gcp-serviceaccounts-signed-jwt-output

A signed JWT can act as a bearer assertion even though the private key is not returned.

gcpcritical service: gcp:serviceaccounts emits ExposesCredential

Where it sits

locationiamcredentials.projects.serviceAccounts.signJwt.signedJwt
location kindoutput_value
data kindscredential signing_secret
emits edgeExposesCredential
serviceService Accounts (gcp:serviceaccounts)

Collection recipe

access moderead_api
operationiamcredentials.projects.serviceAccounts.signJwt
response pathsignedJwt
encodingstring
params{"name": "\u003cresource-name\u003e"}

Required permissions

iam.serviceAccounts.signJwt

References

move · open · esc close