessType

* CallerRelationshipType

* CheckOnboardingStatusResponse

* ListEntitlementsResponse

* ListGrantsResponse

* PrivilegedAccess

* SearchEntitlementsResponse

* SearchGrantsResponse

*

v1beta

*
REST Resources

*

folders.locations

* Overview

* checkOnboardingStatus

* fetchEffectiveSettings

* get

* getSettings

* list

* updateSettings

*

folders.locations.entitlements

* Overview

* create

* delete

* get

* list

* patch

* search

*

folders.locations.entitlements.grants

* Overview

* approve

* create

* deny

* get

* list

* revoke

* search

* withdraw

*

folders.locations.operations

* Overview

* delete

* get

* list

*

organizations.locations

* Overview

* checkOnboardingStatus

* fetchEffectiveSettings

* get

* getSettings

* list

* updateSettings

*

organizations.locations.entitlements

* Overview

* create

* delete

* get

* list

* patch

* search

*

organizations.locations.entitlements.grants

* Overview

* approve

* create

* deny

* get

* list

* revoke

* search

* withdraw

*

organizations.locations.operations

* Overview

* delete

* get

* list

*

projects.locations

* Overview

* checkOnboardingStatus

* fetchEffectiveSettings

* get

* getSettings

* list

* updateSettings

*

projects.locations.entitlements

* Overview

* create

* delete

* get

* list

* patch

* search

*

projects.locations.entitlements.grants

* Overview

* approve

* create

* deny

* get

* list

* revoke

* search

* withdraw

*

projects.locations.operations

* Overview

* delete

* get

* list

*
Types

* CallerAccessType

* CallerRelationshipType

* CheckOnboardingStatusResponse

* FetchEffectiveSettingsResponse

* ListEntitlementsResponse

* ListGrantsResponse

* PrivilegedAccess

* SearchEntitlementsResponse

* SearchGrantsResponse

* Settings

*

Shared types

*
Types

* DeleteOperationRequest

* GetLocationRequest

* GetOperationRequest

* ListLocationsRequest

* ListLocationsResponse

* ListOperationsRequest

* ListOperationsResponse

*

Security Token Service REST API

* Overview

*

v1

*

TopLevel

* token

*
Types

* AccessBoundary

* Binding

* Options

*

v1beta

*

TopLevel

* token

*
Types

* AccessBoundary

* Options

*
Types

* Expr

*

Service Account Credentials REST API

* Overview

*

v1

*
REST Resources

*

locations.workforcePools

* Overview

* getAllowedLocations

*

projects.locations.workloadIdentityPools

* Overview

* getAllowedLocations

*

projects.serviceAccounts

* Overview

* generateAccessToken

* generateIdToken

* getAllowedLocations

* signBlob

* signJwt

*

Workload Identity REST API

* Overview

*

v1

*
REST Resources

*

folders.locations

* Overview

* get

* list

*

folders.locations.operations

* Overview

* cancel

* delete

* get

* list

*

folders.locations.serviceProducers

* Overview

* generateServiceAgents

*

organizations.locations

* Overview

* get

* list

*

organizations.locations.operations

* Overview

* cancel

* delete

* get

* list

*

organizations.locations.serviceProducers

* Overview

* generateServiceAgents

*

projects.locations

* Overview

* get

* list

*

projects.locations.operations

* Overview

* cancel

* delete

* get

* list

*

projects.locations.serviceProducers

* Overview

* generateServiceAgents

*
Types

* ListLocationsResponse

* ListOperationsResponse

*

Agent Identity Credentials REST API

* Overview

*

v1

*
REST Resources

*

projects.locations.authProviders.credentials

* Overview

* finalize

* retrieve

*

Agent Identity REST API

* Overview

*

v1

*
REST Resources

*

projects.locations

* Overview

* get

* list

*

projects.locations.accessSummaries

* Overview

* get

* list

*

projects.locations.authProviders

* Overview

* create

* delete

* disable

* enable

* get

* getIamPolicy

* list

* patch

* query

* queryWorkloads

* revokeAuthorization

* setIamPolicy

* testIamPermissions

* undelete

*

projects.locations.authProviders.authorizations

* Overview

* delete

* get

* list

*

v1beta

*
REST Resources

*

projects.locations

* Overview

* get

* list

*

projects.locations.accessSummaries

* Overview

* get

* list

*

projects.locations.authProviders

* Overview

* create

* delete

* disable

* enable

* get

* getIamPolicy

* list

* patch

* query

* queryWorkloads

* revokeAuthorization

* setIamPolicy

* testIamPermissions

* undelete

*

projects.locations.authProviders.authorizations

* Overview

* delete

* get

* list

*

Shared types

*
Types

* AuditConfig

* Binding

* GetIamPolicyRequest

* GetLocationRequest

* ListLocationsRequest

* ListLocationsResponse

* LogType

* Policy

* SetIamPolicyRequest

* TestIamPermissionsRequest

* TestIamPermissionsResponse

*

RPC API reference

*

IAM RPC API

* Overview

* cloud.control2.shared.operations

* google.cloud.common

* google.iam.admin.v1

*

google.iam.v1

* Overview

* logging

* google.iam.v1beta

* google.iam.v2

* google.iam.v2beta

* google.iam.v3

* google.iam.v3beta

* google.longrunning

* google.rpc

* google.type

*

PAM RPC API

* Overview

* google.cloud.common

* google.cloud.location

* google.cloud.privilegedaccessmanager.v1

* google.cloud.privilegedaccessmanager.v1alpha

* google.cloud.privilegedaccessmanager.v1beta

* google.longrunning

* google.rpc

*

IAM MCP reference

* Overview

*

Tools

* list_deny_policies

* get_deny_policy

* create_deny_policy

* update_deny_policy

* delete_deny_policy

* get_deny_policy_status

* list_roles

* get_role

* create_role

* update_role

* delete_role

* undelete_role

* Use the IAM remote MCP server

*

IAM Conditions reference

* Conditions attribute reference

* Conditions resource attribute value reference

* Services that allow conditional role bindings

*

Roles and permissions reference

* Roles and permissions index

* Roles for job functions

*

A-C

* Access Approval

* Access Context Manager

* Access Transparency

* Actions

* Advisory Notifications

* Agent Gateway

* Agent Identity API

* Agent Registry

* AI Commerce Search API

* AI Edge Portal

* AI Platform

* AI Platform Data Labeling Service

* AlloyDB for PostgreSQL

* Android Management

* Anthos

* Anthos Audit API

* Anthos Support

* API Gateway

* API Hub

* API Keys

* API Management

* Apigee

* Apigee Connect

* Apigee Registry

* App Development Experience

* App Engine

* App Engine flexible environment

* App Hub

* App Optimize API

* App Topology

* Appliance Activation Service

* Application Design Center

* Artifact Analysis

* Artifact Registry

* Assured Open Source Software

* Assured Workloads

* Audit Manager

* AutoML

* Backup and Disaster Recovery

* Backup for GKE

* Bare Metal Solution

* Batch

* BigLake

* BigQuery

* BigQuery Connection API

* BigQuery Continuous Query

* BigQuery Data Policy

* BigQuery Data Transfer Service

* BigQuery Engine for Apache Flink

* BigQuery Migration API

* BigQuery Omni

* BigQuery sharing

* Bigtable

* Binary Authorization

* Blockchain Node Engine

* Blockchain Validator Manager

* Browser

* Business AI Code

* Capacity Planner

* Care Studio

* Certificate Authority Service

* Certificate Manager

* Chrome Enterprise Premium

* Client Auth Config

* Cloud API Registry

* Cloud Asset Inventory

* Cloud Autoscaling

* Cloud Billing

* Cloud Build

* Cloud Commerce Consumer Procurement

* Cloud Controls Partner API

* Cloud Data Fusion

* Cloud Debugger

* Cloud Deploy

* Cloud Deployment Manager

* Cloud DNS

* Cloud Domains

* Cloud Endpoints

* Cloud Endpoints Portal

* Cloud FTP

* Cloud Healthcare API

* Cloud Hub

* Cloud Infrastructure Entitlement Management (CIEM)

* Cloud Integrations

* Cloud Intrusion Detection System

* Cloud IoT

* Cloud Key Management Service

* Cloud License Manager

* Cloud Life Sciences

* Cloud Location Finder

* Cloud Logging

* Cloud Monitoring

* Cloud Notifications

* Cloud Number Registry

* Cloud Optimization

* Cloud OS Config

* Cloud Profiler

* Cloud Quotas

* Cloud Run

* Cloud Run functions

* Cloud Runtime Configuration API

* Cloud Scheduler

* Cloud Security Compliance

* Cloud Service Mesh

* Cloud Service Mesh control plane

* Cloud Source Repositories

* Cloud SQL

* Cloud Storage

* Cloud Tasks

* Cloud Tool Results

* Cloud TPU

* Cloud Trace

* Cloud Workstations

* Cluster Director

* Commerce Agreement Publishing

* Commerce Business Enablement

* Commerce Offer Catalog

* Commerce Org Governance

* Commerce Price Management

* Commerce Producer

* Compliance Scanning

* Compute Engine

* Confidential Computing

* Config Delivery

* Config Management

* Connectors

* Container Registry

* Container Scanning

* Container Security

* Container Threat Detection

* Content Warehouse

* Customer Experience Insights

* Customer Usage Data Processing

* Cyber Insurance Hub

*

D-F

* Data Catalog

* Data Connectors

* Data Lineage API

* Data Pipelines

* Data Security Posture Management

* Data Studio

* Database Center

* Database Insights

* Database Migration Service

* Dataflow

* Dataform

* Dataprep by Trifacta

* Dataproc Metastore

* Datastream

* Dell EMC Cloud OneFS

* Developer Connect

* Device Run

* Device Streaming API

* Dialogflow

* Discovery Engine

* Distributed Cloud Edge Container

* Distributed Cloud Edge Network

* Document AI

* Enterprise Knowledge Graph

* Enterprise Purchasing API

* Error Reporting

* Essential Contacts

* Eventarc

* External Exposure

* Fault Injection Testing

* Filestore

* Financial Services

* Firebase

* Firebase A/B Testing

* Firebase AI Logic

* Firebase App Check

* Firebase App Distribution

* Firebase App Hosting

* Firebase Authentication

* Firebase Cloud Messaging

* Firebase Cloud Messaging Data

* Firebase Crashlytics

* Firebase Data Connect

* Firebase Dynamic Links

* Firebase Extensions

* Firebase E

Links found on this page

  1. Skip to main content [direct]
  2. Documentation [direct]
  3. Get Started with Google Cloud [direct]
  4. Product List [direct]
  5. Cloud Customer Care [direct]
  6. Agent Platform [direct]
  7. Apigee API Management [direct]
  8. BigQuery [direct]
  9. Compute Engine [direct]
  10. Cloud CDN [direct]
  11. Cloud Run [direct]
  12. Cloud Storage [direct]
  13. Cloud SQL [direct]
  14. Gemini Enterprise [direct]
  15. Google Kubernetes Engine [direct]
  16. Looker [direct]
  17. Access and resources management [direct]
  18. Costs and usage management [direct]
  19. Infrastructure as code [direct]
  20. SDK, languages, frameworks, and tools [direct]
  21. AI and ML [direct]
  22. Application development [direct]
  23. Application hosting [direct]
  24. Compute [direct]
  25. Data analytics and pipelines [direct]
  26. Databases [direct]
  27. Distributed, hybrid, and multicloud [direct]
  28. Industry solutions [direct]
  29. Migration [direct]
  30. Networking [direct]
  31. Observability and monitoring [direct]
  32. Security [direct]
  33. Storage [direct]
  34. Console [direct]
  35. IAM [direct]
  36. Start free [direct]
  37. Guides [direct]
  38. Reference [direct]
  39. Samples [direct]
  40. Resources [direct]
  41. Authenticate to IAM [direct]
  42. Retry failed requests [direct]
  43. Client libraries [direct]
  44. gcloud iam commands [direct]
  45. Overview [direct]
  46. Overview [direct]
  47. get [direct]
  48. Overview [direct]
  49. create [direct]
  50. delete [direct]
  51. get [direct]
  52. list [direct]
  53. patch [direct]
  54. searchTargetPolicyBindings [direct]
  55. Overview [direct]
  56. get [direct]
  57. Overview [direct]
  58. create [direct]
  59. delete [direct]
  60. get [direct]
  61. list [direct]
  62. patch [direct]
  63. searchTargetPolicyBindings [direct]
  64. Overview [direct]
  65. create [direct]
  66. delete [direct]
  67. get [direct]
  68. list [direct]
  69. patch [direct]
  70. searchPolicyBindings [direct]
  71. Overview [direct]
  72. get [direct]
  73. Overview [direct]
  74. create [direct]
  75. delete [direct]
  76. get [direct]
  77. list [direct]
  78. patch [direct]
  79. searchTargetPolicyBindings [direct]
  80. ListPolicyBindingsResponse [direct]