v1

latestOpenAPI 3.0.0Creative Commons Attribution 3.02026-07-1351119.0 KB
projects

Signs a blob using a service account's system-managed private key.

post/v1/{+name}:signBlob

Path parameters

namestring required

Required. The resource name of the service account for which the credentials are requested, in the following format: projects/-/serviceAccounts/{ACCOUNT_EMAIL_OR_UNIQUEID}. The - wildcard character is required; replacing it with a project ID is invalid.

Request body

delegatesstring[]

The sequence of service accounts in a delegation chain. Each service account must be granted the roles/iam.serviceAccountTokenCreator role on its next service account in the chain. The last service account in the chain must be granted the roles/iam.serviceAccountTokenCreator role on the service account that is specified in the name field of the request. The delegates must have the following format: projects/-/serviceAccounts/{ACCOUNT_EMAIL_OR_UNIQUEID}. The - wildcard character is required; replacing it with a project ID is invalid.

payloadstring byte

Required. The bytes to sign.

Response

Successful response

All 5 operations