gcp-wif-workforce-oauth-client-secret-create-output

IAM returns the system-generated workforce OAuth client secret in the credential-creation response.

gcpcritical service: gcp:wif emits ExposesCredential

Where it sits

locationiam.projects.locations.oauthClients.credentials.create.clientSecret
location kindoutput_value
data kindsoauth_token secret_key credential
emits edgeExposesCredential
serviceWorkload Identity Federation (gcp:wif)

Collection recipe

access modecreation_response_only
operationiam.projects.locations.oauthClients.credentials.create
response pathclientSecret
encodingstring
params{"name": "\u003cresource-name\u003e"}

Required permissions

iam.googleapis.com/oauthClientCredentials.create

References

move · open · esc close