gcp-iap-oauth-client-secret

The IAP OAuth client resource returns its client secret to callers with the dedicated get-with-secret permission.

gcpcritical service: gcp:iap emits CanReadCredential

Where it sits

locationiap.projects.brands.identityAwareProxyClients.get.secret
location kindsecret_value
data kindsoauth_token secret_key credential
emits edgeCanReadCredential
serviceIdentity-Aware Proxy (gcp:iap)

Collection recipe

access moderead_api
operationiap.projects.brands.identityAwareProxyClients.get
response pathsecret
encodingstring
params{"name": "\u003cresource-name\u003e"}

Required permissions

clientauthconfig.clients.getWithSecret

References

move · open · esc close