You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

能否使用gcloud生成的凭证文件调用GCP API?求相关指引

Can I use the .google_libcloud_auth.${GCE_PROJECT} file to access GCP APIs?

Absolutely! That file stores OAuth2 credentials created by gcloud (via the libcloud library it relies on), and you can absolutely leverage its contents to authenticate against GCP APIs. Let's break down how to do this, step by step.

1. Directly use the existing access token

The file contains a valid access_token (a Bearer token) that you can use immediately to make API requests. Here's how:

  • First, extract the access token from the file (using jq for simplicity, or just open it in a text editor):
    jq -r '.access_token' ~/.google_libcloud_auth.your-project-id
    
  • Include this token in the Authorization header of your API request. For example, to list Compute Engine instances in a zone:
    curl -H "Authorization: Bearer $(jq -r '.access_token' ~/.google_libcloud_auth.your-project-id)" \
      https://compute.googleapis.com/compute/v1/projects/your-project-id/zones/us-central1-a/instances
    
  • Keep in mind: The access token has an expiration time (check the expire_time or expires_in fields in the file). Once it expires, this method will stop working—you'll need to refresh the token (see below).

2. Refresh the token when it expires

The file also includes a refresh_token, which lets you get a new valid access token without re-authenticating manually. Use GCP's OAuth2 token endpoint for this:

curl -X POST https://oauth2.googleapis.com/token \
  -d "client_id=32555940559.apps.googleusercontent.com" \
  -d "client_secret=ZmssLNjJy2998hD4CTg2ejr2" \
  -d "refresh_token=$(jq -r '.refresh_token' ~/.google_libcloud_auth.your-project-id)" \
  -d "grant_type=refresh_token"

This request will return a new set of credentials (including a fresh access_token and updated expiration times). You can use this new token immediately, or even overwrite the original file with the new credentials to keep things consistent.

3. Use the credentials in code (example with Python)

If you're building a script, you can read the file directly and use the credentials in your HTTP requests:

import json
import requests

# Load the credentials from the file
with open('/home/your-username/.google_libcloud_auth.your-project-id', 'r') as cred_file:
    credentials = json.load(cred_file)

# Build the authorization header
auth_header = {'Authorization': f"Bearer {credentials['access_token']}"}

# Make an API request
response = requests.get(
    'https://compute.googleapis.com/compute/v1/projects/your-project-id/zones/us-central1-a/instances',
    headers=auth_header
)

# Print the response
print(response.json())

If you want to handle token expiration automatically in code, you can add logic to check if the current token is expired, and run the refresh flow if needed.

Important Notes

  • Secure the file: This file contains sensitive credentials (refresh token included). Make sure to set strict permissions on it with chmod 600 ~/.google_libcloud_auth.your-project-id to prevent other users on your system from accessing it.
  • gcloud manages this file automatically: If you're using gcloud regularly, it will refresh the token for you in the background. Manual use is best for custom scripts or cases where you don't want to rely on the gcloud CLI.
  • Standard OAuth2 format: Even though the filename is libcloud-specific, the JSON fields are standard OAuth2 credential fields—so this works with any GCP API that accepts Bearer token authentication.

内容的提问来源于stack exchange,提问作者pepoluan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:16:59