gcp-wif-workforce-scim-token-create-output

Gemini Enterprise workforce SCIM token creation returns the token only at creation; the official method documents OAuth scopes but no IAM permission action.

gcpcritical service: gcp:wif emits ExposesCredential

Where it sits

locationiam.locations.workforcePools.providers.scimTenants.tokens.create.securityToken
location kindoutput_value
data kindsbearer_token credential
emits edgeExposesCredential
serviceWorkload Identity Federation (gcp:wif)

Collection recipe

access modecreation_response_only
operationiam.locations.workforcePools.providers.scimTenants.tokens.create
response pathsecurityToken
encodingstring
params{"name": "\u003cresource-name\u003e"}

References

move · open · esc close