v1

latestOpenAPI 3.0.0Creative Commons Attribution 3.02026-07-1351119.0 KB
projects

Generates an OpenID Connect ID token for a service account.

post/v1/{+name}:generateIdToken

Path parameters

namestring required

Required. The resource name of the service account for which the credentials are requested, in the following format: projects/-/serviceAccounts/{ACCOUNT_EMAIL_OR_UNIQUEID}. The - wildcard character is required; replacing it with a project ID is invalid.

Request body

includeEmailboolean

Include the service account email in the token. If set to true, the token will contain email and email_verified claims.

organizationNumberIncludedboolean

Include the organization number of the service account in the token. If set to true, the token will contain a google.organization_number claim. The value of the claim will be null if the service account isn't associated with an organization.

delegatesstring[]

The sequence of service accounts in a delegation chain. Each service account must be granted the roles/iam.serviceAccountTokenCreator role on its next service account in the chain. The last service account in the chain must be granted the roles/iam.serviceAccountTokenCreator role on the service account that is specified in the name field of the request. The delegates must have the following format: projects/-/serviceAccounts/{ACCOUNT_EMAIL_OR_UNIQUEID}. The - wildcard character is required; replacing it with a project ID is invalid.

audiencestring

Required. The audience for the token, such as the API or account that this token grants access to.

Response

Successful response