v1
latestOpenAPI 3.0.02026-07-246171,3332.1 MBRequest body
Access expiration date in Unix timestamp (select 0 for access without expiry date)
limit the auth method usage for specific client types [cli,ui,gateway-admin,sdk,mobile,extension]
The audience to verify in the JWT received by the client
Subclaims to include in audit logs, e.g "--audit-logs-claims email --audit-logs-claims username"
A CIDR whitelist with the IPs that the access is restricted to
A comma-separated list of GCP labels formatted as "key:value" strings that must be set on authorized GCE instances. TODO: Because GCP labels are not currently ACL'd ....
=== Human and Machine authentication section === Array of GCP project IDs. Only entities belonging to any of the provided projects can authenticate.
List of regions that a GCE instance must belong to in order to be authenticated. TODO: If bound_instance_groups is provided, it is assumed to be a regional group and the group must belong to this region. If bound_zones are provided, this attribute is ignored.
List of service accounts the service account must be part of in order to be authenticated.
=== Machine authentication section === List of zones that a GCE instance must belong to in order to be authenticated. TODO: If bound_instance_groups is provided, it is assumed to be a zonal group and the group must belong to this zone.
Protection from accidental deletion of this object [true/false]
Auth Method description
How many days before the expiration of the auth method would you like to be notified.
if true: enforce role-association must include sub claims
A CIDR whitelist with the GW IPs that the access is restricted to
Set output format to JSON
Jwt TTL
Auth Method name
Choose the relevant product type for the auth method [sm, sra, pm, dp, ca]
ServiceAccount credentials data instead of giving a file path, base64 encoded
Authentication token (see /auth and /configure)
Type of the GCP Access Rules
The universal identity token, Required only for universal_identity authentication
A unique identifier (ID) value which is a "sub claim" name that contains details uniquely identifying that resource. This "sub claim" is used to distinguish between different identities.
Response
authMethodCreateGcpResponse wraps response body.