v1
latestOpenAPI 3.0.02026-07-246171,3332.1 MBRequest body
Customize how temporary usernames are generated using go template
Protection from accidental deletion of this object [true/false]
Description of the object
For externally provided users, denotes the key-name of IdP claim to extract the username from (Relevant only when --access-type=external)
Base64-encoded service account private key text
Service account key algorithm, e.g. KEY_ALG_RSA_1024 (Relevant only when --access-type=sa and --gcp-cred-type=key)
GCP Project ID override for dynamic secret operations
The email of the fixed service account to generate keys or tokens for (Relevant only when --access-type=sa and --service-account-type=fixed)
Access token scopes list, e.g. scope1,scope2 (Relevant only when --access-type=sa; required when --gcp-cred-type=token)
Agentic input rule in name=...,rule=... format (e.g. name=rule1,rule=Sanitize input) Mirrors commands.AgenticRulesParams — kept separate because ResourceDS cannot embed it (different package, different struct layout).
Additional custom fields to associate with the item
Set output format to JSON
Dynamic secret name
Dynamic secret name
Agentic output rule in name=...,rule=... format (e.g. name=rule1,rule=Mask secrets)
Dynamic producer encryption key
Role binding definitions in JSON format (Relevant only when --access-type=sa and --service-account-type=dynamic)
Comma-separated list of GCP roles to assign to the user (Relevant only when --access-type=external)
The delay duration, in seconds, to wait after generating just-in-time credentials. Accepted range: 0-120 seconds
Enable/Disable secure remote access [true/false]
Destination URL to inject secrets
Secure browser via Akeyless's Secure Remote Access (SRA)
Web-Proxy via Akeyless's Secure Remote Access (SRA)
The type of the GCP service account. Options [fixed, dynamic] (Relevant only when --access-type=sa)
Add tags attached to this object
Target name
Authentication token (see /auth and /configure)
The universal identity token, Required only for universal_identity authentication
User TTL
Response
dynamicSecretUpdateGcpResponse wraps response body.