gcp-cloudidentity-inbound-oidc-client-secret-input

An inbound OIDC SSO profile carries its relying-party client secret only in create or patch input; the official methods document OAuth scopes but no IAM permission action.

gcpcritical service: gcp:cloudidentity emits ContainsCredential

Where it sits

locationcloudidentity.inboundOidcSsoProfiles.create/cloudidentity.inboundOidcSsoProfiles.patch.request.rpConfig.clientSecret
location kindsecret_value
data kindsoauth_token secret_key credential
emits edgeContainsCredential
serviceCloud Identity / Workspace (gcp:cloudidentity)

Collection recipe

access modewrite_only_input
operationcloudidentity.inboundOidcSsoProfiles.create/cloudidentity.inboundOidcSsoProfiles.patch
response pathrequest.rpConfig.clientSecret
encodingstring
params{"name": "\u003cresource-name\u003e"}

References

move · open · esc close