You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何限制Google API Server-to-Server服务账号密钥仅用于特定IP/域名?

Can Google API Server-to-Server Service Account Keys (JSON/P12) Be Restricted to Specific IPs or Domains?

Question

Google API Server-to-Server service account keys (in JSON or P12 format) carry a risk of exposure in some scenarios. Is it possible to restrict these keys to only be used from specific IP addresses or domains via the Google Developer Console? The existing support topics in the console don't provide clear guidance on this.

Answer

Great question—this is a common concern for securing service account keys, and the good news is you can restrict these keys to specific IP addresses (though domain restrictions aren't supported for this authentication method). Here's how to do it directly in the Google Cloud Console:

  • Navigate to IAM & Admin > Service Accounts in the Google Cloud Console.
  • Locate the service account associated with the key you want to restrict, then click into its details page.
  • Switch to the Keys tab, find the JSON/P12 key you need to secure, and click the three-dot menu on its right side.
  • Select Edit key permissions from the dropdown.
  • In the pop-up window, look for the IP restrictions section. Here you can add single IP addresses or CIDR ranges (e.g., 192.168.1.0/24) that are allowed to use this key.
  • Save your changes, and from that point on, any requests using this key from outside the specified IP ranges will be rejected.

A few important notes to keep in mind:

  • Domain restrictions aren't feasible here because service account keys are used for machine-to-machine authentication—there's no direct tie to a user-facing domain in the authentication flow. IP-based restrictions are the way to go for this use case.
  • This works for both JSON and P12 keys; the setup process is identical for both formats.
  • Even with IP restrictions enabled, it's still a best practice to rotate your service account keys regularly to minimize risk if a key is ever exposed.
  • If you couldn't find guidance in the console's support topics, that's understandable—this setting lives in the service account key management section rather than the general API settings, so it's easy to overlook at first.

内容的提问来源于stack exchange,提问作者RWS

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:55:03