gcp-wif-workforce-oauth-client-secret-create-output
IAM returns the system-generated workforce OAuth client secret in the credential-creation response.
Where it sits
| location | iam.projects.locations.oauthClients.credentials.create.clientSecret |
|---|---|
| location kind | output_value |
| data kinds | oauth_token secret_key credential |
| emits edge | ExposesCredential |
| service | Workload Identity Federation (gcp:wif) |
Collection recipe
| access mode | creation_response_only |
|---|---|
| operation | iam.projects.locations.oauthClients.credentials.create |
| response path | clientSecret |
| encoding | string |
| params | {"name": "\u003cresource-name\u003e"} |
Required permissions
iam.googleapis.com/oauthClientCredentials.create