Googleapis Iamcredentials
Googleapis Iamcredentials is a connector for the Google Cloud IAM Credentials API used to create short-lived service account credentials and sign tokens.
- Base URL:
https://iamcredentials.googleapis.com - Auth: OAuth 2.0 (user-delegated) — attach an InTouch
oauthcredential. Mint one withitcli.py /oauth <provider>(device-code) or/google-auth(Google); the server auto-refreshes the access token before each run, so the connector never handles or stores tokens.
Operations
iamcredentials_projects_serviceaccounts_generate— POST /v1/{name}:generateAccessToken — Generates an OAuth 2.0 access token for a service account.iamcredentials_projects_serviceaccounts_signblob— POST /v1/{name}:signBlob — Signs a blob using a service account's system-managed private key.iamcredentials_projects_serviceaccounts_signjwt— POST /v1/{name}:signJwt — Signs a JWT using a service account's system-managed private key.
Inputs
- a linked
oauthcredential (no key inputs) — the server injects a freshAuthorization: Bearerfrom it operation— one of the operations above- path parameters when an operation's path contains
{...} query— optional JSON object of query paramsbody— JSON object for create/update ops
Example
operation: iamcredentials_projects_serviceaccounts_generate
# (attach an 'oauth' credential to the task — no inline secrets)
Publishes
The keys a later task may reference as {{taskName.key}}. Referencing anything not listed here resolves to nothing at run time.
erroroperationresultstatus
Input Properties
Every property this tool accepts, from its own tool.iml.
| Property | Type | Required | Default | Description |
|---|---|---|---|---|
operation |
string | yes | — | One of: iamcredentials_projects_serviceaccounts_generate, iamcredentials_projects_serviceaccounts_signblob, iamcredentials_projects_serviceaccounts_signjwt |
name |
string | no | — | Path parameter name (required by some operations). |
body |
string | no | — | Request body as a JSON object string (for create/update operations). |
query |
string | no | — | Query-string parameters as a JSON object string, e.g. {"limit": 50}. Parsed and url-encoded onto the request. |