You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过IAM为普通用户授予API Credentials访问权限?无适配预定义角色

How to Let a Regular IAM User Manage Their Own OAuth Credentials

Got it, let's work through this together. Since there's no predefined Google Cloud IAM role that directly lets a regular user manage their own OAuth credentials (without involving service accounts), you'll need to create a custom role with targeted permissions and a condition to restrict access to their own resources. Here's how to set this up:

Step 1: Define the Required Permissions

First, identify the permissions that let a user create, view, and delete their OAuth 2.0 client IDs. These are the key ones you'll need:

  • oauth2.clientIds.create: Create new OAuth client credentials
  • oauth2.clientIds.get: View details of a specific OAuth client
  • oauth2.clientIds.list: List all OAuth clients associated with the user
  • oauth2.clientIds.delete: Delete an existing OAuth client
  • (Optional) oauth2.clientIds.update: Edit existing OAuth client settings

Step 2: Create a Custom Role with a Restrictive Condition

The critical part here is adding a condition to ensure the user can only manage their own credentials (not everyone else's in the project).

Using the Google Cloud Console

  1. Navigate to IAM & Admin > Roles in your Google Cloud project.
  2. Click Create Role at the top of the page.
  3. Give the role a clear name (e.g., Custom_OAuth_Credentials_Manager) and description (e.g., "Allows a user to manage their own OAuth 2.0 client IDs").
  4. Under Permissions, click Add Permissions and search for each of the permissions listed above, then select them.
  5. Click Add Condition to set up the restriction:
    • For the condition expression, enter: resource.name.contains(principal.email)
    • Give the condition a title like RestrictToOwnCredentials
    • This ensures the user can only interact with OAuth clients linked to their own email address.
  6. Save the role.

Using the gcloud CLI

If you prefer command-line tools, run this command (replace PROJECT_ID with your actual project ID):

gcloud iam roles create CustomOAuthCredentialsManager \
  --project=PROJECT_ID \
  --title="Custom OAuth Credentials Manager" \
  --description="Allows managing own OAuth 2.0 client IDs" \
  --permissions=oauth2.clientIds.create,oauth2.clientIds.get,oauth2.clientIds.list,oauth2.clientIds.delete \
  --condition="expression: resource.name.contains(principal.email), title: RestrictToOwnCredentials"

Step 3: Assign the Custom Role to Your User

Once the custom role is ready:

  1. Go to IAM & Admin > IAM in the Console.
  2. Find the user you want to grant access to, or click Add to invite a new user.
  3. In the Role dropdown, search for and select the custom role you just created.
  4. Save the changes.

Step 4: Verify Access

Have the user log into the Google Cloud Console and go to APIs & Services > Credentials. They should now be able to create, view, and delete their own OAuth client IDs—without being able to modify other users' credentials or service accounts.

Quick Notes

  • If you also want the user to manage API keys (not just OAuth clients), add relevant apikeys.* permissions (like apikeys.create, apikeys.list) to the custom role, keeping the same restrictive condition.
  • Double-check the condition to make sure it's applied correctly—this prevents over-granting access to the entire project's credentials.

内容的提问来源于stack exchange,提问作者dmux

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 08:28:29